Anthropic Warns Claude Sessions Are Being Stolen by Malware
Claude sessions stolen by infostealer malware are allowing attackers to access users’ accounts and consume their usage limits without going through the normal login process.
Anthropic is warning some Claude users that malware already present on their computers has stolen active Claude browser sessions.
Affected users may notice their Claude usage limits unexpectedly refill and then drain even when they have not used the service.
Because attackers can steal an already authenticated browser session, they may gain access without entering the victim’s password or completing two-factor authentication.
Anthropic is revoking stolen Claude sessions
Anthropic is signing affected users out of Claude to invalidate compromised sessions.
The company is also removing saved payment methods from affected accounts and refunding charges that it identifies as unauthorized.
Anthropic says it continues to investigate the attacks.
Infostealer malware is behind the attacks
Anthropic believes the affected computers were already infected with general-purpose infostealer malware.
The identified Windows threats include Vidar, LummaC2, StealC, RedLine, and Acreed. A small number of affected Macs reportedly contained Atomic Stealer, also known as AMOS.
Infostealers commonly spread through malicious downloads or compromised applications. Once installed, they can collect browser passwords, cookies, session tokens, and credentials stored by other applications.
Attackers appear to be finding Claude session data inside larger collections of credentials stolen by these malware campaigns.
Signing out of Claude does not remove the malware
Revoking a stolen Claude session blocks attackers from continuing to use that specific session, but it does not clean the infected computer.
If the infostealer remains active, it could steal a newly created Claude session again.
Anthropic recommends removing the malware, changing compromised credentials, and revoking other active sessions.
Users should also consider passwords, browser sessions, and other credentials stored on the infected computer as potentially compromised.
In other Claude news, Claude now uses unified memory that works across Cowork and chats. Anthropic also plans to add hidden watermarks and metadata for Claude users in the EU.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages