cd /news/ai-products/anthropic-warns-claude-users-of-info… · home topics ai-products article
[ARTICLE · art-116531] src=cryptobriefing.com ↗ pub= topic=ai-products verified=true sentiment=↓ negative

Anthropic warns Claude users of infostealer malware infections that hijacked active sessions

Anthropic began contacting affected Claude users on August 30, 2026, after discovering that infostealer malware had compromised their computers and stolen active login session cookies, allowing attackers to hijack accounts and run up paid usage quotas. The company forcibly signed out all compromised sessions, removed saved payment methods, and issued refunds for unauthorized charges, clarifying that the infections originated from malicious downloads and compromised software, not from Claude's infrastructure. The malware families involved included Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, with a limited number of Mac devices affected by Atomic Stealer (AMOS).

read2 min views2 publishedAug 31, 2026
Anthropic warns Claude users of infostealer malware infections that hijacked active sessions
Image: Cryptobriefing (auto-discovered)

Photo: Merlin Lightpainting / Pexels

The AI company began contacting affected users after detecting unusual usage patterns tied to stolen browser cookies across multiple malware families.

Anthropic started reaching out to impacted Claude users on August 30, 2026, after discovering that infostealer malware had compromised their computers and siphoned off active login session cookies. The stolen cookies gave attackers a backdoor into user accounts, letting them burn through paid usage quotas without ever needing a password or cracking two-factor authentication.

What happened and how Anthropic responded #

The breach came to light through unusual usage patterns on Claude accounts. Once Anthropic’s security team connected the dots, they moved quickly. All compromised sessions were forcibly signed out. Saved payment methods were stripped from affected accounts. And for users who got hit with unauthorized charges from attackers running up their quotas, Anthropic issued refunds.

Anthropic was also careful to draw a clear line: the malware had nothing to do with Claude itself, its infrastructure, or anything users did on the platform. The infections originated from malicious downloads and compromised software applications that users had installed on their own machines.

The malware families identified in the campaign included Vidar, LummaC2, StealC, RedLine, and Acreed on Windows. A limited number of Mac devices were also affected, primarily through Atomic Stealer, also known as AMOS.

Why infostealers are targeting AI accounts #

The infostealer families involved in this campaign are well-established tools in the cybercrime ecosystem. RedLine has been one of the most widely distributed infostealers for years, while LummaC2 has surged in popularity among threat actors for its ability to harvest browser data, crypto wallet credentials, and session tokens. Vidar and StealC operate on similar principles, scraping stored credentials and cookies from browsers. Atomic Stealer has carved out a niche as one of the more capable macOS-focused threats.

The common thread across all of these tools is their focus on browser session cookies. Modern web applications keep users logged in through session tokens stored as cookies. Steal the cookie, and you inherit the session. No password prompt, no 2FA challenge, no suspicious login alert. From the server’s perspective, the attacker looks identical to the legitimate user.

This session-hijacking campaign is distinct from other security concerns that surfaced around AI platforms in 2026. Earlier in the year, separate reports documented attackers misusing Claude’s own features or orchestrating phishing campaigns designed to deliver malware. Anthropic’s latest advisory is specifically focused on the session-hijacking aspect rather than the methods of initial infection.

Some security-conscious users have started adopting browser-level protections like Google Chrome’s Device Bound Session Credentials, which ties session cookies to a specific device and makes them useless if exfiltrated.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-products 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-warns-clau…] indexed:0 read:2min 2026-08-31 ·