Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Summary
Anthropic warned in late August 2026 that infostealer malware is being used to hijack active Claude AI sessions, allowing attackers to drain victims' paid usage and access data held in the account. The company identified several well-known infostealer families โ including Vidar, LummaC2, StealC, RedLine and AMOS โ as vehicles for the abuse.
Details
The attack does not require the victim's Claude password. Infostealer malware that has already compromised a machine captures authentication tokens and active session cookies, which the attacker replays to take over the logged-in session in the browser. From there the operator can consume the victim's subscription quota, run prompts, and read or exfiltrate conversation data the account can access. The technique is a straightforward extension of the session-token theft long used against banking and email accounts, now pointed at AI assistants that hold valuable paid capacity and sensitive conversational context.
Assessment
Anthropic's warning highlights the growing value of AI session tokens as a target for commodity infostealer operations, and it underlines the importance of credential and session hygiene on devices that run AI assistants. Users should review and terminate active sessions, enable multi-factor authentication, and treat AI accounts like any other privileged service. Infostealer infection is often the root cause, so remediating the underlying malware is the primary defence. No Australian-specific impact has been reported.