Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent Malvertising Campaign Deploys SectopRAT via Trojanized Claude Desktop Installer

Infostealer Malware Hijacks Claude Login Sessions to Bypass (TL-2026-2249), also tracked as FakeAgent Campaign, is a high-severity malware campaign, first published 2026-08-30. It has no confirmed attribution, affects Anthropic Claude.ai web sessions / Claude Desktop application, maps to 13 MITRE ATT&CK techniques (T1027, T1036.005, T1053.005), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2249

Threat ID
TL-2026-2249
Also known as
FakeAgent Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-30
Last reviewed
2026-08-30
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
26

Malware and tooling in Infostealer Malware Hijacks Claude Login Sessions to Bypass

Malware and tooling: Acreed, Atomic Stealer (AMOS), LummaC2, RedLine, RedLine Stealer - S1240, SectopRAT, Stealc, Vidar, EtherHiding, VMProtect

Anthropic is warning users that Windows/macOS infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) are harvesting authenticated Claude session cookies and replaying them to hijack accounts without needing passwords or MFA, draining usage quotas. A related but distinct malvertising campaign, "FakeAgent," used malicious Bing ads and a public Claude Artifact hosted on claude.ai to distribute a trojanized ClaudeDesktop.exe that DLL-sideloads a VMProtect-packed libcef.dll to deploy the SectopRAT (Arechclient2) .NET RAT, compromising at least 29 organizations in a two-day window.

How Infostealer Malware Hijacks Claude Login Sessions to Bypass works

Two distinct but related attack chains against Claude users surfaced in August 2026. First, Anthropic identified that commodity infostealer malware families — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on macOS — are routinely harvesting browser-saved passwords, autofill data, and authenticated session cookies from already-infected endpoints. Because Claude session cookies represent an already-authenticated session, an attacker who copies and replays them gains direct account access without triggering password or MFA/SSO checks. Anthropic detected the abuse via usage-pattern anomalies (usage limits appearing to refill and then drain while the legitimate owner was inactive) and is remediating by force-signing-out affected sessions, stripping saved payment methods, and refunding unauthorized charges — while cautioning that these account-side fixes do not remove the malware from the victim's device, so a fresh session can be stolen again on next login. A newer persistence variant layered on top of this abuses poisoned SKILL.md files (Claude's agent-skill configuration/documentation files): attackers disguise hidden commands as ordinary style-guide notes, and when Claude loads the tainted file it silently re-downloads the infostealer, letting the compromise survive even a full OS reinstall if the tainted file is reintroduced.

Second, and separately, Huntress's SOC identified a malvertising campaign it dubbed "FakeAgent." Victims searching for the Claude desktop app on Bing were redirected through sponsored ads to a malicious public Claude Artifact hosted on the legitimate claude.ai domain, masquerading as an official installer download page. The page accumulated roughly 7,100 views/downloads before Anthropic removed it. The delivered binary, ClaudeDesktop.exe, was actually a repurposed, legitimately signed JetBrains JCEF helper binary (jcef_helper.exe) vulnerable to DLL side-loading; placed alongside it was a tampered, VMProtect-packed libcef.dll that retrieves further C2 configuration data via blockchain transactions on Ethereum/BNB Smart Chain (the "EtherHiding" technique) rather than a fixed domain. A second stage abused a legitimately signed IBM SPSS binary (renamed sslconf.exe) side-loading a malicious tempdir.dll, which decrypts the final SectopRAT payload using a custom AES-256-CTR routine executed via a DirectX SM5 shader on the GPU (evading CPU-based crypto API hooks) and performs anti-VM checks (DXGI adapter vendor ID / VRAM enumeration, shader timing) before establishing persistence via a scheduled task and reaching out to C2 infrastructure. SectopRAT (aka Arechclient2), a .NET RAT active since 2019, harvests browser logins, cookies, autofill data, stored credit cards, Chromium encryption keys, FTP credentials, and Discord/messaging-app data, and can spawn a hidden secondary desktop to manipulate browser sessions directly. Huntress attributed the campaign to a threat actor previously observed running an April 2026 Docker Hub malvertising campaign (fake DockerDesktop.exe) using the identical libcef.dll side-loading tactic, and found the domain-registration email tied to at least 10 malware-distribution domains since December 2025, one of which (polse.us, a StealC host) was seized by Microsoft as part of Operation Endgame.

MITRE ATT&CK techniques used in TL-2026-2249

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task

Command and Control

T1102.001 Web Service: Dead Drop Resolver; T1573.001 Encrypted Channel: Symmetric Cryptography

Execution

T1204.002 User Execution: Malicious File

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Resource Development

T1583.008 Acquire Infrastructure: Malvertising; T1608.001 Stage Capabilities: Upload Malware

Affected products and versions in Infostealer Malware Hijacks Claude Login Sessions to Bypass

  • Anthropic — Claude.ai web sessions / Claude Desktop application
    Vulnerable versions: any endpoint with locally cached/stolen Claude session cookies; Claude Desktop obtained from unofficial/malvertised sources (Windows)

Remediation for Infostealer Malware Hijacks Claude Login Sessions to Bypass

Immediate actions

  • Anthropic is proactively force-signing-out sessions matching known-compromised device/behavioral patterns, stripping saved payment methods, and issuing refunds for unauthorized usage
  • Run a full antivirus/EDR scan and reimage any endpoint suspected of infostealer infection before re-authenticating to Claude; signing out alone does not remove device-resident malware
  • Rotate all credentials and clear browser-saved passwords/cookies on any machine showing usage-quota refill-then-drain anomalies
  • Locate and remove the scheduled task named 'MicrosoftEdgeUpdate' (/sc onlogon /rl highest) and files under %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install\ or AppData\Roaming\EdgeUpdate-* if present
  • Audit any Claude agent SKILL.md files for injected/hidden instructions before allowing Claude to load them again

Workarounds

  • Restrict or disable the use of publicly-shared Claude Artifacts as a software-distribution channel within the organization
  • Block known malicious infrastructure at the perimeter: claude.ai.download-app.us, downloading-api.it.com, 5ca8758c-02d0-4a72-89c8-d468b66dda41.com, and 2.24.131.246

Longer-term hardening

  • Only obtain Claude Desktop from the official claude.ai/download page or an Anthropic-signed installer; never via search-ad links or third-party/public Artifact pages
  • Enforce short session lifetimes and device/IP binding for high-value SaaS and AI-platform accounts to reduce the value of a stolen session cookie
  • Deploy EDR detections for DLL side-loading from non-standard directories alongside signed JetBrains (jcef_helper.exe) or IBM SPSS binaries
  • Establish integrity monitoring/version control review for locally stored agent-skill configuration files (SKILL.md) so injected instructions are caught before Claude loads them

Timeline of Infostealer Malware Hijacks Claude Login Sessions to Bypass

  • Acreed infostealer first observed on the Russian Market dark-web forum, later rising to dominance after the May 2026 Lumma takedown.
  • The same threat actor behind FakeAgent runs an earlier malvertising campaign distributing a fake DockerDesktop.exe using the identical libcef.dll DLL side-loading tactic, per Huntress infrastructure analysis.
  • The malicious lookalike domain claude.ai.download-app.us is registered, later used to host/redirect the FakeAgent payload delivery chain.
  • Huntress SOC detects unusual ClaudeDesktop.exe installs, Microsoft Defender exclusions, and anomalous persistence across customer environments, marking the start of the FakeAgent campaign.
  • Anthropic removes the malicious public Claude Artifact page from claude.ai that had been used to distribute the trojanized installer.
  • Huntress confirms at least 29 organizations compromised over the two-day window; the malicious public Claude Artifact page had accumulated roughly 7,100 views/downloads.
  • Anthropic responds by force-signing-out compromised sessions, removing saved payment methods, and issuing refunds for unauthorized charges, while noting the fixes do not remove malware from infected devices.
  • Anthropic begins notifying users that infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; Atomic Stealer on macOS) has been harvesting Claude session cookies to hijack accounts and drain usage without triggering MFA/SSO.

Sources cited for Infostealer Malware Hijacks Claude Login Sessions to Bypass

More in malware

Detection coverage for TL-2026-2249

As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2249 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats