A fake desktop app posing as the Claude AI assistant is spreading a new strain of crypto-stealing malware. The malware, named RevStealer, is built to drain more than 50 different crypto wallets, and it doesn't stop there — it also grabs browser passwords, cookies, messaging data, and selected documents.
What RevStealer grabs
RevStealer is a stealer-type malware, meaning it's designed to harvest credentials and sensitive files from an infected machine. Its primary target is cryptocurrency, with support for more than 50 wallets. That covers the major desktop and browser-based wallets most people use.
But crypto is just the start. The malware also siphons saved passwords from browsers, steals session cookies, pulls messaging app data, and picks out specific documents from the user's files. That combination makes it a serious threat to anyone who stores keys or recovery phrases on their computer.
The fake Claude desktop app
The malware is being distributed through a fake desktop version of Claude, the AI assistant. The app looks legitimate enough to fool users who are looking for a native desktop client. It's not clear yet how the fake app is being pushed — whether through phishing emails, malicious ads, or fake download sites — but the end result is the same: a user installs it, and RevStealer starts running.
This isn't the first time malware has ridden on the coattails of a popular AI tool, but it's a reminder that the hype around AI products makes them a prime target for impersonation.
Why the document theft matters
The fact that RevStealer also targets selected documents suggests the attackers aren't just after crypto. They may be looking for recovery phrases, private keys, or other sensitive information that could be used for further attacks. The cookie and messaging data theft adds another layer — it could let an attacker hijack active sessions and bypass two-factor authentication.
What to do if you're affected
If you've downloaded a desktop app claiming to be Claude from anywhere other than the official source, treat it as suspicious. Run a full security scan, check for unfamiliar processes, and change passwords for any accounts you've accessed on that machine. The malware's ability to steal cookies and passwords means a simple password change might not be enough — logging out of sessions and clearing browser data is a good idea too.
For now, the safest approach is to stick to official app stores and verified download links. The distribution channels for RevStealer are still being mapped, and it's unclear how many people have been hit. Security teams are working to trace the campaign's origin, but until they do, the best defense is to be careful about what you install.




