Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Scheduled Pinned Locked Moved Malware Analysis
1 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Anthropic has issued a warning to a subset of Claude users that infostealer malware on their systems has been used to steal active login sessions for the AI assistant. Rather than compromising accounts through stolen passwords, these attackers are hijacking the existing session tokens, which allows them to authenticate as the legitimate user without triggering a standard login prompt.

    The result is that victims’ accounts are being accessed and drained by the attackers, consuming their allocated usage. This type of attack affects the convenience of persistent login sessions, as the stolen tokens bypass the usual re-authentication requirements. The warning highlights that the compromise originates from the user’s device being infected, rather than a breach on Anthropic’s side.

    For users concerned about exposure, the primary advice is to ensure that the endpoint is clean before taking further action. Recommended steps include:

    • Run a full anti-malware scan on the affected device to identify and remove the infostealer.
    • After the system is verified clean, log out of all active sessions on the Claude account to invalidate any stolen session tokens.
    • Change the account password and enable two-factor authentication (2FA) if not already active.

    Likely indicators that a session has been compromised include unexpected usage spikes or changes to account settings that the user did not make. While the article does not identify the specific infostealer family or assign a CVE, the core lesson is that session tokens are a valuable target and that endpoint security is a critical component of protecting AI account usage.

    Source: Unknown

    Is your organization auditing for unusual usage spikes in AI assistant accounts as a potential early-warning sign of session hijacking?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World