Researchers tied several new programs to the REVSTEALER Windows info-stealer that can steal crypto wallet data, hijack clipboard crypto addresses, and even disable Windows Update and Microsoft Defender to run a crypto miner. Victims are primarily pulled in through “game-cheat” downloads promoted by hijacked YouTube channels and through impersonated/pirated software such as a fake “Claude Opus 5 Free Desktop” app. The write-up includes enough real-world lure and delivery workflow details to build realistic awareness simulations around risky downloads and fake software branding.
How the attack worked
REVSTEALER primarily reaches victims through two lure paths that both rely on trust in familiar-looking content rather than technical exploitation. The first is game-cheat lures: researchers found at least 17 YouTube channels, many hijacked from their original owners, promoting cheat websites through short AI-generated videos. The second is impersonated or pirated software, most notably a fake "Claude Opus 5 Free Desktop" application that copied Anthropic's branding to appear legitimate, even though Anthropic itself was not compromised.
Once a victim downloads and runs the installer, associated modules such as LockAppHost can disable Windows Update services and weaken Microsoft Defender protections before launching a cryptocurrency miner with elevated privileges. Another module, WinUpdate, monitors the clipboard and replaces copied cryptocurrency addresses with attacker-controlled ones while also scanning for recovery phrases.
Why it succeeded
The scheme works because it targets everyday behaviors: gamers looking for an edge and users seeking free access to a paid AI tool. Hijacked YouTube channels lend false credibility to cheat promotion, and copied branding on the fake AI app removes the usual visual cues people rely on to judge legitimacy. Because the core stealer deletes itself after establishing the additional modules, victims may believe the threat is gone even though components remain resident and active.
What to watch for
- Cheats, cracks, or "free" versions of paid software promoted from unofficial sites or video channels
- Video-driven urgency or social proof claiming a cheat or tool "works" without independent verification
- A required executable download for something normally available through an official store or vendor site
- Unexpected changes to Windows Update settings, Defender exclusions, or scheduled security tasks
- Cryptocurrency addresses that change unexpectedly after being copied to the clipboard
Building resistance
- Treat game cheats, cracks, and unofficial "free" versions of paid tools as high risk, and block or avoid installing them on work devices
- Verify that any software installer comes from the vendor's official channel; copied branding does not confirm authenticity
- If infection is suspected, end active sessions on accounts rather than assuming a password change alone resolves the risk, since session cookies and encryption keys can be stolen
- Periodically check that Windows Update and Defender settings have not been silently altered, since some malicious components can persist after the main stealer deletes itself
- Encourage staff to report suspicious download prompts, especially those tied to gaming content or unexpected "free" versions of popular software
Key findings
- Elastic documented four previously unreported executables associated with REVSTEALER: ProManager, WinUpdate, SoftManager, and LockAppHost.
- LockAppHost can disable Windows Update and weaken Microsoft Defender protections before running a cryptocurrency miner with elevated privileges.
- REVSTEALER infections are driven largely by “game-cheat lures,” including hijacked YouTube channels promoting cheat sites with short AI-generated videos.
- REVSTEALER has also been distributed as pirated/impersonated software, including a fake “Claude Opus 5 Free Desktop” app using Anthropic branding.
- WinUpdate replaces copied cryptocurrency addresses in the clipboard with attacker-controlled addresses and looks for recovery phrases.
- Because the core stealer deletes itself, victims may think the infection is gone while the modules remain resident.
Who’s being targeted
- Commonly targeted roles: All employees, IT / Helpdesk, Security team, Developers/technical staff, Employees who install software or use crypto wallets.
- Affected industries: Gaming, Consumer software / end users, Cryptocurrency users.
- Attack channels: website.
- Impersonated: Game-cheat provider / cheat download site, Anthropic (Claude desktop app branding).
Red flags to watch for
- Cheats/cracks promoted as downloads from unofficial sites
- Video-driven urgency/social proof (“working cheat”) without reputable verification
- Executable download required for a “cheat” rather than a trusted store install
- “Free” version of a paid tool from a non-official download channel
- Branding copied to imply legitimacy
- Installer not obtained from the vendor’s official site/app store
Frequently asked questions
How does REVSTEALER typically infect victims?
It reaches victims mainly through game-cheat lures, including hijacked YouTube channels that use short AI-generated videos to promote cheat websites. It has also been packaged as pirated or impersonated software, such as a fake Claude Opus 5 Free Desktop app.
What does REVSTEALER do once installed?
Associated modules can disable Windows Update services and weaken Microsoft Defender protections, then run a cryptocurrency miner with elevated privileges. One module also swaps clipboard cryptocurrency addresses and searches for recovery phrases.
Was Anthropic compromised by the fake Claude app?
No. The fake app copied Anthropic's branding to appear legitimate, but there is no indication Anthropic itself was compromised.
Is changing my password enough if I suspect infection?
No. Because the stealer can take session cookies and browser encryption keys, affected users should end active sessions on their accounts rather than assume a password reset alone is sufficient.
Read the video transcript
You’re on YouTube, see a short clip: “New aim-assist cheat, 100% safe, link in description.” You click. The site offers a “ProManager cheat installer.” You run it, thinking it’s just for games, but it’s REVSTEALER. It can grab your crypto wallets, hijack clipboard addresses with WinUpdate, and even drop a miner after LockAppHost weakens Microsoft Defender. Same trick with apps: a site pushing “Claude Opus 5 Free Desktop” using Anthropic branding. Looks polished, but it’s just REVSTEALER in a costume, and the core stealer can delete itself so you think it’s gone while its modules keep running. Aha moment: if a cheat, crack, or “free” Claude desktop app isn’t from an official store or the vendor’s own site, treat it as REVSTEALER. Your move: don’t install it, report the link to IT and walk away.