Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has begun locking Claude users out of their accounts after detecting compromised login sessions caused by infostealer malware infections on users' devices. The campaign leverages multiple infostealers including Vidar, Lumma, StealC, RedLine, and Acreed on Windows systems, as well as Atomic Stealer on a limited number of Macs, with these general-purpose malware typically arriving through unofficial downloads or malicious applications. Affected users received notification emails explaining the account lockouts as a protective measure against the credential theft campaign.
Boston Scientific engaged CrowdStrike and additional forensic partners to investigate a cyberattack that disrupted its global network operations. The medical device manufacturer continues recovery efforts following the incident.
Anthropic disclosed that commodity infostealer malware including Vidar, LummaC2, StealC, RedLine, Acreed, and AMOS have been hijacking Claude session cookies from compromised machines to drain paid subscriptions without needing passwords or multi-factor authentication. The attackers exploit stolen authentication cookies that bypass login credentials entirely, targeting AI assistant accounts as a commodity worth stealing alongside traditional streaming and gaming services. Anthropic is signing affected users out, removing saved payment methods, and refunding unauthorized charges, while warning that the infections stem from common vectors like pirated software rather than vulnerabilities in Claude itself.
Threat actors are distributing ValleyRAT, a backdoor malware, disguised as legitimate adware to evade detection and infiltrate systems. Kaspersky researchers have analyzed the complete infection chain, detailing how the malicious installer executes and delivers the final payload. This deceptive distribution method highlights the importance of scrutinizing software sources and installation processes to prevent backdoor infections.
Infostealers are actively targeting Claude sessions to bypass authentication and consume paid subscriptions without requiring passwords, exploiting stolen session tokens to drain user accounts. Anthropic has confirmed the threat and is revoking compromised sessions while processing refunds for unauthorized usage. The vulnerability demonstrates how session hijacking through infostealer malware can circumvent traditional security measures like two-factor authentication.