LIVE · cybersecurity feed
Live wire
malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]

zeroday.news ·

Anthropic has issued a warning to some users of its Claude AI service, indicating that their accounts have been compromised by infostealer malware. The company reports that these malicious programs have stolen active Claude login sessions from users' computers, enabling attackers to access accounts and consume their allocated usage.

In response, Anthropic is taking several steps for affected users, including signing them out of Claude, removing any saved payment methods, and refunding charges identified as unauthorized. The company communicated to affected users that if their usage limits appeared to refill and then deplete without their interaction, this was the likely cause.

The infostealer malware operates by copying already authenticated browser sessions, which means attackers can bypass the standard password and two-factor authentication processes. Anthropic's ongoing investigation suggests that the compromised computers were already infected with general-purpose infostealer malware. The company emphasized that there is no indication the malware is related to Claude itself, was installed through Claude, or connected to any user activity within the service.

According to Anthropic, this type of malware typically infiltrates systems through downloads or malicious applications. Once installed, it steals locally stored information, including browser passwords, login cookies, and credentials for various applications. Claude sessions were likely among the many pieces of data collected, which attackers are now reportedly exploiting. One user who received the warning confirmed their system was compromised after downloading a pirated game.

Anthropic has identified several specific malware families involved in these attacks. On Windows systems, these include Vidar, LummaC2, StealC, RedLine, and Acreed. A smaller number of Mac users were affected by Atomic Stealer (AMOS).

While Anthropic is revoking compromised sessions and removing payment methods to prevent further unauthorized purchases, the company stressed that signing users out of Claude does not eliminate the malware from their computers. If the malware remains, subsequent login sessions could be stolen in the same manner.

Affected users are advised to implement basic security measures. These include changing credentials for their accounts, revoking other active sessions, and thoroughly removing the malware from their personal computers to prevent future compromises.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

vulnerabilityhigh

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evide