AI

Infostealer Malware Is Hijacking Paid Claude Sessions

Anthropic warns that Vidar, LummaC2 and other infostealers are stealing Claude session cookies, bypassing passwords, 2FA and SSO. The cleanup order matters.

Muhammet Fatih BatmanAugust 31, 20263 min read3 views
Infostealer Malware Is Hijacking Paid Claude Sessions

Your Claude account can be hijacked without your password ever leaking, and Anthropic says it is happening right now. The company is warning that infostealer malware on users' computers is lifting Claude session cookies out of browsers and handing working, logged-in sessions to strangers.

The named culprits are familiar to anyone who follows cybercrime: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on macOS.

Cookies beat passwords

A session cookie is the small record that tells a website you have already signed in. Steal it, and you skip the password, the two-factor prompt and even corporate single sign-on. That last part deserves emphasis for IT teams: an account behind SSO can be taken over without a single event appearing in the identity system.

Infostealers are not new; they have spent years harvesting banking, email and social media credentials, selling the results in bulk. What is new is the target list. A Claude account with an unused monthly limit inside it is now a sellable asset, and Anthropic noticed the trade exactly that way: accounts whose limits were draining while their owners were idle turned out, on inspection, to be running someone else's workloads.

What Anthropic is doing, and where that stops

The company is logging affected users out, removing saved payment methods and refunding unauthorized charges. It is also candid about the limits of that response: as long as the malware remains on the machine, the next session can be stolen the same way. Changing your password without cleaning the device fixes nothing, because the password was never the thing that was taken.

The refunds are the right gesture. But the summary is uncomfortable: the vendor absorbs the cost while the root cause sits on the user's laptop.

The part that lands on businesses

AI subscriptions have quietly become corporate assets. A hijacked session is not just lost quota; it is a door into chat history, projects and every tool connected to the account. And a stealer that grabs one cookie grabs them all, so the same package likely includes the victim's banking and email sessions too.

  • Keep pirated software, cracks and unvetted browser extensions off any machine that signs in to AI tools for work; these remain the main infection paths.
  • If you suspect a theft, clean the device first, then revoke all sessions, then change the password. Doing it in the reverse order wastes the effort.
  • Review usage graphs on team accounts weekly. A limit that drains at 3 a.m. on a quiet Sunday is your earliest warning signal.

Sources: BleepingComputer

Share This Article

Muhammet Fatih Batman

Written by

Muhammet Fatih Batman

Founder & Editor

Founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk