CTIPilot

Claude session-hijacking infostealer campaign

campaign · campaign:claude-session-hijack-infostealers-2026 single-source-victim

Unattributed criminal actor picking stolen Claude (claude.ai) login sessions out of commodity infostealer logs (Vidar, LummaC2, StealC, RedLine, Acreed, AMOS) to hijack accounts and consume paid usage; Anthropic revoked affected sessions and refunded unauthorized charges (Anthropic user notification, relayed by BleepingComputer/Help Net Security/Dark Reading, 2026-08-30/31).

Coverage timeline
1
first 2026-09-01 → last 2026-09-01
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Credential Access TA0006

T1539Steal Web Session Cookie×1

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-09-01/anthropic-claude-session-hijack-infostealers · ATT&CK page ↗

Lateral Movement TA0008

T1550.004Use Alternate Authentication Material: Web Session Cookie×1

Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.

Evidence: 2026-09-01/anthropic-claude-session-hijack-infostealers · ATT&CK page ↗

Story timeline

  1. 2026-09-01Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS
    active-threatsAnthropic force-revokes Claude sessions hijacked by infostealer-harvested cookies, bypassing password and 2FA entirely

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • darkreading.com1 (33%)
  • helpnetsecurity.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Claude session-hijacking infostealer campaign (1)

2026-09-01 · view entry permalink →

NOTABLENATOB2

Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS

Anthropic sent emails to affected users last week, according to Help Net Security's 2026-08-31 report, to say a threat actor had stolen active Claude (claude.ai) login sessions using general-purpose infostealer malware already resident on those users' machines, then replayed the stolen session cookies to access the accounts and consume paid usage (Help Net Security, 2026-08-31; Anthropic, via BleepingComputer, 2026-08-30). Anthropic names the malware families involved as Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs (Anthropic, via Help Net Security, 2026-08-31); all commodity infostealers whose logs are traded on criminal markets. Anthropic states the infection vector is unrelated to Claude itself, typically an unofficial download or a malicious app; the case that surfaced publicly traced to a pirated-game download (BleepingComputer, 2026-08-30).

Because a stolen browser session cookie authenticates as an already-logged-in user, the attacker bypasses password and two-factor authentication entirely; Dark Reading frames the incident as part of a broader shift, as stronger password policies and wider MFA adoption make traditional credential theft harder, toward attackers targeting session cookies and tokens to hijack already-authenticated sessions instead (Dark Reading, 2026-08-31). Anthropic's remediation was to invalidate the stolen sessions, strip saved payment methods from affected accounts, and refund unauthorized charges; it explicitly warns that signing a user out does not remove the infostealer itself, so an unremediated host will have its next session stolen the same way (Anthropic, via BleepingComputer, 2026-08-30).

Triage: the discriminating signal Anthropic itself points users to is a usage allotment that "refilled and then drained" while the subscriber was not using Claude (Anthropic, via BleepingComputer, 2026-08-30). A legitimate usage spike correlates with the account owner's own activity; a drained allotment with no corresponding use by the account owner is the anomaly infostealer-driven session replay produces.

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage

Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware,

If it's still on your computer, your next login session could be stolen the same way.

Anthropic (email to affected users, via BleepingComputer)

The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs

Anthropic (email to affected users, via Help Net Security)

If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause,

Anthropic (email to affected users, via BleepingComputer)
threat01 Sep 04:11Zsingle-source · victim disclosureOpen finding ↗