BlocktoBlockto
Fake Claude Desktop App Used to Spread Crypto-Stealing Malware
AI

Photo: Illustrative

Fake Claude Desktop App Used to Spread Crypto-Stealing Malware

Cybersecurity researchers have identified a fake desktop application impersonating a popular AI assistant, used to distribute a Windows based malware strain known as RevStealer. The counterfeit program, marketed as a free version of a premium AI model, tricks users into downloading malicious software disguised as legitimate technology.

Laurisa
By Laurisa

Junior Author · September 1, 2026

2 min
Key takeaways
Cybersecurity researchers have identified a fake desktop application impersonating a popular AI assistant, used to distribute a Windows based malware strain known as RevStealer.
The counterfeit program, marketed as a free version of a premium AI model, tricks users into downloading malicious software disguised as legitimate technology.
How the Malware Operates RevStealer is built to quietly harvest sensitive data, including browser passwords, cookies, saved credentials, VPN and remote access settings , messaging records, screenshots and select documents.

Cybersecurity researchers have identified a fake desktop application impersonating a popular AI assistant, used to distribute a Windows based malware strain known as RevStealer. The counterfeit program, marketed as a free version of a premium AI model, tricks users into downloading malicious software disguised as legitimate technology.

How the Malware Operates

RevStealer is built to quietly harvest sensitive data, including browser passwords, cookies, saved credentials, VPN and remote access settings, messaging records, screenshots and select documents. The malware also targets more than 50 different cryptocurrency wallets, making it a serious threat to digital asset holders.

Built to Avoid Detection

Before activating, the malware checks whether it is running on a genuine user device by examining system memory, processor details, hostname and graphics hardware. It also watches for delays typical of malware analysis tools. Only if the system appears authentic does it decrypt and execute its payload under a randomized file name.

The discovery follows a separate report on another crypto targeting malware framework capable of stealing wallet files and hijacking browser extensions.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.

Fake Claude Desktop App Used to Spread Crypto-Stealing Malware — Blockto - Blockto