Doctorcrypto About RSS Subscribe
Doctorcrypto
Home › Latest › Fake Claude desktop app spreads crypto-stealing malware
Latest

Fake Claude desktop app spreads crypto-stealing malware

By Malik Sokolov · · 2 min read

Cybersecurity researchers have uncovered a fraudulent version of Anthropic's Claude desktop application that is being used to distribute malware designed to drain cryptocurrency wallets and harvest sensitive user data.

How the Scam Works

The malicious software, identified as RevStealer, masquerades as the legitimate Claude AI desktop client to trick unsuspecting users into downloading it. Once installed, the program quietly begins scanning the victim's system for valuable information, all while appearing to function as a normal AI tool.

The malware is engineered to target more than 50 different cryptocurrency wallets, making it a serious threat to anyone storing digital assets on an infected machine. Beyond crypto, it reaches into browsers to extract saved passwords and cookies, effectively opening the door to a wide range of online accounts.

A single fake download can hand attackers the keys to your wallets, your accounts, and your private conversations.

What Data Is at Risk

RevStealer casts a wide net when it comes to collecting personal information. Security analysts say the malware pulls data from several categories, exposing victims to financial theft and privacy breaches at the same time.

The threat highlights a growing trend in which cybercriminals exploit the popularity of well-known AI brands to lend credibility to their malicious campaigns. By impersonating a trusted product like Claude, attackers increase the odds that users will lower their guard and install the software without scrutiny.

The information targeted by the malware includes:

  • Credentials from more than 50 cryptocurrency wallets
  • Saved browser passwords and cookies
  • Data from messaging applications
  • Selected documents stored on the device

Staying Protected

Users are urged to download applications only from official sources and verified developer channels rather than third-party sites or unsolicited links. Verifying the authenticity of a download before installation remains one of the most effective defenses against this type of attack.

The incident serves as a reminder that the rapid rise of AI tools has created fresh opportunities for scammers. As crypto holders increasingly become prime targets, exercising caution around any software claiming to offer popular AI capabilities is more important than ever.

Was this useful?👍 Yes👎 No