Interestana
Home/News/Anthropic Warns Infostealer Malware Hijacking Claude Sessions
BleepingComputer2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Anthropic Warns Infostealer Malware Hijacking Claude Sessions

Anthropic has issued a critical warning to some of its users, alerting them to a sophisticated threat where infostealer malware, residing on their personal computers, is actively hijacking active Claude login sessions. This malicious activity allows unauthorized attackers to gain access to user accounts and subsequently consume their allocated Claude usage, potentially leading to significant disruption and unauthorized resource depletion. The company detailed this emerging threat in a security advisory, emphasizing the need for users to take immediate protective measures.

This type of attack exploits vulnerabilities in how session tokens are stored and managed by web browsers and applications. Infostealer malware is designed to scan a user's system for sensitive information, including stored credentials and active session cookies. When such malware successfully identifies an active Claude session cookie, it can transmit this information to attackers, enabling them to impersonate the legitimate user without needing to know their password. The consequence is that attackers can then interact with the Claude service as if they were the actual user, initiating queries, generating content, and thereby depleting the user's available usage quotas. This poses a direct financial risk to users who pay for their Claude access, as well as a security risk due to the potential for unauthorized data access or generation.

Anthropic has advised affected users to immediately revoke any suspicious active sessions within their Claude account settings and to perform thorough scans of their personal computers for malware. The company also recommends implementing robust cybersecurity practices, such as using strong, unique passwords for all online accounts, enabling multi-factor authentication wherever possible, and being vigilant about phishing attempts or suspicious downloads that could lead to malware infection. Furthermore, keeping operating systems and antivirus software up-to-date is crucial for defending against known threats. The company stated that it is actively monitoring the situation and working to enhance its security protocols to better detect and prevent such session hijacking incidents in the future, though specific technical details of these enhancements were not disclosed. The advisory did not specify the exact number of users affected or the geographic regions where this activity has been most prevalent, but it stressed that any user could be a target if their system is compromised by infostealer malware.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next