Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI Sessions to Drain Paid Usage
Infostealer Malware (Vidar, LummaC2, StealC, RedLine (TL-2026-2262) is a high-severity malware campaign, first published 2026-08-31. It has no confirmed attribution, affects Anthropic Claude.ai / Claude Desktop (session-cookie-based account, maps to 8 MITRE ATT&CK techniques (T1005, T1078, T1082), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2262
- Threat ID
- TL-2026-2262
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-31
- Last reviewed
- 2026-08-31
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Infostealer Malware (Vidar, LummaC2, StealC, RedLine
Malware and tooling: AMOS, Acreed, Atomic Stealer (AMOS), Lumma Stealer - S1213, LummaC2, RedLine, RedLine Stealer - S1240, Stealc, Vidar, Vidar dead-drop-resolver C2 (social-media-hosted)
Anthropic disclosed that commodity infostealer malware families are harvesting locally stored browser session cookies from compromised Windows and macOS machines, letting attackers replay stolen Claude session tokens to access victim accounts and consume paid usage/API quotas without needing a password or 2FA. Anthropic force-signed-out affected sessions, stripped saved payment methods, and refunded unauthorized charges.
How Infostealer Malware (Vidar, LummaC2, StealC, RedLine works
On 2026-08-30, Anthropic began notifying Claude users that infostealer malware already present on their personal devices had captured active Claude login-session cookies and that attackers were subsequently replaying those cookies to access the victims' accounts and burn through paid usage limits. Because a session cookie represents an already-authenticated state, the technique (MITRE ATT&CK T1539 Steal Web Session Cookie, used in conjunction with T1550.004 Use Alternate Authentication Material: Web Session Cookie) lets an attacker step past both the account password and multi-factor authentication entirely — no credential guessing, phishing of the password, or MFA bypass trick is required. Anthropic named five Windows-targeting infostealer families as responsible — Vidar, LummaC2 (Lumma Stealer), StealC, RedLine, and Acreed — plus Atomic Stealer (AMOS) on a small number of Macs. All six are commodity Malware-as-a-Service (MaaS) products sold/rented on cybercrime forums; none are custom tooling built for this campaign. Anthropic was explicit that this is not a Claude software vulnerability, breach of Anthropic infrastructure, or anything installed through Claude itself — the malware is general-purpose credential/cookie-stealing malware that most commonly arrives bundled with pirated software, cracked games, or other unofficial downloads (one affected user traced their own infection to a pirated game downloaded from a Russian underground forum), and it happened to also scoop up the victim's Claude session cookie along with everything else in the browser's cookie jar. The user-facing symptom Anthropic described as diagnostic is a usage limit that appears to refill and then silently drain while the account owner is not actively using Claude. In response, Anthropic (1) detected the anomalous replay activity, (2) force-signed-out the compromised sessions, (3) removed saved payment methods from affected accounts as a precaution, and (4) refunded charges it identified as unauthorized; existing subscriptions continue through the current billing period, but users must re-verify malware removal from their device before re-adding a payment method. Anthropic stressed that these account-side remediations do not remove the malware from the infected endpoint, and users must run a full anti-malware scan and reset other credentials as well. Reporting also notes phones/tablets were not implicated — the compromise chain requires a malware-infected desktop/laptop browser. Two of the named families illustrate the broader MaaS ecosystem's resilience: RedLine's original C2 infrastructure was disrupted by law-enforcement Operation Magnus in October 2024, and LummaC2's infrastructure was hit by a coordinated law-enforcement/industry takedown in May 2025 — in both cases the platforms were rebuilt or succeeded within weeks/months, with Acreed rapidly rising to become the top contributor of stolen-credential logs on the Russian Market dark-web marketplace in the LummaC2 takedown's aftermath. This demonstrates that disrupting one stealer brand does little to reduce the overall session-hijacking threat to SaaS/AI platforms, since the underlying MaaS supply chain and buyer base persist across rebrands.
MITRE ATT&CK techniques used in TL-2026-2262
Collection
Initial Access
Discovery
T1082 System Information Discovery
Execution
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
lateral-movement
T1550 Use Alternate Authentication Material
Impact
Affected products and versions in Infostealer Malware (Vidar, LummaC2, StealC, RedLine
- Anthropic — Claude.ai / Claude Desktop (session-cookie-based account authentication)
Vulnerable versions: N/A — not a software flaw in Claude; any authenticated Claude session cookie stored in a browser on a malware-infected Windows or macOS endpoint is subject to theft and replay
Fixed in: N/A — mitigated operationally via forced session sign-out, payment-method removal, and refunds; no software patch applies
Remediation for Infostealer Malware (Vidar, LummaC2, StealC, RedLine
Immediate actions
- Run a full anti-malware/EDR scan on any device that accessed Claude before re-adding a payment method or trusting a new session
- Force sign-out of all active Claude sessions and reset the account password
- Re-verify and re-enable 2FA only after confirming the device is clean of infostealer malware
- Review Claude billing/usage history for the 'refill then drain' anomaly and report any unauthorized charges to Anthropic support
- Reset browser-saved passwords and re-issue any credentials/cookies that were stored on the infected machine, not just the Claude session
Workarounds
- Anthropic proactively force-signs-out compromised sessions, strips saved payment methods, and refunds identified unauthorized charges pending user-side malware remediation
Longer-term hardening
- Deploy EDR/behavioral detection for non-browser processes reading browser cookie/credential-store files (T1539 / T1555.003 / T1555.001 telemetry)
- Avoid installing software from pirated/cracked sources, unofficial download sites, and untrusted forums — the primary distribution vector named in this campaign
- Adopt short-lived or step-up-authenticated sessions and anomaly-based session-risk scoring (impossible-travel, device-fingerprint mismatch) for SaaS/AI platform logins
- Educate users that a usage limit which refills and then silently drains without active use is an indicator of session theft, not a billing glitch
- Monitor for stolen-credential-log listings referencing the organization's domains on dark-web marketplaces such as Russian Market
Timeline of Infostealer Malware (Vidar, LummaC2, StealC, RedLine
- Law-enforcement Operation Magnus disrupts the original RedLine Stealer C2 infrastructure; successor RedLine variants continue circulating and are later named by Anthropic in this campaign.
- A coordinated law-enforcement and industry takedown disrupts LummaC2 (Lumma Stealer) infrastructure; the platform is rebuilt within weeks, accelerating the rise of successor stealers including Acreed.
- Acreed becomes the leading infostealer contributing stolen-credential/session logs to the Russian Market dark-web marketplace, uploading over 4,000 logs in its first week of operation.
- Anthropic force-signs-out compromised sessions, removes saved payment methods from affected accounts, and refunds charges it identifies as unauthorized.
- Anthropic begins notifying affected Claude users, via email, that Vidar, LummaC2, StealC, RedLine, and Acreed (Windows) and Atomic Stealer/AMOS (macOS) have been harvesting and replaying Claude session cookies to drain paid usage; BleepingComputer publishes the first press coverage.
- A Reddit user reports using Claude's own Opus model to scan running processes on their infected machine and identify the infostealer, prior to Anthropic's disclosure reaching wide press coverage.
- Affected users publicly trace their own infections to pirated-software downloads (e.g., a pirated game from a Russian underground forum), corroborating Anthropic's statement that the malware arrived via 'usual vectors.'
- Broader security-press coverage (SecurityWeek, Security Affairs, The Cyber Express, HelpNetSecurity, CyberSecurityNews, GridinSoft) corroborates the named malware families, the 'refill then drain' usage-pattern indicator, and that phones/tablets were not implicated.
Sources cited for Infostealer Malware (Vidar, LummaC2, StealC, RedLine
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
- Anthropic Warns Claude Users of Infostealer Malware Infections
- Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
- Anthropic Warns Of Infostealers Hijacking Claude Sessions
- Anthropic locks out Claude users after infostealers hijack login sessions
- Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts
- Claude Session Stolen by Infostealer? What to Do
More in malware
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub Repos
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
Detection coverage for TL-2026-2262
As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2262 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.