Fake Claude app targets 50+ crypto wallets with RevStealer
Covered by 2 sources · 2 articles
A counterfeit Claude desktop application has been circulating as a vector for RevStealer, a Windows malware targeting cryptocurrency assets and sensitive user data. The malware extracts information from over 50 cryptocurrency wallets alongside password managers and browser data. The attack exploits users' familiarity with the legitimate Claude AI tool, using the impersonation to lower defenses and facilitate malware installation on Windows systems.
- The fake Claude app serves as delivery mechanism for RevStealer, which harvests wallet credentials, passwords, and browser information rather than spreading indiscriminately.
- The attack's scale extends across multiple wallet platforms and password management tools, suggesting targeting of users managing multiple digital assets.
- Desktop application spoofing remains an effective social engineering vector, particularly when imitating popular legitimate software.
All coverage
Fake Claude App Distributes RevStealer Malware Built To Steal Crypto And Credentials
A fake desktop application impersonating the artificial intelligence assistant Claude is being used to distribute RevStealer, a Windows malware designed to steal cryptocurrencies, passwords and browser data. According to a report published…
Fake Claude app targets 50+ crypto wallets with RevStealer
A fake Claude desktop application has distributed RevStealer malware designed to steal data from more than 50 cryptocurrency wallets, password managers, and web browsers on Windows computers. Fake Claude app conceals RevStealer payload Cybe…