Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Anthropic warns Claude users of infostealer malware hijacking sessions to drain usage
00

Anthropic warns Claude users of infostealer malware hijacking sessions to drain usage

Aug 30, 2026

Anthropic has warned Claude users that threat actors are using common infostealer malware—including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer—to hijack active browser session cookies. This technique allows attackers to bypass passwords and multi-factor authentication to drain victims' paid usage quotas. Anthropic is responding by terminating compromised sessions, removing saved payment methods, and refunding unauthorized charges, but warns that users must fully remove the malware from their devices to prevent immediate reinfection.

Claude session hijacking attacks

  • ▪The session hijacking campaign targeting Claude accounts came to light through unusual usage patterns, such as quotas refilling and mysteriously draining.
  • ▪Anthropic warned Claude users that threat actors are using infostealer malware to hijack active login sessions and drain paid usage quotas.
  • ▪Anthropic clarified that the credential theft wave is unrelated to Claude's infrastructure, its software, or any user activity on the platform.

Infostealer malware families identified

  • ▪Anthropic identified Atomic Stealer, also known as AMOS, as the malware family used to target a limited number of macOS devices.
  • ▪Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed as the Windows-based infostealer malware families involved in the session-hijacking campaign.

Session cookie theft mechanics

  • ▪Infostealer malware copies authenticated browser session cookies, allowing attackers to bypass passwords and multi-factor authentication to access Claude accounts.
  • ▪Some security-conscious users have adopted Google Chrome's Device Bound Session Credentials to tie session cookies to specific devices and prevent exfiltration.
  • ▪The infostealer malware typically infects devices through malicious downloads, compromised software applications, or pirated games downloaded by users.

Anthropic security response measures

  • ▪Anthropic issued refunds to Claude users who incurred unauthorized charges from attackers running up their usage quotas.
  • ▪Anthropic removed saved payment methods from compromised Claude accounts to prevent unauthorized purchases and fraud by attackers.
  • ▪Anthropic responded to the compromises by forcibly signing out all affected Claude sessions and revoking the stolen session tokens.

User remediation steps required

  • ▪Anthropic warned that signing users out only addresses the symptom, as active malware remaining on a device can steal the very next login session.
  • ▪Anthropic urged affected users to change their account credentials, revoke other active sessions, and thoroughly remove the malware from their computers.

4 sources

Theregister
Anthropic cracks down on hijacked user accounts mining AI tokens
View source article
Timesofindia
Anthropic has a warning for Claude users: We have recently seen some ...
View source article
Cryptobriefing
Anthropic warns Claude users of infostealer malware infections that hijacked active sessions
View source article
Bleepingcomputer
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
View source article

Featured stories

View more in AI security

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

Story comments

Loading comments…

Related Projects

Anthropic

Topics

AI securityAI tools & productsAI assistants & chatbots

Featured stories

View more in AI security

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources