[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-anthropic-warns-infostealer-malware-claude-sessions":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"anthropic-warns-infostealer-malware-claude-sessions","Anthropic Warns: Infostealer Malware Hijacking Claude Sessions to Drain Usage","Anthropic has alerted users to a campaign where infostealer malware steals Claude login sessions to abuse accounts and consume usage quotas. The company is signing out affected users and refunding unauthorized charges.","2026-08-31","07:43","2026-08-31T07:43:00+02:00","","August 31, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"Security","Malware","AI Services","Claude","Authentication","\u002Ftools\u002Fki-durchsetzungsmonitor","AI Security Incidents","Vidar, LummaC2, StealC, and RedLine identified","\u002Fnewsroom\u002Fimg\u002Fanthropic-warns-infostealer-malware-claude-sessions.webp","\u002Fog-nr\u002Fanthropic-warns-infostealer-malware-claude-sessions.en.png",2,444,"\u003Cp>Anthropic has officially warned of a security campaign in which cybercriminals use infostealer malware to steal Claude login sessions from infected computers and subsequently abuse the accounts. In an email to affected users, the company stated that stolen sessions are being used to consume usage quotas and incur charges.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Multiple malware families\u003C\u002Fstrong> identified: Vidar, LummaC2, StealC, and RedLine on Windows; \u003Cstrong>Atomic Stealer (AMOS)\u003C\u002Fstrong> on a small number of Macs\u003C\u002Fli>\n\u003Cli>Anthropic \u003Cstrong>signs out affected users\u003C\u002Fstrong>, removes saved payment methods, and refunds unauthorized charges\u003C\u002Fli>\n\u003Cli>Infostealers copy \u003Cstrong>already-authenticated browser sessions\u003C\u002Fstrong>, so attackers do not need to repeat the normal login process with password and 2FA\u003C\u002Fli>\n\u003Cli>Malware typically arrives via \u003Cstrong>downloads or malicious apps\u003C\u002Fstrong> – one user confirmed downloading a pirated game\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>How the Abuse Works\u003C\u002Fh2>\n\u003Cp>Infostealers collect locally stored data such as browser passwords, login cookies, and credentials from other applications. Claude sessions are just one of many targets. Anthropic explains in its warning:\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>&quot;We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people&#39;s computers, then using those login sessions to access Claude accounts and consume their usage.&quot;\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>The key difference: because the session is already authenticated, attackers do not need to go through the normal login process again. They can access the account immediately.\u003C\u002Fp>\n\u003Ch2>Detection Signs and Countermeasures\u003C\u002Fh2>\n\u003Cp>Users should be alert if their usage quota suddenly appears to refill and then drain without them actively using Claude. This is a strong indicator of abuse.\u003C\u002Fp>\n\u003Cp>Anthropics measures are limited: the company revokes stolen sessions and removes saved payment methods. However, Anthropic explicitly warns:\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>&quot;Signing you out of Claude stops the stolen sessions, but it doesn&#39;t remove the malware. If it&#39;s still on your computer, your next login session could be stolen the same way.&quot;\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>Therefore, Anthropic recommends affected users take basic security steps: change passwords, revoke other sessions, and remove the malware from their computer.\u003C\u002Fp>\n\u003Ch2>What This Means for Enterprises\u003C\u002Fh2>\n\u003Cp>This warning is a wake-up call for organizations using Claude or other AI services with API keys or usage quotas. The attack demonstrates that \u003Cstrong>infostealers are increasingly targeting AI service authentication\u003C\u002Fstrong>, not just banking credentials or email passwords. For companies with high API budgets or usage limits, this represents a direct financial risk.\u003C\u002Fp>\n\u003Cp>Organizations should educate employees against downloading pirated software or suspicious applications. Additionally, implementing \u003Cstrong>session management tools\u003C\u002Fstrong> and regularly reviewing usage bills for anomalies is advisable. Anthropic&#39;s investigation is ongoing – further details about the campaign may emerge.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fartificial-intelligence\u002Fanthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage\u002F\">BleepingComputer\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.firstpost.com\u002Ftech\u002Fanthropic-warns-claude-users-after-infostealers-hijack-active-login-sessions-14042009.html\u002Famp\">Firstpost\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1788173776533]