Anthropic Warns of Infostealer Malware Hijacking Claude Sessions to Drain Usage
Anthropic has issued a warning about a cybersecurity incident involving unauthorized access to Claude user accounts through infostealer malware.
Cybersecurity Incident Overview
Anthropic reported that malicious software installed on affected devices has been extracting active login sessions, enabling threat actors to exploit these credentials for unauthorized usage of Claude services. The company has initiated measures to log out affected users, delete stored payment information, and process refunds for any unapproved charges detected.
Malware and Attack Details
The breach was identified through user reports and internal investigations, with the company confirming that attackers are leveraging compromised sessions to consume Claude’s resources without user interaction. “We have observed a malicious actor utilizing widely available infostealer malware to extract Claude login sessions from infected systems, subsequently using these sessions to access accounts and deplete usage allowances,” the statement disclosed.
Infostealer Variants Involved
Anthropic’s analysis linked the attacks to multiple infostealer variants, including Vidar, LummaC2, StealC, RedLine, and Acreed, which are known to target Windows systems. A smaller number of Mac users were found to be affected by Atomic Stealer (AMOS).
- Vidar
- LummaC2
- StealC
- RedLine
- Acreed
- Atomic Stealer (AMOS)
User Actions and Security Measures
Users affected by the breach are advised to take immediate steps to secure their accounts, including changing credentials, revoking all active sessions, and removing the malware from their devices. Anthropic warned that even after being logged out, residual malware on a system could lead to repeated session theft.
Industry Implications and Response
The incident underscores the growing threat of session hijacking in enterprise environments, where infostealer malware remains a prevalent attack vector. Anthropic emphasized that the malware is not specific to Claude and is unrelated to the platform’s software or user interactions. “There is no evidence to suggest that this malware was installed via Claude or is connected to any actions taken within the service,” the statement clarified.
“There is no evidence to suggest that this malware was installed via Claude or is connected to any actions taken within the service,” the statement clarified.
Statistics and Ongoing Efforts
Anthropic noted that 37% of malicious activities conducted with stolen credentials go undetected by existing security measures. The company’s response includes ongoing monitoring and communication with affected users to mitigate further damage.
Conclusion
This incident highlights the critical need for users to remain vigilant and proactive in securing their accounts. Anthropic continues to work on addressing the breach and preventing future attacks.
