Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage
Anthropic disclosed that commodity infostealer malware including Vidar, LummaC2, StealC, RedLine, Acreed, and AMOS have been hijacking Claude session cookies from compromised machines to drain paid subscriptions without needing passwords or multi-factor authentication. The attackers exploit stolen authentication cookies that bypass login credentials entirely, targeting AI assistant accounts as a commodity worth stealing alongside traditional streaming and gaming services. Anthropic is signing affected users out, removing saved payment methods, and refunding unauthorized charges, while warning that the infections stem from common vectors like pirated software rather than vulnerabilities in Claude itself.
Boston Scientific engaged CrowdStrike and additional forensic partners to investigate a cyberattack that disrupted its global network operations. The medical device manufacturer continues recovery efforts following the incident.
Infostealers are actively targeting Claude sessions to bypass authentication and consume paid subscriptions without requiring passwords, exploiting stolen session tokens to drain user accounts. Anthropic has confirmed the threat and is revoking compromised sessions while processing refunds for unauthorized usage. The vulnerability demonstrates how session hijacking through infostealer malware can circumvent traditional security measures like two-factor authentication.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]
A new ClickFix variant called TerminalFix deceives users by displaying fake Cloudflare CAPTCHAs to trick them into executing malicious commands in Windows Terminal or PowerShell. This approach represents an evolution of traditional ClickFix tactics, leveraging the command-line interface to increase the success rate of deploying a reverse-tunnel backdoor. Microsoft has disclosed technical details about this campaign, highlighting the growing sophistication of social engineering attacks targeting Windows users.