Alert: Infostealer Malware Hijacks Claude AI Accounts

Anthropic recently issued a critical alert to Claude users. A coordinated cyberattack involving widespread infostealer malware has been detected. The malware steals active login sessions from victims’ computers, thereby granting attackers unrestricted access to paid accounts. This is achieved without the need for a password or two-factor authentication code.

The AI company has identified six malware families responsible for the campaign: Vidar, LummaC2, StealC, RedLine, and Acreed targeting Windows machines, and Atomic Stealer (AMOS) affecting a smaller number of macOS devices. These commodity stealers are sold and rented on criminal dark-web marketplaces. They harvest browser credentials, authentication cookies, and autofill data from infected systems and send them to attacker-controlled servers.

As the malware captures authenticated browser session tokens, attackers can bypass multi-factor authentication completely. They can exploit victims’ Claude subscriptions as if they were the legitimate user. Anthropic’s systems first detected the fraud when they observed usage limits being rapidly drained while account holders were inactive.

In a related campaign monitored by cybersecurity firm Huntress, at least 29 organizations were compromised in just two days. Attackers ran sponsored Bing ads that led to a malicious fake Claude desktop installer. This resulted in approximately 7,100 downloads. In response, Anthropic has signed affected users out of all sessions, removed stored payment methods, and issued refunds for unauthorized charges.

Source: BleepingComputer – August 30, 2026

Move to the category:

Leave a Reply

Your email address will not be published. Required fields are marked *