A saved AI service login represents a highly valuable commodity. Anthropic actively notifies users after generic info-stealers hijack their active Claude sessions. Affected individuals recently highlighted this troubling problem online. Malicious actors accessed compromised accounts and rapidly exhausted the available service limits.
The Mechanics of Session Hijacking
Malware secretly copied the authenticated login state directly from the victim’s browser. This stolen data included crucial authorization cookies. This specific session theft forces the service to recognize the attacker as legitimate. The saved session entirely eliminates the need for secondary passwords or two-factor authentication.
Prevalent Malware Families Identified
Anthropic links these breaches to prevalent malware families like Vidar and LummaC2. They also identified StealC, RedLine, and Acreed explicitly targeting Windows platforms. Furthermore, investigators discovered the Atomic Stealer malware infecting a small number of Mac computers. Preliminary company findings confirm these malicious programs possess no direct connection to Claude. These threats typically breached devices through hazardous downloads or perilous applications.
Beyond Isolated Claude Data
Info-stealing malware harvests far more than merely isolated Claude session data. Their illicit bounty encompasses saved passwords, cookies, and diverse application credentials. They extract this sensitive information directly from the infected computer. Attackers likely began isolating Claude sessions from previously amassed data collections. They subsequently utilized these specific sessions to breach the AI service.
Warning Signs and Immediate Remediation
Users might notice an unexpected quota restoration followed by rapid depletion. This rapid exhaustion occurs without owner interaction, clearly signaling a likely compromise. Anthropic proactively terminates these stolen sessions and completely removes saved payment methods. The company then issues refunds for any charges it deems unauthorized. The formal investigation into these alarming incidents remains ongoing.
Eradicating the Persistent Threat
Simply logging out of Claude remains dangerously insufficient for total security. The lingering info-stealer will simply steal the very next active session. Anthropic strongly advises users to eradicate the malicious software completely. Victims must change compromised passwords and meticulously terminate all other active sessions. Users should only re-enter their accounts after thoroughly sanitizing their infected devices.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.