Fake Claude Desktop App Spreads RevStealer Malware to Drain Crypto
Attackers are leveraging AI hype to trick users into installing a malicious application that exfiltrates private keys and browser data.
A malicious campaign is currently distributing a fake Claude desktop application designed to infect users with RevStealer malware. The attack targets individuals seeking desktop versions of the AI tool, using the software to steal sensitive financial assets and personal credentials.
According to reports from Cointelegraph, the malware masquerades as "Claude Opus 5" to lure victims into installation. Once active on a system, RevStealer specifically targets more than 50 different cryptocurrency wallets to exfiltrate private keys. Beyond financial assets, the malware is designed to harvest browser passwords, cookies, and messaging data, sending these credentials directly to the attackers.
The Rise of AI Impersonation
This campaign is part of a broader trend where cybercriminals impersonate popular AI productivity tools to bypass user caution. Because many high-demand AI services are primarily web-based, attackers create unofficial "desktop" versions to fill a perceived gap in the user experience. By leveraging the urgency and hype surrounding AI adoption, attackers can more easily convince users to download and execute unsigned or suspicious software.
Risks of Shadow AI
This attack underscores the significant dangers of "shadow AI" installations—the practice of users installing unauthorized or unofficial AI software to increase productivity. A single malicious download can compromise a user's entire digital identity and financial portfolio. When users bypass official channels to find desktop shortcuts for web tools, they remove the primary security layers provided by official developers and app stores, leaving their private keys and browser sessions exposed to stealer-class malware.
What to Watch
Security experts advise users to only download software from official developer domains and to be wary of AI tools offering "pro" or "Opus" versions via unofficial installers. While the current campaign focuses on RevStealer, the success of such impersonation tactics suggests that other AI tools may be targeted in similar ways. Users should monitor for unauthorized login attempts and consider moving cryptocurrency assets to hardware wallets to mitigate the risk of private key exfiltration.