Anthropic has issued a critical warning regarding infostealer malware that is stealing active Claude login sessions. Attackers are bypassing security to drain user usage limits.
- Infostealer malware is stealing active Claude login sessions from user PCs.
- Attackers can access accounts without needing passwords or 2FA.
- Anthropic is revoking compromised sessions and removing saved payment methods.
- Key malware identified: Vidar, LummaC2, StealC, RedLine, and AMOS.
In a significant cybersecurity development, AI giant Anthropic has alerted its user base that infostealer malware is actively hijacking Claude login sessions. These malicious programs are designed to steal authenticated browser sessions, allowing bad actors to access user accounts and consume usage limits without ever needing to provide a password.
The threat is particularly insidious because it targets the 'session cookie' rather than the login credentials themselves. By copying an already authenticated session, attackers can bypass standard security measures, including Two-Factor Authentication (2FA). Users who notice their Claude usage limits refilling and then immediately draining while they are inactive are likely victims of this type of attack.
Why This Matters
BozokMedia analysis shows that this trend highlights a shift in cybercrime tactics: moving from stealing credentials to stealing 'identities' via active sessions. As high-value AI tools like Claude become central to professional workflows, they become prime targets for attackers looking to exploit computational resources or access sensitive user data.
When attackers utilize valid, stolen sessions, traditional prevention defenses often drop to as low as 37% effectiveness.
Anthropic has clarified that the malware is not a result of any vulnerability within the Claude platform itself. Instead, it is general-purpose malware that typically enters a system through malicious downloads, pirated software, or suspicious apps. The company has identified several specific malware strains involved, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS.
Historical Background
Infostealer malware has evolved from simple keyloggers to sophisticated tools capable of extracting entire browser profiles. In the era of 'Session Hijacking,' the goal is no longer just to find a password, but to steal the digital 'token' that tells a website the user is already logged in. This bypasses the most common modern defense: Multi-Factor Authentication.
Frequently Asked Questions
1. How does Anthropic protect affected users?
Anthropic is proactively signing affected users out, removing saved payment methods to prevent unauthorized charges, and issuing refunds for unauthorized usage.
2. Will changing my password stop the attack?
Not necessarily. If the malware is still on your computer, it will simply steal your new session as soon as you log back in. You must remove the malware first.