Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
On a system that passes the checks, the program decrypts an AES-256-CBC payload stored in its resources.
The native payload resolves Windows APIs without an import table and calls the kernel through 14 indirect syscall wrappers.
The threat is delivered through a trojanized Electron desktop app that impersonates legitimate software; the lure is a “Claude Opus 5 Free Desktop” GitHub project.
It writes that component into a randomly named AppData folder, runs it without a visible window and tries to remove its staging file... Its operators aim for a brief theft window, then self-delete.
The native stage adds... a CAPTCHA window that stops automated execution outright.
RevStealer searches browser databases, cookies, password-manager records...
Confirmed collection targets include... VPN and remote-access credentials...
Its focus on more than 50 cryptocurrency wallets means an infection may expose assets that cannot be recovered once transferred.
RevStealer searches browser databases, cookies, password-manager records, VPN and remote-access settings, messaging data, screenshots and selected documents.
The native stage adds... a CAPTCHA window that stops automated execution outright.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows information stealer distributed in a trojanized Electron application masquerading as a free Claude Opus 5 desktop app, and also via game-cheat lures. It performs host and VM/sandbox checks, decrypts and executes an embedded payload, attempts to add the user AppData directory to Microsoft Defender exclusions, and self-deletes after collection. It steals browser databases, cookies, saved passwords, password-manager records, VPN and remote-access settings, messaging data, screenshots, selected documents, and data from more than 50 cryptocurrency wallets. It exfiltrates short encrypted records and can retrieve fallback C2 infrastructure through a Polygon smart contract.
A Windows information stealer delivered through a trojanized Electron application impersonating legitimate software, notably a fake Claude Opus 5 desktop app. It performs anti-analysis and anti-VM checks, decrypts and launches a native payload, attempts to add an AppData Microsoft Defender exclusion, steals browser, credential-manager, password-manager, cryptocurrency-wallet, VPN, messaging, gaming, clipboard, screenshot, and selected document data, then exfiltrates it in a short burst and self-deletes. It uses indirect syscalls, runtime string decryption, CAPTCHA gating, and a Polygon smart-contract C2 failover mechanism.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.