CRITICALStripe breach ~33GB of exposed data across 662 organizations. Is your domain exposed?
Run free scan
CyberXtron
Anthropic Sounds the Alarm: Infostealers Target Claude Accounts for Hijacking Claude Sessions to Drain Usage
#cyberxtron#Anthropic #Infostealers #Claude #SessionHijacking#CredentialTheft#ThreatIntelligence

Anthropic Sounds the Alarm: Infostealers Target Claude Accounts for Hijacking Claude Sessions to Drain Usage

 

Executive Summary

In late August and early September 2026, Anthropic began notifying a subset of Claude users that their accounts had been accessed by criminals using commodity information stealing malware. Rather than cracking passwords or defeating two factor authentication, the attackers copied already authenticated browser sessions from infected computers and replayed them to log into victims' Claude accounts. Once inside, the attackers consumed victims' usage allowances and, in accounts with consumption based billing enabled, risked triggering unauthorized charges.

Key Takeaways

  • Session cookies and authentication tokens can be as valuable to attackers as passwords, since they allow login without needing credentials or a multifactor authentication code.
  • Multiple well known infostealer families, including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer (AMOS) on macOS, were connected to the affected machines.
  • Victims often only noticed something was wrong because their usage allowance appeared to refill and then drain rapidly while they were not actively using Claude.
  • Pirated software and fake installers, including counterfeit Claude Code installation pages seen earlier in the year, remain common delivery mechanisms for this class of malware.
  • As AI assistants gain more agentic capability, such as executing code or connecting to other services, the value of a compromised AI identity to an attacker increases well beyond the cost of a subscription.

Attack Method

 

The attackers did not need to defeat Claude's authentication controls directly. The general flow of the campaign worked as follows. A victim's computer became infected with commodity infostealer malware, typically delivered through a pirated game, a cracked application, or a fake software installer. The malware operated quietly in the background, harvesting browser stored passwords, cookies, session tokens, and credentials for numerous locally installed applications. Among this harvested material were the cookies and tokens representing an already logged in Claude session. Criminals later sorted through the larger stolen data collections and specifically extracted Claude related session data. They then loaded those stolen session artifacts into their own browser or tooling to impersonate the victim's authenticated session, gaining direct access to the Claude account without ever needing the victim's password or a live multifactor authentication code. Once inside, the attackers consumed the account's usage allowance, and in cases where consumption based billing or auto reload was enabled, risked generating additional charges.

Targeted Vulnerability

There was no vulnerability in Claude's platform, authentication system, or infrastructure involved in this campaign.

The exposure originated entirely at the endpoint level: unpatched or unprotected personal and work computers infected with general purpose infostealer malware.

The underlying weakness being exploited is the standard reliance on persistent browser sessions, which, once stolen, can bypass password and multifactor authentication protections because the authentication step has already been completed by the legitimate user.

Targeted Country

Individual Claude subscribers located wherever commodity infostealer malware happens to circulate, which is a globally distributed problem rather than a geographically confined one.

MITRE ATT&CK TTPs

T1555.003: Credentials from Web Browsers

T1539: Steal Web Session Cookie

T1071.001: Application Layer Protocol, Web Protocols

T1204.002: Malicious File

T1195.002: Compromise Software Supply Chain (relevant to fake installer and cracked software delivery)

T1657: Financial Theft

T1078: Valid Accounts

T1567: Exfiltration Over Web Service

Indicators of Compromise

Email Address : usersafety[@]anthropic[.]com

Anthropic's Response

Anthropic's response involved signing out affected sessions, removing saved payment methods, and refunding unauthorized charges. The company was clear that the underlying malware infections did not originate from Claude itself; instead, general purpose infostealers already present on victims' machines happened to harvest Claude session data along with a wide range of other credentials. The incident illustrates a broader shift in the threat landscape: authenticated sessions for AI platforms are now valuable enough that criminal groups are actively hunting for them inside larger stolen data collections.

Conclusion

This incident is less a story about a flaw in Claude and more a signal of where credential theft is heading. Commodity infostealer malware, long used to raid banking logins and email accounts, has now been pointed at AI platform sessions simply because those sessions have measurable value: compute time that someone else has already paid for. Anthropic's response of revoking sessions, stripping saved payment methods, and refunding unauthorized usage addresses the immediate financial harm, but it cannot clean an infected endpoint. The durable fix sits with users and organizations treating AI account sessions as privileged credentials worth protecting with the same rigor applied to banking or cloud infrastructure logins. As AI tools take on more agentic capabilities, from executing code to touching connected services, the cost of a stolen AI session is likely to keep climbing well past the price of a subscription.

 

 

 

 

Elevate your security—get curated threat insights in your inbox.