Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released

Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released

Key Takeaways

Cybersecurity researchers at Morphisec said they’ve found a fake “Claude Opus 5 Free Desktop” app, distributed via Github. It lures people by offering a “free version” of the paid artificial intelligence (AI) model and tries to trick them into installing a Windows infostealer that targets various crypto asset wallets, among other things, such as browser databases, password managers, and VPN configurations. The targeted crypto asset apps are Atomic, Armory, Cake Wallet, Sparrow, Wasabi, Ledger Wallet, Trezor Suite, Electrum, and others, according to the researchers.

Secure Your Passwords

However, it’s not clear how successful the attackers have been, especially when Ledger Wallet and Trezor Suite are just interfaces for managing a hardware wallet.

According to Morphisec, wallet files are simply copied as-is and may be compressed before being uploaded.

“No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample,” they said.

Therefore, if a wallet has a weak passphrase, reused credentials, or a password stolen from a password manager, criminals might get access to the funds. While not directly tied to crypto assets, one user said their device was infected with Revstealer after downloading what they believed to be legitimate software from Github.

“Despite the infection, their installed security product reportedly did not initially detect the malicious executable. The victim later reported that several online accounts, including Microsoft and EA accounts, had been compromised, illustrating how quickly an infostealer infection can lead to credential and session theft,” the researchers said.

Revstealer is designed to protect itself from detection and can even delete itself.

Another Social Engineering Threat

According to Morphisec, the “free access to Claude Opus 5” case shows that demand for AI tooling is now “a first-class social engineering surface.”

It may therefore be only a matter of time before criminals start impersonating and offering “free” access to the Fable 5.1 and Mythos 5.1 models that were released on September 1. While Fable 5.1 is generally available, Mythos 5.1 can be accessed only via Anthropic’s trusted programs, making it an even more attractive opportunity for scammers trying to trick people with “exclusive access” to Anthropic’s most capable model.

Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers

This week, the co-founder of Refi Hub, Numa Lunah, explained that he was compromised by following a download link delivered…

Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers

Bitcoin.com News

Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers

This week, the co-founder of Refi Hub, Numa Lunah, explained that he was compromised by following a download link delivered…

Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers

Bitcoin.com News

Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers

This week, the co-founder of Refi Hub, Numa Lunah, explained that he was compromised by following a download link delivered…


Source link

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert