Anthropic Alerts Claude Users to Infostealer Malware Threats
Anthropic has notified certain Claude users that malicious software on their devices enabled unauthorized access to login sessions and excessive usage of the service, as disclosed in internal communications to affected customers.
Malware Types and Distribution
Anthropic reported detecting suspicious activity, terminating compromised sessions, and deleting stored payment information from impacted accounts as a preventive measure. The AI provider is informing users whose systems were compromised by infostealer malware, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows platforms, as well as Atomic Stealer (AMOS) on a limited number of macOS devices.
Malware Characteristics
The company clarified that the malware is not specific to Claude but is typically distributed through unofficial channels. These malicious programs operate covertly to extract saved passwords, browser authentication cookies, and credentials for local applications.
Unauthorized Session Exploitation
Anthropic determined that a threat actor subsequently identified and exploited stolen Claude sessions from the harvested data to gain unauthorized account access. Users who observed unexpected fluctuations in their usage limits—such as sudden replenishment followed by rapid depletion—were advised this was likely the cause.
Mitigation Measures
To mitigate risks, the company has logged out affected sessions and warned that further unauthorized activity could trigger additional sign-outs. In addition to terminating sessions, Anthropic removed stored payment methods to prevent unauthorized transactions. Users are required to re-add a payment method only after confirming their systems are free of malware.
Broader Threat Landscape
The incident highlights the broader threat landscape where infostealer malware targets user credentials across multiple platforms, enabling attackers to leverage compromised sessions for financial or operational gain. Anthropic’s response underscores the importance of proactive monitoring and user education in mitigating such risks.
System Security Recommendations
Victims are urged to conduct thorough system scans and ensure complete removal of malicious software before resuming service usage. The company emphasized that its actions were aimed at minimizing harm while maintaining account security.
Industry Implications
The breach also raises concerns about the persistence of malware distribution through unverified sources, reinforcing the need for robust endpoint protection and regular software updates. Anthropic’s transparency in addressing the issue provides a framework for other organizations to follow in similar scenarios.
User Vigilance
Users are advised to remain vigilant, avoid downloading software from non-official sources, and regularly review account activity for anomalies. The incident serves as a reminder of the evolving tactics employed by threat actors to exploit vulnerabilities in both user behavior and system configurations.
The organization also stated it will refund any charges deemed unauthorized.
