Infostealer used to take over Claude Login Sessions
Share
Anthropic has issued a statement that infostealer malware is being misused to get into authorized Claude sessions. Cyberattackers have the ability to use Claude AI subscriptions owned by others. The former use up the legitimate subscriber’s allotted quota.
How the Adverse Incidents Took Place
We look at the modus operandi of the malicious actors. First, users are tricked into downloading infostealer malware. It proceeds to copy saved passwords, login cookies in existing browsers and Claude session related tokens stored in existing browsers. One of the many things present in the infected machine are tokens for Claude sessions. The adverse incident was made possible because the malware did not have to know the correct password or go through the MFA (Multi-Factor Authentication) process. Usually, passwords and MFA are difficult or impossible to penetrate. However, some cybercriminals have devised a workaround. Hence the present and credible danger. Also, this technique for credential harvesting could be utilized for other domains quite easily.
Anthropic’s Prompt Response
Anthropic has taken the initiative by beginning to sign out Claude users whose accounts were determined to be compromised. Credit card data and payment methods saved on the browser were deleted. In case of financial losses arising because of the incident Anthropic is reimbursing the same to affected users.
An Effective Solution That Will Help
However just logging out and deleting financial data is not enough. If the infostealer is still present on the machine it will exploit opportunities to take over Claude AI sessions. Users must scan the system with malware detection and removal software. Give linked primary email accounts fresh passwords as well as 2FA keys.
Anthropic revealed the many malware strains that were involved. The Windows malware include Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed. While the macOS malware employed was Atomic Stealer (AMOS). As per Anthropic, its Claude AI product was safe and unaffected.
FAQs
1. What is an infostealer?
An infostealer is a type of malware designed to secretly collect sensitive information from a device, such as passwords, browser cookies, login details, and authentication tokens.
2. How can an infostealer take over a Claude login session?
An infostealer may steal browser session cookies or authentication tokens. Attackers can potentially use these stolen credentials to access an already authenticated Claude account without needing the user’s password.
3. Does changing the Claude password always stop the attack?
Not necessarily. If an attacker has already stolen an active session token, changing the password alone may not immediately invalidate that session. Users should also sign out of active sessions and follow Claude’s account-security guidance.
4. How do infostealers get onto a user’s computer?
They are commonly distributed through malicious downloads, fake software updates, phishing emails, cracked applications, malicious advertisements, or deceptive websites.
5. How can users protect their Claude accounts from infostealers?
Keep the operating system, browser, and security software updated; avoid suspicious downloads and cracked software; use strong, unique passwords; enable available multi-factor authentication; and avoid clicking links or opening attachments from unknown sources.
SOURCES:-
https://cybersecuritynews.com/hackers-steal-claude-login-sessions/
https://www.searchenginejournal.com/anthropic-warns-hackers-are-stealing-claude-sessions-to-hijack-accounts/587566/
https://www.esecurityplanet.com/threats/news-claude-session-hijacking-infostealer-malware/
https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/
https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
https://www.theregister.com/security/2026/08/31/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/5293461
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
