Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2604+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Infostealers Are Hijacking Stolen Claude Sessions to Drain Usage
Infostealers Are Hijacking Stolen Claude Sessions to Drain Usage
NEWS

Infostealers Are Hijacking Stolen Claude Sessions to Drain Usage

Anthropic warns that common infostealer malware is stealing active Claude login sessions from infected PCs and Macs to drain usage and payment methods.

Dylan H.

News Desk

August 30, 2026
5 min read

What Happened

Anthropic has warned a subset of Claude users that widely circulating infostealer malware has been harvesting their active Claude login sessions directly from infected computers, and that attackers have now begun using those stolen sessions to log in as the victim and drain their account usage. The company identified several common infostealer families behind the activity — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on macOS. Anthropic said: "It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them."


Incident Details

AttributeValue
VectorCommodity infostealer malware on victims' own devices
Malware FamiliesVidar, LummaC2, StealC, RedLine, Acreed (Windows); Atomic Stealer / AMOS (macOS)
What Was StolenActive Claude login sessions, browser passwords/cookies, credentials for other apps, stored payment methods
Distribution MethodPirated software downloads and malicious applications
Anthropic's ResponseRevoked compromised sessions, removed saved payment methods, issued refunds, notified affected users

How It Works

Infostealers Don't Attack Claude — They Attack the Device

Infostealer malware is designed to sweep an infected machine for anything of value: saved browser passwords, cryptocurrency wallet files, and — critically — authenticated session tokens and cookies sitting in the browser. Because a signed-in Claude session already carries a valid authentication token, an attacker who steals that token can act as the logged-in user without needing the password or a second factor — normal login protections never come into play.

From Bulk Collection to Targeted Abuse

Infostealer logs are typically harvested in bulk and traded or dumped by criminal groups with little immediate discrimination about what's inside. Anthropic's disclosure indicates that a threat actor has since gone back through previously collected logs specifically to extract and reuse the Claude session tokens, turning passive data theft into active account abuse — including running up usage on the AI service and, in some cases, charging saved payment methods.

How Victims Noticed

Anthropic pointed to a specific symptom affected users should watch for: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause." One affected user confirmed their infection traced back to a pirated video game download, consistent with infostealers' most common distribution channel.

Not a Claude Vulnerability

Anthropic was explicit that this is not a flaw in Claude itself: "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." The compromise originates entirely from malware already present on the user's device, capturing whatever authenticated sessions happen to be active in the browser — Claude included.


Impact Assessment

Impact AreaDescription
Account AbuseAttackers consumed victims' Claude usage allowances using hijacked sessions
Financial ExposureStored payment methods on affected accounts were at risk of unauthorized charges
Broader CompromiseInfostealers that captured Claude sessions typically also captured passwords and cookies for other services on the same device
Detection DifficultySession-token theft bypasses password and two-factor authentication checks entirely, leaving no failed-login trail

Recommendations

For Affected or Potentially Affected Users

  • If usage appears to drain without corresponding activity, treat it as a probable sign of session hijacking and act immediately.
  • Run a full malware/antivirus scan and remove any identified infostealer before doing anything else — resetting credentials on an infected machine will just have them stolen again.
  • Change your Claude password and any reused passwords on other services from a clean device.
  • Revoke active sessions on Claude and any other accounts that may have been accessed from the infected device.
  • Review payment methods on file for unauthorized charges and remove saved cards if in doubt.

For Organizations

  • Reinforce policies against installing pirated software or unverified applications on any device used to access corporate or paid SaaS accounts, including AI tools.
  • Consider session-anomaly monitoring (impossible-travel logins, unusual usage spikes) for accounts tied to paid AI services, which are increasingly valuable targets for credential and session theft.

Key Takeaways

  1. Commodity infostealers — Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer — are stealing active Claude browser sessions from infected devices.
  2. Stolen session tokens let attackers act as the logged-in user, bypassing passwords and two-factor authentication entirely.
  3. A threat actor has begun actively reusing previously harvested Claude sessions to drain usage limits and, in some cases, attempt unauthorized charges.
  4. The most common infection vector reported was pirated software downloads, not any weakness in Claude itself.
  5. Anthropic has revoked affected sessions, removed saved payment methods, and issued refunds to impacted users.
  6. Users should watch for usage that refills and drains unexpectedly, scan for malware, and rotate credentials from a clean device if affected.

Sources

  • BleepingComputer — Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
#Anthropic#Claude#Infostealer#Account Security#Malware

Related Articles

Claude Fable 5 Isn't Permanently Leaving Subscriptions, Anthropic Says

Anthropic confirms Claude Fable 5 will leave Pro, Max, and Team subscription plans on July 7, shifting to usage credits priced at $10/M input and $50/M...

3 min read

Claude Code Leak Used to Push Infostealer Malware on GitHub

Threat actors are capitalising on the Claude Code source code leak by creating fake GitHub repositories that impersonate the leaked source to deliver...

6 min read

Critical Vulnerability in Claude Code Emerges Days After

Adversa AI has discovered a critical vulnerability in Anthropic's Claude Code AI coding assistant, disclosed just days after Anthropic accidentally leaked...

5 min read
Back to all News