Cybersecurity

Anthropic Signs Out Users After Infostealers Hijack Claude

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Anthropic Signs Out Users After Infostealers Hijack Claude
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

Anthropic said it is signing Claude users out of their accounts, stripping saved payment methods, and refunding unauthorized charges after discovering that infostealer malware on users' own computers was hijacking active login sessions to burn through paid usage.

According to the company, the malware itself has nothing to do with Claude. It is general-purpose infostealer software that typically arrives through malicious downloads or fake apps and harvests whatever is stored locally on an infected machine: browser passwords, login cookies and credentials for other services. Attackers then sift through that stolen data for active Claude session cookies and reuse them to access accounts as if they were the legitimate owner.

Because the sessions are already authenticated, the technique sidesteps passwords and two-factor authentication entirely. A session cookie keeps a browser marked as signed in after the login step, so an attacker who steals and replays it inherits that authenticated state without ever needing a password or a one-time code.

Anthropic said it has identified five infostealer families behind the campaign on Windows — Vidar, Lumma (LummaC2), StealC, RedLine and Acreed — along with Atomic Stealer (AMOS) on a small number of Macs. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company said, adding that signing affected users out stops the stolen sessions from being reused but does not remove the malware from an infected computer.

As part of its response, Anthropic is revoking compromised sessions, removing saved payment methods from affected accounts, and issuing refunds for charges it identifies as unauthorized. Security researchers tracking the campaign note that infostealer-driven session hijacking has become a increasingly common way for attackers to quietly consume paid subscriptions across AI services, since stolen cookies are harder for users to notice than a stolen password.

Disclosure: NewUJ's editorial process uses Anthropic's Claude models.

Report / request removal

Related

Comments

No comments yet. Be the first.