[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAKKqJsLBC4_2YqLdhFBlOX1wDeOQaO9AceginKgaOUo":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"f19e0373-54cc-4c36-bee1-ccfbd3fdf6f4","Anthropic warns infostealer malware is hijacking Claude sessions to drain usage","anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-f14f42","Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]","Anthropic is warning users that infostealer malware on their PCs is stealing active Claude login sessions. Attackers are using these stolen sessions to access accounts and consume user usage, leading Anthropic to sign affected users out, remove payment methods, and issue refunds. The company stressed that the malware is not related to Claude itself but is a general-purpose threat that collects various credentials, including Claude sessions.","Infostealer malware hijacks Claude AI sessions, draining user accounts and usage.","Anthropic warns infostealer malware is hijacking Claude sessions to drain usage By Mayank Parmar August 30, 2026 10:30 AM 0 Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. \"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage,\" Anthropic said in an email sent to an affected user, who shared it on Reddit. \"If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause,\" Anthropic warned. Anthropic sending emails to affected users Source: Reddit It is also worth noting that infostealers can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again. Anthropic links attacks to Vidar, LummaC2, StealC, RedLine and other infostealers In the email, which is also being sent out to other compromised account holders, Anthropic says its investigation is ongoing, but computers were likely already infected with general-purpose infostealer malware. \"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,\" the company stressed. According to Anthropic, the malware typically arrives through downloads or malicious apps and steals information stored locally, including browser passwords, login cookies, and credentials belonging to other apps. \"Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them,\" Anthropic said. In this case, the Redditor who shared the email confirmed that they downloaded a pirated game, which explains why their system got compromised. Anthropic has identified multiple malware, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs. If you get affected, Claude will revoke compromised sessions and remove saved payment methods to prevent unauthorized purchases. \"Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware,\" Anthropic warned. \"If it's still on your computer, your next login session could be stolen the same way.\" Anthropic has urged affected users to take basic security steps, including changing credentials, revoking other sessions, and removing the malware from the PCs. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Anthropic is cutting Claude Code's current weekly limits by 17%Anthropic confirms Claude is down in major outage affecting multiple servicesHow Anthropic plans to watermark Claude's AI-generated textAI 'watermark removers' flood the web. Almost none can prove they work.Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fartificial-intelligence\u002Fanthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F02\u002F13\u002FClaude_chats.jpg","2026-08-30T14:30:25+00:00","2026-08-30T16:00:09.747366+00:00",7,[18,21],{"name":19,"type":20},"Claude","product",{"name":22,"type":23},"Anthropic","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":26,"name":27,"slug":28},null,"Malware","malware",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,51,53,55,57,59],{"type":28,"value":49,"context":50},"Vidar","Infostealer malware identified by Anthropic",{"type":28,"value":52,"context":50},"LummaC2",{"type":28,"value":54,"context":50},"StealC",{"type":28,"value":56,"context":50},"RedLine",{"type":28,"value":58,"context":50},"Acreed",{"type":28,"value":60,"context":61},"Atomic Stealer (AMOS)","Infostealer malware identified by Anthropic on Macs"]