Overview
Anthropic has issued a warning that infostealer malware is actively hijacking Claude login sessions from infected PCs, allowing attackers to access accounts and consume usage without authorization. The company is proactively signing affected users out, removing saved payment methods, and refunding unauthorized charges.
How the Attack Works
- Session hijacking: Infostealers copy authenticated browser sessions, bypassing passwords and 2FA.
- Malware families: Vidar, LummaC2, StealC, RedLine, Acreed (Windows) and Atomic Stealer (AMOS) on macOS.
- Delivery vectors: Pirated games, malicious downloads, and compromised apps.
- Data theft: Browser passwords, login cookies, app credentials, and Claude sessions among other sensitive data.
Signs of Compromise
- Usage anomalies: Usage limits refilling and draining unexpectedly.
- Unauthorized charges: Payment methods misused for fraudulent consumption.
- Persistent infection: Even after Claude sessions are revoked, malware can steal new sessions.
Anthropic’s Response
- Session revocation: Compromised sessions forcibly signed out.
- Payment protection: Saved payment methods removed to prevent misuse.
- Refunds: Unauthorized charges refunded.
- User notifications: Emails sent to affected users with remediation steps.
Defensive Guidance
Anthropic urges users to:
- Remove malware: Use trusted antivirus or endpoint protection tools.
- Change credentials: Update passwords and revoke sessions across apps.
- Avoid risky downloads: Steer clear of pirated software and suspicious apps.
- Monitor accounts: Watch for unusual login activity or drained usage.
Expert in the Cloud Insight
This incident highlights how general-purpose malware can weaponize stolen sessions from AI platforms like Claude. The lesson is clear: endpoint hygiene is as critical as account security. Even the most advanced AI services are vulnerable if the user’s device is compromised. Protecting against infostealers requires patch discipline, cautious downloading habits, and layered defenses.
Leave a Reply