A widespread cyber threat has emerged, targeting users of the popular AI platform Claude. Infostealer malware, which typically infects computers through downloads or malicious apps, is hijacking active Claude sessions to drain usage limits and consume account resources. The affected accounts are being signed out, payment methods removed, and unauthorized charges refunded by the company.
The malicious software, linked to various infostealers including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, as well as Atomic Stealer (AMOS) on Macs, steals sensitive information stored locally such as browser passwords, login cookies, and credentials belonging to other apps. This compromised data is then exploited by attackers to access Claude accounts without needing to navigate the normal password and 2FA login process.
Anthropic has confirmed that its investigation into this incident is ongoing, but early findings suggest that the malware was likely present on users’ computers before accessing their Claude sessions. The company has reassured affected users that it does not believe the malware is related to Claude or installed through any action taken by users.
Infostealer malware operates by collecting and storing sensitive information, including login credentials for various apps and services. This data can then be sold or used for malicious activities such as identity theft or financial fraud. In this case, attackers are using the stolen Claude sessions to drain usage limits and consume account resources, which may not be immediately apparent due to the way some security measures work.
Once an attacker has valid credentials, only a small percentage of their actions are blocked by traditional security defenses. The Blue Report 2026 highlights the effectiveness of various defense techniques in preventing attacks, but notes that once attackers have access, prevention rates drop significantly. This underscores the importance of taking proactive steps to protect against such threats.
To mitigate this risk, affected users are advised to change their credentials and revoke other sessions to protect personal information. Additionally, users should take basic security actions such as running regular antivirus scans, keeping software up-to-date, and avoiding suspicious downloads or apps.
Ultimately, this incident serves as a reminder of the importance of robust cybersecurity measures in protecting against sophisticated threats. As AI-powered tools like Claude become increasingly prevalent, it is crucial that users remain vigilant and take proactive steps to safeguard their online presence.
Source: Bleeping Computer — 2026-08-30