Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain Usage — Threadlinqs Intelligence
As of 2026-08-31, Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain Usage is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-2255 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Anthropic disclosed that commodity infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; Atomic Stealer/AMOS on macOS) already resident on some users' devices is harvesting Claude
On August 30-31, 2026, Anthropic notified affected users that commodity infostealer malware already present on their devices had harvested saved passwords, browser login cookies, and locally stored application credentials, including active Claude session cookies. Because these tools steal already-authenticated session cookies rather than passwords, the theft bypasses two-factor authentication and single sign-on entirely: attackers replay the stolen session to impersonate an already-logged-in user without ever supplying credentials. Anthropic said it detected the pattern after noticing usage limits that appeared to refill and then drain while account owners were inactive. The malware families named -- Vidar, LummaC2 (Lumma Stealer), StealC, RedLine Stealer, and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs -- are general-purpose, financially motivated commodity stealers unrelated to Claude itself and typically arrive via unofficial downloads or malicious apps, not through any vulnerability in Claude. Anthropic's response was to sign out compromised sessions, remove saved payment methods from affected accounts, refund unauthorized charges, and warn that further misuse could trigger additional sign-outs; the company stressed that signing a user out stops the stolen session but does not remove the malware from the device.
Technically, this class of malware is well documented in MITRE ATT&CK: Lumma Stealer (S1213) and RedLine Stealer (S1240) both implement T1539 (Steal Web Session Cookie) and T1555.003 (Credentials from Web Browsers) as their core credential-theft techniques, alongside T1082 (System Information Discovery), T1005/T1113 (local data and screen collection), T1071.001 (web-protocol C2), T1041 (exfiltration over the C2 channel), and, for RedLine specifically, T1657 (Financial Theft) -- directly matching the usage-draining and payment-method-abuse pattern Anthropic observed. Both families also support T1204.002 (User Execution: Malicious File) as their infection vector and T1027/T1553.002 (packing and code-signing abuse) for defense evasion, consistent with delivery via unofficial or trojanized installers.
A directly Claude-branded campaign in the same threat window corroborates and extends this pattern: Huntress documented "FakeAgent," a malvertising operation active July 21-22, 2026, in which Bing search ads for "Claude Desktop app" redirected victims through claude.ai.download-app.us and downloading-api.it.com to a trojanized ClaudeDesktop.exe. That installer was in fact a repurposed, legitimate JetBrains JCEF helper binary abused to sideload a malicious libcef.dll (T1574.002), which persisted via a scheduled task disguised as DockerDesktop.exe (T1053.005) and ultimately decrypted an embedded, VMProtect-packed SectopRAT payload using a GPU-shader-based AES-256-CTR routine -- a technique that doubles as anti-sandbox evasion (T1497.001), since the decryption also checks for QEMU/VMware GPU signatures and low VRAM. SectopRAT is an HVNC-capable .NET RAT that gives attackers persistent remote access to browser passwords, cookies, credit-card data, and corporate files; its command-and-control used both conventional IPs and an EtherHiding-style scheme that staged payloads via BSC smart-contract transactions. Huntress observed at least 29 organizations compromised and roughly 7,100 downloads of the malicious Claude Artifact before Anthropic removed it; operator infrastructure for this cluster had been tracked since May 30, 2025, including a prior, technique-identical Docker Hub malvertising campaign in April 2026. SectopRAT is a distinct malware family from the six stealers named in Anthropic's own advisory, but it produces the same outcome -- stolen Claude sessions and credentials -- and confirms that attackers are deliberately targeting Claude's install/download surface, not just opportunistically harvesting sessions from generically infected machines.
The macOS side of the campaign (Atomic Steal
Target sectors: technology, software development, general consumer individual users
Target regions: Global
Timeline
- Global law-enforcement operation seizes 2,300+ LummaC2 domains (per CISA advisory AA25-141B), disrupting the then-dominant infostealer family.
- Huntress later attributes the operator infrastructure behind the FakeAgent/SectopRAT campaign to activity tracked back to this date, predating the Claude-branded lure by over a year.
- Atomic Stealer (AMOS) campaign observed impersonating the OpenClaw AI-agent platform via a fake "Clearly AI" app (clearl.co, Cleal_AI.dmg), illustrating AMOS's pattern of targeting AI-tool users specifically.
- A technique-identical malvertising campaign abuses Docker Hub with the same libcef.dll sideloading method later reused against Claude Desktop, per Huntress.
- The malicious domain claude.ai.download-app.us, used to redirect victims to the trojanized ClaudeDesktop.exe installer, is registered.
- Atomic Stealer (AMOS) adds hardware-wallet trojanization and hidden LaunchDaemon persistence, per a Brinztech breach alert.
- Huntress detects the start of the FakeAgent campaign: Bing search ads for "Claude Desktop app" begin redirecting victims to a fake, malicious installer that deploys SectopRAT via DLL sideloading.
- FakeAgent campaign window closes after compromising at least 29 organizations and accumulating roughly 7,100 downloads of the malicious Claude Artifact; Anthropic removes the artifact.
- Anthropic begins notifying users that commodity infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) harvested Claude session cookies, and starts signing out compromised sessions, removing saved payment methods, and issuing refunds.
- SecurityWeek, BleepingComputer, Help Net Security, and other outlets independently corroborate and detail Anthropic's infostealer disclosure.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1566, T1195, T1204, T1574, T1053, T1027, T1036, T1553, T1497, T1140