Anthropic Warns Infostealer Malware Hijacking Claude Sessions

Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Table of Contents
    Add a header to begin generating the table of contents

    Anthropic issued a security alert on August 30 that infostealer malware families—including Vidar, Lumma, StealC, and RedLine on Windows, and Atomic Stealer (AMOS) on macOS—are compromising active Claude login sessions by stealing browser cookies and saved credentials, enabling attackers to access user accounts and consume credits without authorization. The company is signing out compromised sessions, removing saved payment methods to prevent unauthorized charges, and issuing refunds for identified fraudulent usage after users noticed their usage limits mysteriously refilling and draining without active use.

    Vidar, Lumma, StealC, RedLine, and Atomic Stealer Targeting Claude Browser Cookies and Saved Credentials

    The attack method relies on infostealer malware that “quietly copies saved passwords, browser login cookies, and credentials for other local applications” from infected devices. Threat actors then use the stolen Claude session tokens to access accounts and consume user credits, often running sustained usage that drains limits and triggers automatic refills tied to saved payment methods. Users reported noticing their usage limits refilling and draining without any active Claude use, which Anthropic confirmed as a pattern of unauthorized consumption driven by stolen session credentials.

    The infostealer malware families involved—Vidar, Lumma, StealC, and RedLine on Windows, and Atomic Stealer (AMOS) on macOS—are commodity credential-harvesting tools widely distributed through phishing emails, malicious downloads, and software cracks. These infostealers operate silently in the background, extracting browser cookies, saved passwords, cryptocurrency wallet data, and application credentials without triggering antivirus alerts in many cases. The stolen session tokens give attackers access to active Claude sessions without needing to know the user’s password, bypassing two-factor authentication if the user’s browser session was already authenticated.

    Users Noticed Usage Limits Mysteriously Refilling and Draining Without Active Claude Use

    Users noticed their usage limits mysteriously refilling and draining without any active Claude use, prompting them to contact Anthropic about the anomalous activity. This pattern indicated that attackers were not just accessing accounts—they were actively consuming credits by running sustained Claude queries, likely to monetize access by reselling Claude services or using the credits for their own projects. The automatic refills tied to saved payment methods meant attackers could drain users’ credits repeatedly, triggering new charges each time the usage limit reset.

    Anthropic’s Response: Forced Logouts, Payment Method Removal, and Fraudulent Usage Refunds

    Anthropic’s response includes signing out compromised sessions, removing saved payment methods to prevent unauthorized charges, and issuing refunds for confirmed fraudulent usage. The company warned it may sign users out again if further misuse is detected. Anthropic emphasized that attackers sourced credentials from general malware infections on user devices rather than exploiting Claude-specific vulnerabilities, and users should only re-add payment methods after completely removing malware from their systems.

    The decision to remove saved payment methods from compromised accounts prevents attackers from running up additional charges before users notice the fraud, but it also forces legitimate users to re-authenticate and re-enter payment information after cleaning their infected devices. Anthropic’s statement that it has no indication the stolen credentials came from Claude-specific vulnerabilities places remediation responsibility on users to identify and remove the underlying infostealer infections before resuming normal Claude usage with payment methods restored.

    Growing Attacker Interest in AI Platform Credentials for Credit Abuse and API Monetization

    The session hijacking campaign demonstrates increasing attacker interest in AI platform credentials for credit abuse and potential API abuse. Infostealer malware families like Vidar, Lumma, StealC, RedLine, and AMOS are commodity tools widely deployed for credential harvesting, but their use against AI platform sessions marks an emerging threat vector as attackers recognize the value of compromised AI service accounts. The ability to consume credits fraudulently or resell access to premium AI services creates a monetization path for stolen credentials beyond traditional banking or cryptocurrency theft.

    Anthropic’s proactive session termination and payment method removal reflects the company’s awareness that compromised AI accounts can generate significant unauthorized charges in a short time. The refunds issued for fraudulent usage indicate Anthropic is absorbing the cost of the credential theft rather than holding users responsible for charges incurred through stolen sessions, a policy decision that protects users but creates financial exposure for the company as long as infostealer malware continues targeting Claude sessions.

    Related Posts