Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login Sessions

Anthropic Locks Out Claude Users After Commodity (TL-2026-2253) is a medium-severity malware campaign, first published 2026-08-31. It has no confirmed attribution, affects Anthropic Claude (claude.ai account login sessions), maps to 16 MITRE ATT&CK techniques (T1005, T1027.002, T1036), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2253

Threat ID
TL-2026-2253
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-08-31
Last reviewed
2026-08-31
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cross-sector
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Anthropic Locks Out Claude Users After Commodity

Malware and tooling: AMOS, Acreed, Atomic Stealer (AMOS), Lumma Stealer - S1213, LummaC2 (Lumma Stealer), RedLine Stealer - S1240, Stealc, Vidar

Anthropic disclosed on 2026-08-29 that commodity infostealer malware on users' own devices had been stealing Claude browser session cookies and replaying them to bypass 2FA, letting attackers hijack accounts to drain paid usage quotas. Anthropic responded by force-signing-out affected sessions, removing saved payment methods, and refunding unauthorized charges.

How Anthropic Locks Out Claude Users After Commodity works

On 2026-08-29 Anthropic began notifying a subset of Claude users that infostealer malware running on their own computers, not any vulnerability in Claude itself, had stolen active browser session cookies for claude.ai and used them to hijack accounts. Anthropic explained the mechanism plainly: 2FA protects the login event, but once a user authenticates, the site issues a session cookie that keeps the browser signed in; an attacker who exfiltrates and replays that cookie is treated by the application as an already-authenticated user, skipping password and MFA entirely (MITRE T1539 / T1550.004).

Anthropic named the malware families observed in the campaign: on Windows, Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed; on macOS, a small number of cases involving Atomic Stealer (AMOS). All are commodity, malware-as-a-service (MaaS) infostealers sold or rented on Russian-language cybercrime markets, not bespoke tooling built to target Anthropic or Claude specifically. Distribution followed the stealers' typical pattern of unofficial downloads and malicious/pirated applications; Anthropic and press coverage cite at least one affected user who traced their infection to a pirated game downloaded from a Russian-language underground forum.

Because the stolen material is a full authenticated browser session rather than a password, attackers were able to log in as the victim without triggering password-reset or new-device MFA prompts, and used the access to consume the victim's paid Claude usage quota rather than (per Anthropic's public statements) exfiltrating conversation content. Affected users reported usage limits refilling and then draining while they were not using the product themselves — a symptom Anthropic pointed to directly as a hijacking indicator. Some accounts also had unauthorized charges placed against saved payment methods.

Anthropic's incident response consisted of three operational moves: force-invalidating (signing out) all sessions identified as compromised, removing saved payment methods from affected accounts to stop further unauthorized charges, and issuing refunds for charges it identified as unauthorized. Anthropic's guidance to affected users emphasized that revoking the session alone is insufficient — the underlying malware infection must be found and removed, or the same device will simply exfiltrate a fresh session cookie the next time the user logs back in. Recommended remediation also included rotating the email account password (with 2FA enabled), updating any passwords the browser had saved, reviewing card statements, and clearing active sessions on other online services the same device had accessed, since a general-purpose infostealer harvests credentials and cookies for far more than one site at a time.

Acreed's presence on the list is notable in isolation: multiple 2025-2026 threat-intel reports (Bitsight, webz.io) describe Acreed's rapid rise to become one of the leading stealer-log sources on Russian Market and other dark-web marketplaces after a May 2025 law-enforcement disruption of LummaC2's infrastructure displaced Lumma affiliates toward rival services; Acreed research describes it combining C2 channels layered over Steam and the BNB Smart Chain with JSON-based exfiltration and DLL side-loading, and its stolen logs are redistributed through Telegram channels and dark-web stores. This positions the Claude-session campaign as an instance of a much broader, already-tracked commodity infostealer ecosystem rather than a novel or Claude-specific attack technique.

MITRE ATT&CK techniques used in TL-2026-2253

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027.002 Software Packing; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Execution

T1059.003 Windows Command Shell

Command and Control

T1071.001 Web Protocols

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery

execution

T1204.002 Malicious File

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Persistence

T1547.001 Registry Run Keys / Startup Folder

lateral-movement

T1550.004 Web Session Cookie

Impact

T1657 Financial Theft

Affected products and versions in Anthropic Locks Out Claude Users After Commodity

  • Anthropic — Claude (claude.ai account login sessions)
    Vulnerable versions: N/A - authentication/session-cookie design pattern, not a specific software version
    Fixed in: N/A - mitigated operationally via mass session invalidation, payment-method removal, and refunds; no product patch issued

Remediation for Anthropic Locks Out Claude Users After Commodity

Immediate actions

  • Run a full anti-malware/EDR scan on any device used to access Claude before logging back in; do not simply re-authenticate after a forced sign-out
  • Treat a forced Claude sign-out or an Anthropic security notice as a signal that the underlying device, not just the account, is compromised
  • Rotate the Claude account password and the email account password used for recovery, with 2FA enabled on both
  • Update every other password saved in the affected browser, since general-purpose infostealers harvest credentials for all sites, not just Claude
  • Review payment card statements for unauthorized Claude (or other SaaS) charges and report them
  • Clear/revoke active sessions on other online services accessed from the same device, since the same infostealer run likely stole those cookies too

Workarounds

  • Avoid downloading pirated software, cracked games, or unofficial installers, which is the confirmed distribution vector in at least one traced victim case
  • Manually revoke browser sessions across all frequently used services after any suspected malware infection, since a platform-side forced sign-out does not remove the malware or prevent a fresh cookie theft on next login

Longer-term hardening

  • Treat unofficial downloads, pirated software, and cracked-game installers as a primary infostealer distribution vector and block/flag them at the endpoint
  • Deploy EDR detections for browser cookie-store/session-database access by non-browser processes (behavior common to Vidar/Lumma/StealC/RedLine/Acreed/AMOS)
  • Shorten session-cookie lifetimes and require step-up re-authentication for high-risk actions (payment method changes, high-volume API/usage spikes) rather than relying on login-time MFA alone
  • Monitor for anomalous usage/credit consumption patterns (quota refilling/draining without corresponding user activity) as a session-hijacking indicator
  • Consider binding session cookies to device/browser fingerprint or IP-range where feasible to reduce the value of a replayed stolen cookie

Weaknesses (CWE) in Anthropic Locks Out Claude Users After Commodity

CWE-294, CWE-613

Timeline of Anthropic Locks Out Claude Users After Commodity

  • Law-enforcement action disrupted LummaC2's infrastructure in May 2025, displacing Lumma affiliates and reshaping the commodity infostealer market that later produced the malware families named in this campaign.
  • Following the LummaC2 disruption, Acreed stealer logs on prominent Russian dark-web markets surged past 118,000 by June 2025, establishing Acreed as one of the dominant stealer-as-a-service families later observed hijacking Claude sessions.
  • Anthropic removed saved payment methods from affected accounts and began refunding charges it identified as unauthorized.
  • Anthropic force-signed-out affected accounts to invalidate the hijacked sessions.
  • Anthropic began notifying affected users and disclosed that infostealer malware had stolen and replayed Claude browser session cookies to hijack accounts, bypassing 2FA.
  • BleepingComputer reported the incident, detailing that hijacked sessions were primarily used to drain paid usage quotas and quoting Anthropic's usage-refill/drain symptom description.
  • Press coverage documented at least one affected user tracing their infection to a pirated game downloaded from a Russian-language underground forum, illustrating the campaign's commodity, non-targeted distribution vector.
  • Help Net Security published detailed coverage naming the specific malware families (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) and Anthropic's technical explanation of session-cookie-based 2FA bypass.

Sources cited for Anthropic Locks Out Claude Users After Commodity

More in malware

Detection coverage for TL-2026-2253

As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2253 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats