Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methods — Threadlinqs Intelligence
As of 2026-08-31, Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methods is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 8 indicators of compromise.
Threat ID: TL-2026-2257 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Anthropic disclosed that commodity infostealer malware (Vidar, LummaC2, StealC, RedLine, and Acreed on Windows; Atomic Stealer/AMOS on a small number of Macs) is harvesting authenticated Claude
Beginning around August 30, 2026, Anthropic notified a subset of Claude users that commodity infostealer malware already resident on their personal machines had exfiltrated their authenticated Claude browser session cookies alongside other locally stored browser credentials, and that a threat actor had subsequently begun using those stolen sessions to access victims' Claude accounts, consume paid usage quota, and attempt to use stored payment methods. Anthropic named five Windows-targeting stealer families -- Vidar, LummaC2 (Lumma Stealer), StealC, RedLine (RedLine Stealer), and Acreed -- plus Atomic Stealer (AMOS) affecting a small number of Macs. All are mature, actively maintained malware-as-a-service (MaaS) infostealer families sold on Russian-language cybercriminal forums and dark-web marketplaces; none were purpose-built against Claude or Anthropic, and Anthropic explicitly stated it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything the victim did within Claude.
The underlying technique is session-cookie theft rather than password theft: because these infostealers copy already-authenticated browser session state (cookies, in some cases local tokens for cloud SaaS platforms) rather than only capturing typed credentials, an attacker who replays the stolen session is treated by the target service as the already-logged-in, already-2FA/SSO-verified user. This sidesteps password resets and MFA/SSO checks entirely, since those controls only gate the *establishment* of a session, not its subsequent reuse. Anthropic's own account of the detection notes it identified the pattern by observing usage limits that appeared to refill and then drain while the legitimate account owner was inactive -- an anomaly consistent with an attacker periodically returning to consume quota on hijacked accounts.
Infection in the documented cases reported alongside this disclosure was consumer-grade and opportunistic: a BleepingComputer-sourced case involved a pirated video game installer, and a separately reported case involved pirated software downloaded from a Russian-language underground forum; in the latter case, standard Windows Defender antivirus did not flag the malware. This matches the well-documented distribution tradecraft of these specific malware families, which are commonly bundled into cracked/pirated software, fake cracks and key generators, and malvertising campaigns impersonating legitimate downloads. Once resident, these stealers (per public technical analyses of the specifically named families) harvest browser-stored passwords, autofill data, and session cookies via direct access to browser credential/cookie stores (invoking Windows DPAPI/CryptUnprotectData or Firefox NSS3 decryption, or, on macOS, reading Keychain and Safari's Cookies.binarycookies), stage the harvested data locally, and exfiltrate it over HTTP(S) to attacker-controlled C2 infrastructure -- with at least one of the named families (Vidar) documented using Telegram and Steam profile pages as C2 dead-drops. The Acreed family in particular has been documented specifically targeting active session/access tokens for major cloud SaaS platforms (Microsoft 365, Google Workspace, AWS, Azure, Salesforce) to bypass MFA on enterprise identity providers, which is consistent with the same tradecraft being pointed at Claude sessions here.
Anthropic's remediation for affected accounts consisted of forcibly signing out compromised sessions, removing saved payment methods, and refunding usage charges it identified as unauthorized. Anthropic explicitly cautioned that signing a user out stops further abuse of that specific stolen session but does not remove the malware itself from the victim's machine, and directed affected users to run a full malware scan, reset their Claude password and linked email password (enabling 2FA), review payment statements, and revoke other active sessions before resuming use. Coverage of the disclo
Target sectors: cross-sector opportunistic individual end users and employees
Target regions: Global
Timeline
- LummaC2 (Lumma Stealer) first appears for sale as a subscription malware-as-a-service infostealer on Russian-language cybercriminal forums (exact date within 2022 not published).
- Acreed infostealer is first detected in the wild, later rising to replace LummaC2 as a dominant credential-theft tool on dark-web marketplaces such as Russian Market.
- A global law enforcement operation takes down LummaC2 infrastructure, seizing over 2,300 domains, accelerating criminal migration to successor stealers including Acreed (May 2025).
- Anthropic identifies an anomalous usage pattern -- Claude usage limits appearing to refill and then drain while account owners are inactive -- and traces it to hijacked sessions stolen by commodity infostealer malware.
- Anthropic begins emailing affected Claude users, signing out compromised sessions, removing saved payment methods from affected accounts, and refunding charges it identifies as unauthorized.
- BleepingComputer publishes the first widely-cited report on the campaign, naming Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer as the malware families involved.
- Security Affairs publishes independent corroborating coverage of Anthropic's disclosure and the named infostealer families.
- Help Net Security, TheCyberExpress, CyberSecurityNews, and SearchEngineJournal publish further corroborating coverage, adding Anthropic's direct quotes and the enterprise IAM-gap analysis.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 8 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1204.002, T1555.003, T1539, T1528, T1550.004, T1027, T1036, T1055.012, T1497.001, T1217