Skip to content
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
Subscribe
Close

Search

nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Anthropic warns infostealer malware is hijacking Claude user sessions
cybersecurity

Anthropic warns infostealer malware is hijacking Claude user sessions

By abde el aziz
August 30, 2026 2 Min Read
0

Anthropic is warning users that Claude infostealer malware has compromised some accounts by stealing active login sessions directly from infected computers. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges as part of its response.

Table of Contents

  • How systems got infected and what Anthropic found
  • What users need to do now

In an email shared on Reddit, Anthropic explained the attack vector: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” If your usage limits appeared to refill and drain while you weren’t actively using Claude, this was likely the cause.

Anthropic warns infostealer malware is hijacking Claude user sessions

The threat works because infostealers can copy an already authenticated browser session, bypassing the need for attackers to enter passwords or pass two-factor authentication checks. Claude infostealer malware operates as a general-purpose tool—it collects many things from a compromised system, and attackers have now begun extracting Claude sessions from that haul to gain account access.

How systems got infected and what Anthropic found

Anthropic stressed that the malware is not related to Claude itself, was not installed through Claude, and resulted from nothing users did with the service. One affected user who shared the warning confirmed they had downloaded a pirated game, which explains the initial compromise. The company’s investigation identified multiple strains of Claude infostealer malware on Windows systems, including Vidar, LummaC2, StealC, RedLine, and Acreed, along with Atomic Stealer (AMOS) on a small number of Macs.

As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted how attackers exploit valid credentials once they gain initial access—a pattern that mirrors what’s happening here. Similarly, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how threat actors weaponize stolen session data to compromise user accounts across services.

What users need to do now

Revoking compromised sessions stops the stolen sessions from working, but it does not remove the underlying malware from your computer. If the infection remains, your next login session could be stolen the same way. Anthropic urges affected users to change credentials, revoke other active sessions, and remove the malware from their systems using security tools. Taking these basic security steps is essential to prevent re-compromise after signing back into Claude.

المصدر: BleepingComputer

Author

abde el aziz

Follow Me
Other Articles
Malicious Chrome and Edge extensions found stealing crypto and browser data
Previous

Malicious Chrome and Edge extensions found stealing crypto and browser data

NASA Launches Nancy Grace Roman Telescope to Map the Dark Universe
Next

NASA Launches Nancy Grace Roman Telescope to Map the Dark Universe

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • Apple rolls out iOS 27 with Siri AI beta
  • Is the GTA 6 Ultimate Edition worth the extra cost?
  • Apple CEO discusses why iPhone Duo foldable arrived after Android rivals
  • Google launches Gemini app for Windows

Recent Comments

  1. New BambooToken Malware Uses MQTT to Control Windows and Linux Systems on CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks
  2. Apple rolls out iOS 27 with Siri AI beta on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  3. Is the GTA 6 Ultimate Edition worth the extra cost? on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  4. Apple CEO discusses why iPhone Duo foldable arrived after Android rivals on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  5. Google launches Gemini app for Windows on Google AI Mode adds flight price tracking and hotel booking tools

Archives

  • September 2026
  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme