Cointelegraph•
Fake Claude desktop app spreads crypto-stealing malware

Cybersecurity researchers have uncovered a sophisticated malicious campaign exploiting the surging popularity of Anthropic’s Claude AI assistant to deploy asset-draining malware against cryptocurrency investors. Threat actors are circulating a trojanized installer disguised as an official "Claude Desktop" application, embedded with an aggressive malware strain identified as RevStealer. The campaign strategically exploits public demand for native desktop AI interfaces, relying on search engine optimization (SEO) poisoning, malicious social media promotions, and typosquatting domains to trick users into downloading the executable.
Upon execution, RevStealer deploys stealthy persistence mechanisms designed to evade static analysis and standard endpoint detection protocols. The malware immediately initiates an extensive auditing routine targeting local file systems and browser storage layers. Its primary focus is heavily weighted toward the Web3 ecosystem, featuring specialized code modules capable of siphoning cryptographic keys, seed phrases, and state data from more than 50 distinct cryptocurrency wallet extensions and native desktop clients, including MetaMask, Phantom, Coinbase Wallet, and Trust Wallet.
Beyond direct wallet manipulation, RevStealer conducts deep data harvesting across secondary attack vectors. It actively extracts stored web browser credentials, session cookies, auto-fill forms, and local authentication tokens from key communication platforms like Telegram and Discord—hubs critical to crypto community management and project governance. Furthermore, the malware executes automated regex searches across local directories to locate text files and documents labeled with sensitive terms such as "backup," "secret," or "keystore." Harvested data is packed into encrypted archives and exfiltrated to distant Command-and-Control (C2) infrastructure via TLS-protected channels.
The emergence of RevStealer highlights an escalating intersection between generative AI hype and targeted financial cybercrime. Market sentiment among security engineers and Web3 founders has turned distinctly cautious, as social engineering tactics become increasingly tailored and difficult for non-technical users to detect. As capital flows back into digital asset markets, security analysts emphasize that reliance on web-based wallet extensions without hardware isolation leaves investors highly vulnerable to automated information stealers. This breach campaign serves as a stark reminder of the mounting operational security risks facing retail and institutional capital in an era dominated by rapid software adoption.
