Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage

Commodity Infostealers Hijacking Claude Login Sessions to (TL-2026-2234) is a medium-severity malware campaign, first published 2026-08-30. It has no confirmed attribution, affects Anthropic Claude.ai web application login sessions, maps to 17 MITRE ATT&CK techniques (T1027, T1036.005, T1055.004), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2234

Threat ID
TL-2026-2234
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-08-30
Last reviewed
2026-08-30
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, professionalandtechnicalservices
Detection rules
9
Indicators of compromise
12

Malware and tooling in Commodity Infostealers Hijacking Claude Login Sessions to

Malware and tooling: AMOS, Acreed, Atomic Stealer (AMOS), Lumma Stealer - S1213, LummaC2, RedLine Stealer - S1240, Stealc, Vidar, StealC RC4-encrypted JSON C2 protocol, Steam Community profile dead-drop resolver, Telegram profile dead-drop resolver

Anthropic is warning Claude users that commodity infostealer malware (Vidar, LummaC2, StealC, RedLine, and Acreed on Windows; Atomic Stealer/AMOS on a small number of Macs) is stealing authenticated Claude browser login sessions from compromised computers, letting attackers reuse the sessions to access victims' accounts and consume their usage/API credits without needing a password or bypassing MFA.

How Commodity Infostealers Hijacking Claude Login Sessions to works

Anthropic disclosed on August 30, 2026 that a general-purpose infostealer campaign is harvesting authenticated Claude.ai browser sessions alongside the passwords, cookies, and credentials for every other site stored on a victim's compromised computer. Because a stolen session cookie lets an attacker act as the logged-in user without needing the account password or defeating two-factor authentication, victims saw their usage limits refill and then silently drain, and in some cases had payment methods charged without their activity. Anthropic's account of the campaign names five Windows-targeting stealer families -- Vidar, LummaC2 (Lumma Stealer), StealC, RedLine Stealer, and Acreed -- plus Atomic Stealer (AMOS) affecting a small number of Macs. None of these are bespoke tools built to target Claude specifically; they are commodity malware-as-a-service (MaaS) infostealers whose operators indiscriminately harvest every browser session and credential store on an infected machine and sell the resulting 'stealer logs' on marketplaces such as Russian Market. One confirmed infection vector cited in reporting was a pirated video game, consistent with these families' typical distribution through cracked-software sites, malvertising, and ClickFix-style fake-CAPTCHA / paste-and-run social engineering rather than any Claude-branded lure.

Each named family has well-documented session/credential-theft tradecraft. Vidar (active since 2018, a fork of the Arkei stealer, now rewritten in multithreaded C) defeats both legacy DPAPI browser-credential protection and Chrome/Edge's newer App-Bound Encryption by cloning the running browser process via NtCreateProcessEx and injecting an APC to invoke CryptUnprotectMemory from inside the browser's own address space, then exfiltrates cookies, passwords, autofill, and crypto-wallet data over HTTP multipart POST to C2 infrastructure resolved through Telegram and Steam Community profile dead drops. StealC, a $200/month C++ MaaS platform, was recently upgraded to a 64-bit build with an RC4-encrypted JSON C2 protocol, multi-monitor screenshot capture, and enhanced browser session-restoration-file theft; it is frequently delivered via ClickFix lures that trick a user into pasting a PowerShell download-and-execute command into the Windows Run dialog, and self-terminates on CIS-region system locales. RedLine Stealer, MaaS since 2020, ships as an encrypted .NET assembly that process-hollows into a legitimate process and harvests browser cookies/credentials for resale, though its core infrastructure (two domains, three C2 servers) was seized in the October 2024 'Operation Magnus' law-enforcement action alongside its META Stealer clone. LummaC2/Lumma Stealer dominated the stealer-log market (roughly 92% of Russian Market logs in Q4 2024) before a May 2025 Microsoft/FBI/Europol takedown seized 2,300+ domains; it has since rebuilt C2 infrastructure and resurged through 2026 via new loaders and a March 2026 Windows Terminal-based delivery variant. Acreed, first observed by researchers in February 2025, filled the vacuum left by Lumma's takedown and by mid-2025 had surpassed RedLine, Raccoon, StealC, and Vidar as the leading stealer strain feeding Russian Market, with reporting noting it specifically targets SaaS and SSO credentials -- the same session-based access model Claude uses. Atomic Stealer (AMOS), the macOS family named in this campaign, is optimized to pull Keychain data, browser credentials/cookies/autofill, and crypto-wallet artifacts, and in 2026 has been distributed chiefly through ClickFix campaigns that trick users into pasting a Terminal command that silently downloads, mounts, and launches a malicious DMG.

Anthropic's remediation for affected accounts includes proactively revoking the stolen sessions, removing saved payment methods, issuing refunds for unauthorized charges, and emailing notified users -- while explicitly warning that signing a user out only stops the specific stolen session and does not remove the malware itself, so an un-remediated endpoint will simply have its next login session stolen the same way. This is a credential/session-theft incident, not an exploited software vulnerability in Claude or Anthropic infrastructure; no CVE applies.

MITRE ATT&CK techniques used in TL-2026-2234

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.004 Asynchronous Procedure Call; T1497.001 System Checks

Execution

T1059.001 PowerShell; T1204.002 Malicious File; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver

Discovery

T1082 System Information Discovery; T1614.001 System Language Discovery

Collection

T1113 Screen Capture

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools

Affected products and versions in Commodity Infostealers Hijacking Claude Login Sessions to

  • Anthropic — Claude.ai web application login sessions
    Vulnerable versions: N/A - session/credential theft via endpoint malware, not a software flaw in Claude
    Fixed in: N/A
  • Multiple — Windows endpoints (targeted by Vidar, LummaC2, StealC, RedLine, and Acreed)
    Vulnerable versions: Windows 10; Windows 11
    Fixed in: N/A - malware infection vector, not a patchable vulnerability
  • Apple — macOS endpoints (targeted by Atomic Stealer / AMOS)
    Vulnerable versions: Currently supported macOS releases
    Fixed in: N/A

Remediation for Commodity Infostealers Hijacking Claude Login Sessions to

Immediate actions

  • Run a full reputable anti-malware/EDR scan on the affected endpoint and remove any detected infostealer before logging back into Claude
  • Revoke/invalidate the compromised Claude session and force re-authentication (Anthropic has been proactively doing this for identified affected accounts)
  • Change the Claude account password and the password/credentials of any other site whose session was stored in the same infected browser
  • Remove and re-add payment methods on the account; review recent Claude billing and usage history for unauthorized charges and request refunds where warranted

Workarounds

  • Sign out of all active Claude sessions from account settings and revoke any unrecognized active sessions
  • Avoid downloading pirated/cracked software and cracked games, a confirmed infection vector in at least one reported case in this campaign

Longer-term hardening

  • Enforce phishing-resistant MFA / hardware security keys on Claude and other SaaS accounts to reduce the blast radius of session-cookie replay (note: session-cookie theft bypasses standard 2FA, so hardware-bound or step-up re-authentication is required to meaningfully help)
  • Deploy EDR telemetry that flags non-browser processes reading the browser's Local State / cookie store, cloning a browser process (e.g. via NtCreateProcessEx), or patching AmsiScanBuffer
  • User awareness training on ClickFix / fake-CAPTCHA paste-and-run lures and the risks of pirated or cracked software downloads, both confirmed vectors for the named stealer families
  • Monitor for anomalous Claude session/usage activity (new device or IP continuing an existing session, unexpected usage-limit consumption) as a compromise indicator

Timeline of Commodity Infostealers Hijacking Claude Login Sessions to

  • Vidar Stealer first observed on Russian-language underground forums as a fork of the Arkei stealer codebase.
  • RedLine Stealer first observed in the wild, spread via a COVID-19-themed email campaign; later sold as MaaS for $100/week to $800/lifetime.
  • Operation Magnus: Dutch police, FBI, and Eurojust seize RedLine Stealer and META Stealer domains and C2 servers; DOJ charges alleged RedLine developer Maxim Rudometov.
  • Acreed infostealer first observed by researchers at Webz.io, uploading over 4,000 stealer logs within its first week of operation.
  • Global law-enforcement operation led by Microsoft DCU, FBI, and Europol dismantles LummaC2/Lumma Stealer core infrastructure, seizing more than 2,300 domains.
  • Acreed surpasses RedLine, Raccoon, StealC, and Vidar to become the leading infostealer strain in Russian Market credential logs, filling the vacuum left by LummaC2's takedown.
  • Trend Micro reports LummaC2 rebuilding operations with stealthier delivery methods (GitHub abuse, fake CAPTCHA sites) weeks after the takedown.
  • Bitdefender confirms LummaC2 has rebuilt command-and-control infrastructure and resumed active worldwide spread.
  • Microsoft discloses a new Windows Terminal-based LummaC2 delivery variant.
  • Researchers identify 56 additional samples of a new multithreaded Vidar Stealer variant rewritten in pure C.
  • Microsoft's Digital Crimes Unit, with Europol, disrupts more than 200 StealC and Amadey C2 domains and IPs (Operation Endgame follow-on action).
  • Anthropic discloses the campaign, confirming Vidar, LummaC2, StealC, RedLine, and Acreed on Windows plus Atomic Stealer (AMOS) on a small number of Macs are hijacking authenticated Claude sessions; begins revoking sessions, removing payment methods, issuing refunds, and notifying affected users.

Sources cited for Commodity Infostealers Hijacking Claude Login Sessions to

More in malware

Detection coverage for TL-2026-2234

As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2234 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats