Anthropic Signs Claude Users Out After Infostealer Malware Steals Login Sessions and Drains AI Usage

The CyberSec Guru

Claude Infostealer Malware Attack

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

Anthropic is warning some Claude users that attackers used stolen, already-logged-in browser sessions, lifted by infostealer malware, to access their accounts. In response, the company has been forcibly signing affected users out, stripping saved payment methods, and refunding charges it believes were unauthorized.

What makes this notable: the attackers didn’t need a user’s Claude password or a way past two-factor authentication. Infostealer malware copied authentication data already sitting on compromised computers and browsers, including active Claude sessions. Anyone holding a usable authenticated session can act as the account owner without going through a normal login.

Anthropic sent the warning directly to affected users. According to the notification reviewed by BleepingComputer, the company said its systems detected suspicious activity and that someone had been using stolen Claude sessions to access accounts and burn through their usage.

What happened to Claude users?

Anthropic’s notification says the company found a campaign in which an attacker used common infostealer malware to lift Claude login sessions from infected computers, then used those sessions to access accounts and consume their usage.

For affected accounts, Anthropic terminated the compromised sessions and removed the payment method on file, aiming to stop the stolen session from working and to prevent further charges.

The notification also explains a symptom that could otherwise look confusing: a user’s usage limit refilling and then draining quickly even though they aren’t actively using Claude. Anthropic says that pattern can indicate someone else is riding on a stolen session.

Anthropic isn’t describing this as a breach of its own infrastructure. What the evidence points to instead is endpoint compromise: malware on a user’s own machine stole authentication data that was then used against Claude. Anthropic told affected users it had no reason to believe the malware was related to Claude, installed through Claude, or caused by anything they did while using Claude.

The malware families Anthropic identified

Per the notification and multiple reports, Anthropic has linked several infostealer families to the campaign.

PlatformInfostealer families identified
WindowsVidar
WindowsLumma / LummaC2
WindowsStealC
WindowsRedLine
WindowsAcreed
macOSAtomic Stealer (AMOS)

Anthropic says the investigation is ongoing. Vidar, LummaC2, StealC, RedLine, and Acreed turned up on Windows systems; Atomic Stealer, also called AMOS, showed up on a small number of Macs.

None of these are Claude-specific. They’re general-purpose infostealers built to pull valuable data off compromised machines, including saved passwords, browser cookies, authentication tokens, and credentials for other applications, depending on the malware and browser involved.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

Session theft here doesn’t mean Claude itself installed anything malicious.

How an infostealer can hijack a Claude account without stealing the password

The core of this incident is session hijacking.

When you sign into a web app, your browser holds onto authentication data so you don’t have to re-enter your password on every page. An infostealer running locally can pull that browser data off the machine, including session cookies or other authentication artifacts.

If an attacker gets a still-valid session, they can often replay it from another machine entirely. They aren’t cracking a password; they’re reusing an already-authenticated state.

That’s why two-factor authentication doesn’t automatically block this kind of theft. MFA makes it much harder to log in fresh with a stolen password, but if an attacker grabs a session after the real user has already cleared MFA, they can often reuse it without triggering a new authentication challenge. BleepingComputer makes the same point: stolen authenticated browser sessions can let attackers skip the normal password-and-2FA flow entirely.

A simplified version of the attack chain:

Malicious download → infostealer infection → browser data theft → Claude session theft → session replay → unauthorized Claude usage

The security boundary here isn’t just the login page. The endpoint holding the authenticated session matters just as much.

Why attackers are targeting AI account sessions

This incident also points to a shift in what credential theft is worth.

Infostealers have traditionally been valuable for harvesting banking credentials, email accounts, crypto wallets, browser passwords, and corporate logins. AI accounts add something new to that list: compute.

A compromised Claude account hands an attacker paid usage, subscription allowances, or other account capabilities they’d otherwise have to pay for themselves. Anthropic’s warning specifically says the attacker was using stolen sessions to burn through account usage.

For a victim, this can look at first like a billing glitch rather than a malware infection. Signs to watch for:

  • Usage disappearing faster than expected
  • Usage limits refilling, then draining again
  • Activity showing up while you’re not using Claude
  • Charges you don’t recognize
  • Getting logged out of multiple devices unexpectedly
  • A saved payment method vanishing
  • Repeated prompts to sign back in

None of these prove malware on their own, but combined with a security notification from Anthropic, they’re reason enough to treat the machine as potentially compromised.

Anthropic removed saved cards to stop further abuse

Anthropic went beyond just killing sessions.

The notification says the company removed the saved payment method from affected accounts so it couldn’t be charged through Claude again. Existing subscriptions stay active through the period already paid for, but users need to re-add a payment method to renew or buy anything further.

Anthropic also says it has refunded charges it identified as unauthorized. Anyone who still sees a charge they don’t recognize after that should contact support.

This is a reasonable incident-response move: revoking sessions cuts off the stolen access, and pulling the stored card limits the financial damage if an attacker keeps trying. But these are account-side fixes, not endpoint remediation, and that distinction matters.

Signing out does not remove the malware

Anthropic is explicit that signing a user out doesn’t remove the infostealer from their computer. If the malware is still running, the next Claude session created on that machine can just get stolen again.

So this sequence doesn’t work: log out, log back in on the same infected machine, assume it’s fixed. The malware can simply grab the new session too.

Anthropic recommends removing the malware first, then securing the email account tied to Claude along with any other exposed credentials.

What Claude users should do if they receive this warning

Treat this notification as an endpoint-security incident, not just an account logout.

1. Stop using the suspected computer for sensitive logins

Don’t sign back into Claude, email, banking, or anything else important from a machine that might still be infected. Entering fresh credentials on an infected system just gives the malware more to steal.

2. Scan and clean the affected device

Anthropic recommends scanning any computer used with Claude and removing malware before going back to normal use, and points to standard malware-removal guidance for Windows and macOS.

For individuals, an up-to-date security tool plus an offline or recovery-environment scan usually does it. Organizations should treat this as an endpoint compromise and run it through their EDR and incident-response process. If the infection looks serious or persistent, rebuilding the machine from a known-good image is often safer than trusting a deleted file to mean the system is clean.

3. Secure the email account tied to Claude

Once the machine is clean, change the password on the email account you use with Claude. Anthropic also recommends signing out other sessions and turning on two-factor authentication for that email account.

Email deserves extra attention here because a compromised inbox gives attackers password-reset and account-recovery access that goes well beyond Claude.

4. Change any other credentials that may have been exposed

Infostealers aren’t picky. If the malware had access to a browser profile with saved passwords or cookies, other accounts may be exposed too. Prioritize:

  • Email accounts
  • Password managers
  • Banking and financial accounts
  • Cloud platforms
  • Work accounts
  • Developer accounts
  • GitHub and source-control accounts
  • Cryptocurrency wallets
  • Social media accounts
  • Other AI services

Change passwords after the machine is clean, not while an infostealer might still be running.

5. Review financial activity

Check your card and bank statements for anything you don’t recognize. Anthropic says it’s refunding charges it identifies as unauthorized, but it’s still worth checking statements yourself and contacting your bank if something looks of.

6. Revoke sessions and tokens where it applies

Anyone using Claude through developer tooling should think beyond the consumer web session. If an infected machine had API keys, developer credentials, or other secrets on it, rotate or revoke those too. An infostealer’s reach usually extends well past one application.

Why this incident matters beyond Claude

The immediate incident is about Claude, but the underlying problem is bigger than that.

Authentication today leans heavily on persistent sessions, browser tokens, and device state. Once an attacker controls an authenticated endpoint, they often don’t need the password at all. That makes session theft a real problem even where MFA is strong.

It also explains why AI services have become a target. An AI account isn’t just a place to chat with a model anymore. Depending on setup, it can hold private conversations, uploaded documents, project data, developer credentials, paid usage, and access to other tools.

For businesses, the stakes are higher. A compromised employee account could expose confidential prompts and documents, burn through organizational usage, or give an attacker a way into connected development workflows. If that same employee has API keys or other secrets on the infected machine, the Claude session is only part of the problem.

Protecting an account means protecting the device and session used to access it, not just the login page.

This is an endpoint compromise, not evidence of a Claude malware infection

One detail in Anthropic’s warning is easy to misread: Anthropic isn’t saying Claude distributed the malware.

The company’s current read is that affected computers were already infected with general-purpose infostealers, which then scooped up Claude sessions along with whatever else was sitting on the machine.

So, this isn’t evidence that installing or using Claude infected anyone’s machine. The likely entry point is an untrusted download or a malicious app. One affected user’s case reportedly involved a pirated game download, though that’s a single data point, not proof that piracy explains every affected account.

That tracks with how infostealers usually spread: disguised as legitimate software, cracked programs, games, or other downloads people are willing to install themselves.

The bigger lesson: MFA is necessary, but session security still matters

It would be wrong to read this incident as proof that two-factor authentication doesn’t work. MFA is still one of the best defenses against stolen passwords.

The narrower lesson is that MFA can’t retroactively protect authentication data that’s already been stolen off a compromised machine. That means layered defenses still matter: strong authentication, endpoint protection, good credential hygiene, session revocation, least-privilege access, secret rotation, and monitoring, together rather than any one on its own.

For high-value accounts, phishing-resistant authentication cuts down some categories of credential theft, and endpoint detection and response helps catch the malware doing the actual stealing.

This incident is a good example of how identity security and endpoint security overlap. An attacker doesn’t always need to break into the cloud service itself. Sometimes compromising the browser session is enough.

What Anthropic’s response tells us

Anthropic’s handling of this is a decent example of cloud-side containment: detect abnormal behavior, identify the affected accounts, revoke the stolen sessions, pull the stored payment methods, and refund unauthorized charges.

The more important part of the warning is that the endpoint still needs cleaning. Account recovery and malware removal are two separate jobs. Reset the account without cleaning the machine, and you risk reinfection. Clean the machine without rotating exposed credentials, and old stolen credentials are still usable. Doing both is the only way to actually close the loop.

Bottom line

Anthropic is warning a subset of Claude users that infostealer malware compromised their computers and stole active Claude login sessions, which were then used to burn through account usage.

The malware families identified so far: Vidar, Lumma/LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs.

Anthropic’s response has been to revoke the affected sessions, remove saved payment methods, and refund charges it identifies as unauthorized.

For users, the important part isn’t the account fix, it’s not logging straight back in. If Anthropic tells you your session was stolen, assume the machine you used to access Claude may be compromised. Clean it and investigate it first, then rotate exposed credentials and secure the accounts tied to it before creating a fresh session.

A stolen live session can be nearly as useful to an attacker as a stolen password, and often easier to get.

Anthropic’s investigation is ongoing, so the list of affected malware families and the scope of the campaign may change as it learns more.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading