Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Infostealer Malware Hijacks Claude Sessions, Draining User Usage

Anthropic reports that infostealer malware on users' PCs stole active Claude login sessions, allowing attackers to consume paid usage. The incident highlights the need for robust session management and rapid revocation controls for audit readiness.

LiveThreat™ Intelligence · 📅 August 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
bleepingcomputer.com

Infostealer Malware Hijacks Claude Sessions, Draining User Usage

What Happened — Anthropic disclosed that infostealer malware on users’ PCs has stolen active Claude login sessions. Attackers reuse the stolen browser cookies to access accounts and consume paid usage without the legitimate user’s knowledge. Anthropic is revoking compromised sessions, removing saved payment methods, and refunding unauthorized charges.

Why It Matters for Trust & Control Assurance

  • Session‑hijacking illustrates a gap in credential‑and‑session protection that a continuous control‑assurance program should detect and remediate.
  • Demonstrates the need for real‑time monitoring of authentication artifacts (cookies, tokens) and rapid revocation workflows.
  • Aligns with the Identity and Access Management – Session Management control objective, which underpins many frameworks (e.g., NIST CSF 2.0).

Who Is Affected – SaaS AI providers and their enterprise customers (technology, finance, media, etc.) that rely on Claude for business‑critical workloads.

Recommended Actions

  • Enforce MFA and regularly rotate session tokens; implement short‑lived tokens where possible.
  • Deploy endpoint protection that detects and blocks known infostealer families (Vidar, LummaC2, StealC, RedLine, AMOS).
  • Integrate automated session‑revocation and payment‑method removal into your incident‑response playbook.

Source: BleepingComputer

Technical Notes

  • Attack vector: Windows/macOS infostealer malware harvesting browser cookies and saved credentials.
  • Malware families observed: Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer (AMOS).
  • No vulnerability in Claude itself; the compromise originates from the user’s endpoint.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →