Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage — Threadlinqs Intelligence
As of 2026-08-30, Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-2234 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Anthropic is warning Claude users that commodity infostealer malware (Vidar, LummaC2, StealC, RedLine, and Acreed on Windows; Atomic Stealer/AMOS on a small number of Macs) is stealing authenticated
Anthropic disclosed on August 30, 2026 that a general-purpose infostealer campaign is harvesting authenticated Claude.ai browser sessions alongside the passwords, cookies, and credentials for every other site stored on a victim's compromised computer. Because a stolen session cookie lets an attacker act as the logged-in user without needing the account password or defeating two-factor authentication, victims saw their usage limits refill and then silently drain, and in some cases had payment methods charged without their activity. Anthropic's account of the campaign names five Windows-targeting stealer families -- Vidar, LummaC2 (Lumma Stealer), StealC, RedLine Stealer, and Acreed -- plus Atomic Stealer (AMOS) affecting a small number of Macs. None of these are bespoke tools built to target Claude specifically; they are commodity malware-as-a-service (MaaS) infostealers whose operators indiscriminately harvest every browser session and credential store on an infected machine and sell the resulting 'stealer logs' on marketplaces such as Russian Market. One confirmed infection vector cited in reporting was a pirated video game, consistent with these families' typical distribution through cracked-software sites, malvertising, and ClickFix-style fake-CAPTCHA / paste-and-run social engineering rather than any Claude-branded lure.
Each named family has well-documented session/credential-theft tradecraft. Vidar (active since 2018, a fork of the Arkei stealer, now rewritten in multithreaded C) defeats both legacy DPAPI browser-credential protection and Chrome/Edge's newer App-Bound Encryption by cloning the running browser process via NtCreateProcessEx and injecting an APC to invoke CryptUnprotectMemory from inside the browser's own address space, then exfiltrates cookies, passwords, autofill, and crypto-wallet data over HTTP multipart POST to C2 infrastructure resolved through Telegram and Steam Community profile dead drops. StealC, a $200/month C++ MaaS platform, was recently upgraded to a 64-bit build with an RC4-encrypted JSON C2 protocol, multi-monitor screenshot capture, and enhanced browser session-restoration-file theft; it is frequently delivered via ClickFix lures that trick a user into pasting a PowerShell download-and-execute command into the Windows Run dialog, and self-terminates on CIS-region system locales. RedLine Stealer, MaaS since 2020, ships as an encrypted .NET assembly that process-hollows into a legitimate process and harvests browser cookies/credentials for resale, though its core infrastructure (two domains, three C2 servers) was seized in the October 2024 'Operation Magnus' law-enforcement action alongside its META Stealer clone. LummaC2/Lumma Stealer dominated the stealer-log market (roughly 92% of Russian Market logs in Q4 2024) before a May 2025 Microsoft/FBI/Europol takedown seized 2,300+ domains; it has since rebuilt C2 infrastructure and resurged through 2026 via new loaders and a March 2026 Windows Terminal-based delivery variant. Acreed, first observed by researchers in February 2025, filled the vacuum left by Lumma's takedown and by mid-2025 had surpassed RedLine, Raccoon, StealC, and Vidar as the leading stealer strain feeding Russian Market, with reporting noting it specifically targets SaaS and SSO credentials -- the same session-based access model Claude uses. Atomic Stealer (AMOS), the macOS family named in this campaign, is optimized to pull Keychain data, browser credentials/cookies/autofill, and crypto-wallet artifacts, and in 2026 has been distributed chiefly through ClickFix campaigns that trick users into pasting a Terminal command that silently downloads, mounts, and launches a malicious DMG.
Anthropic's remediation for affected accounts includes proactively revoking the stolen sessions, removing saved payment methods, issuing refunds for unauthorized charges, and emailing notified users -- while explicitly warning that signing a user out only stops the specific stolen session and does
Target sectors: technology, professionalandtechnicalservices
Timeline
- Vidar Stealer first observed on Russian-language underground forums as a fork of the Arkei stealer codebase.
- RedLine Stealer first observed in the wild, spread via a COVID-19-themed email campaign; later sold as MaaS for $100/week to $800/lifetime.
- Operation Magnus: Dutch police, FBI, and Eurojust seize RedLine Stealer and META Stealer domains and C2 servers; DOJ charges alleged RedLine developer Maxim Rudometov.
- Acreed infostealer first observed by researchers at Webz.io, uploading over 4,000 stealer logs within its first week of operation.
- Global law-enforcement operation led by Microsoft DCU, FBI, and Europol dismantles LummaC2/Lumma Stealer core infrastructure, seizing more than 2,300 domains.
- Trend Micro reports LummaC2 rebuilding operations with stealthier delivery methods (GitHub abuse, fake CAPTCHA sites) weeks after the takedown.
- Acreed surpasses RedLine, Raccoon, StealC, and Vidar to become the leading infostealer strain in Russian Market credential logs, filling the vacuum left by LummaC2's takedown.
- Bitdefender confirms LummaC2 has rebuilt command-and-control infrastructure and resumed active worldwide spread.
- Microsoft discloses a new Windows Terminal-based LummaC2 delivery variant.
- Researchers identify 56 additional samples of a new multithreaded Vidar Stealer variant rewritten in pure C.
- Microsoft's Digital Crimes Unit, with Europol, disrupts more than 200 StealC and Amadey C2 domains and IPs (Operation Endgame follow-on action).
- Anthropic discloses the campaign, confirming Vidar, LummaC2, StealC, RedLine, and Acreed on Windows plus Atomic Stealer (AMOS) on a small number of Macs are hijacking authenticated Claude sessions; begins revoking sessions, removing payment methods, issuing refunds, and notifying affected users.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1204.002, T1204.004, T1059.001, T1027, T1685, T1553.002, T1036.005, T1055.004, T1497.001, T1539