Infostealer Malware Hijacks Claude User Sessions via Stolen Credentials
Attackers deployed well-known infostealer malware families (Vidar, Lumma, StealC, RedLine, and others) on end-user devices, harvesting session tokens and credentials that allowed them to impersonate legitimate Claude users. The root problem is a combination of poor user security hygiene — downloading software from unofficial sources — and insufficient session-level controls that failed to detect anomalous reuse of stolen tokens. This matters because session hijacking bypasses password and even MFA protections entirely, giving attackers full account access including saved payment methods. Anthropic's response of force-logging sessions and removing payment data is appropriate containment, but the damage window between infection and detection remains a significant risk.
Tactical Insight
Immediate actions
- Run a full endpoint malware scan using an up-to-date EDR/antivirus solution on any device used to access Claude or other SaaS platforms.
- Revoke and rotate all active session tokens and saved payment methods on accounts suspected of compromise.
- Enable multi-factor authentication (MFA) on all accounts to add a second layer beyond session tokens.
Long-term improvements
- Enforce an organizational policy prohibiting software downloads from unofficial or unverified sources, and use application allowlisting where possible.
- Implement continuous session anomaly detection (e.g., impossible travel, new device fingerprints) to automatically invalidate suspicious sessions.
- Adopt a password manager and enforce unique credentials per service to limit credential-reuse blast radius.
Detection measures
- Subscribe to threat intelligence feeds that track infostealer campaigns and indicators of compromise (IOCs) for families like Lumma and RedLine.
- Monitor endpoint logs for processes associated with credential harvesting (e.g., accessing browser credential stores or keychain APIs).
- Establish user notification workflows so affected individuals are alerted quickly when anomalous login activity is detected.