Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS
Anthropic force-revokes Claude sessions hijacked by infostealer-harvested cookies, bypassing password and 2FA entirely
Analysis
Anthropic sent emails to affected users last week, according to Help Net Security's 2026-08-31 report, to say a threat actor had stolen active Claude (claude.ai) login sessions using general-purpose infostealer malware already resident on those users' machines, then replayed the stolen session cookies to access the accounts and consume paid usage (Help Net Security, 2026-08-31; Anthropic, via BleepingComputer, 2026-08-30). Anthropic names the malware families involved as Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs (Anthropic, via Help Net Security, 2026-08-31); all commodity infostealers whose logs are traded on criminal markets. Anthropic states the infection vector is unrelated to Claude itself, typically an unofficial download or a malicious app; the case that surfaced publicly traced to a pirated-game download (BleepingComputer, 2026-08-30).
Because a stolen browser session cookie authenticates as an already-logged-in user, the attacker bypasses password and two-factor authentication entirely; Dark Reading frames the incident as part of a broader shift, as stronger password policies and wider MFA adoption make traditional credential theft harder, toward attackers targeting session cookies and tokens to hijack already-authenticated sessions instead (Dark Reading, 2026-08-31). Anthropic's remediation was to invalidate the stolen sessions, strip saved payment methods from affected accounts, and refund unauthorized charges; it explicitly warns that signing a user out does not remove the infostealer itself, so an unremediated host will have its next session stolen the same way (Anthropic, via BleepingComputer, 2026-08-30).
Triage: the discriminating signal Anthropic itself points users to is a usage allotment that "refilled and then drained" while the subscriber was not using Claude (Anthropic, via BleepingComputer, 2026-08-30). A legitimate usage spike correlates with the account owner's own activity; a drained allotment with no corresponding use by the account owner is the anomaly infostealer-driven session replay produces.
Cited evidence
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage
Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware,
If it's still on your computer, your next login session could be stolen the same way.
The malware identified in this campaign so far include Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs
If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause,
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.