LIVE · cybersecurity feed
Live wire
security

Anthropic Users Hit by Infostealer Attacks, Session Thefts

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

zeroday.news ·

Reports indicate that users of Anthropic's Claude AI platform have been targeted in a series of infostealer attacks. The attacks reportedly involved a threat actor deploying various infostealing malware to compromise user systems, subsequently collecting session information, and then using this data to gain unauthorized access to the affected users' Claude accounts. The scope of the compromise, including the number of users impacted, has not been disclosed.

The technical mechanism behind these attacks centers on the use of infostealers, a broad category of malware designed to exfiltrate sensitive data from compromised machines. In this specific instance, the focus was on session information. Session tokens or cookies are small pieces of data that a web server sends to a user's browser, allowing the server to remember the user's state and authenticate them across multiple requests without requiring re-entry of credentials. When an infostealer successfully extracts these tokens, an attacker can effectively "replay" the session, impersonating the legitimate user to access their account without needing their password.

The affected product in this incident is Anthropic's Claude, an artificial intelligence chatbot. As a cloud-based service, access to Claude accounts is typically managed through web browsers or dedicated applications, both of which rely on session management for user authentication and continuity. The compromise of session information directly impacts the security of these accounts, regardless of the strength of the user's password, as the attacker bypasses the traditional login process.

The likely scope of such an incident can vary widely, but it typically depends on the distribution method of the infostealer and the vigilance of users. Infostealers are commonly spread through phishing campaigns, malicious downloads, drive-by downloads from compromised websites, or bundled with pirated software. Users who fall victim to these distribution methods would have their systems compromised, leading to the exfiltration of their session data.

Mitigation guidance for this class of issue generally emphasizes robust endpoint security and user awareness. Users are typically advised to maintain up-to-date antivirus and anti-malware software, exercise caution when opening attachments or clicking links from unknown sources, and avoid downloading software from unofficial repositories. For services like Claude, enabling multi-factor authentication (MFA) is a critical defense, as it introduces an additional verification step that would ideally prevent an attacker from using stolen session tokens alone to gain access. Regularly clearing browser cookies and logging out of sessions when not actively using a service can also reduce the window of opportunity for stolen session data to be exploited.

This incident underscores the persistent threat posed by infostealing malware, which continues to evolve in its sophistication and targeting. As more critical services migrate to cloud platforms and rely on session-based authentication, the compromise of session information represents a significant risk. It highlights the shared responsibility between service providers, who must implement robust security measures, and users, who must adopt best practices for digital hygiene to protect their accounts and data in an increasingly complex threat landscape.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

breach

Healthcare cyberattacks hit pacemakers and millions of patient records

McKesson admits breach as ShinyHunters demands $55.2M

healthcare

McKesson copes with fallout from data theft extortion attack

The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.

malware

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

security

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.