New Infostealer Malware Hijacks Claude Accounts, Steals Login Sessions
Key Takeaways Anthropic’s Claude AI platform is under active attack from multiple infostealer malware campaigns. Attackers are using sophisticated methods, including session cookie theft to...
Key Takeaways
- Anthropic’s Claude AI platform is under active attack from multiple infostealer malware campaigns.
- Attackers are using sophisticated methods, including session cookie theft to bypass MFA and leveraging Claude’s own infrastructure for distribution.
- Malware families like Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer are implicated.
- A novel persistence mechanism involves poisoned SKILL.md files, allowing reinfection even after system cleanups.
- Anthropic is actively signing out compromised accounts, removing payment methods, and issuing refunds, but users must clean their devices.
The artificial intelligence platform Claude, developed by Anthropic, has become a prime target for cybercriminals, who are deploying sophisticated infostealer malware to compromise user accounts. Multiple attack vectors have been identified, enabling the theft of credentials, unauthorized consumption of paid services, and even persistent reinfection of user devices.
Table Of Content
Anthropic has confirmed these attacks and initiated measures to mitigate the damage, including forcibly signing out compromised accounts, removing stored payment information, and processing refunds for fraudulent charges.
Infostealers Target Claude Accounts
According to an advisory issued by Anthropic, several prominent infostealer malware families are actively exfiltrating sensitive data from infected Windows and macOS machines. On Windows, malware such as Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed have been observed. macOS users are targeted by Atomic Stealer. These malicious programs are designed to steal saved passwords, browser cookies, and other locally stored credentials.
A critical aspect of these attacks is the theft of already-authenticated session cookies. This method allows attackers to bypass traditional security measures like two-factor authentication (2FA) and single sign-on (SSO), as they can simply replay a victim’s active session. This enables threat actors to access Claude accounts and deplete paid usage limits without needing to re-authenticate. Anthropic’s detection of these activities stemmed from unusual patterns, where account usage limits were being rapidly refilled and then drained while legitimate account owners were inactive.
FakeAgent Leverages Claude’s Infrastructure
A distinct but related threat, dubbed “FakeAgent” by security firm Huntress, illustrates how attackers have exploited Claude’s own infrastructure for malware distribution. Between July 21 and July 22, 2026, malicious actors manipulated search engine results, specifically targeting Bing users searching for a “Claude desktop app.” These users were presented with sponsored advertisements directing them to a hostile public Claude Artifact.
Crucially, this malicious artifact was hosted directly on the legitimate claude.ai domain. This allowed it to inherit the domain’s SSL certificate and search engine authority, lending it an air of legitimacy. Victims who clicked on the fake installer, disguised as “ClaudeDesktop.exe,” unwittingly initiated a DLL sideloading attack. This involved a tampered libcef.dll file paired with a repurposed JetBrains helper binary, ultimately deploying SectopRAT. SectopRAT is a .NET-based remote access trojan capable of harvesting browser credentials, credit card data, cookies, and files from infected systems.
Huntress reported that at least 29 organizations were compromised within a mere two days by this campaign. The malicious download page accumulated approximately 7,100 downloads before Anthropic successfully removed it.
Novel Persistence Mechanisms
A new and particularly insidious persistence technique has also emerged, involving “poisoned SKILL.md” files. These documentation-style configuration files are used by Claude’s agent skills. Attackers embed malicious instructions within these files, camouflaging them as ordinary style-guide notes. When Claude loads such a tainted file, the hidden commands silently trigger the re-download and execution of infostealer malware, harvesting credentials once again. This method of persistence is highly dangerous, as it can enable malware to survive even a complete operating system reinstall if the compromised SKILL.md file is reintroduced to the system.
One incident highlighted the severity of this threat when a Web3 founder reported nearly losing control of cryptocurrency wallets after a Claude chat session suggested a terminal command that executed instantly, pulling in the malicious payload.
Anthropic’s Response and User Responsibility
In response to these ongoing threats, Anthropic has taken several protective measures. The company has signed out affected user sessions, removed any stored payment methods to prevent further unauthorized charges, and is issuing refunds for confirmed fraudulent transactions. However, Anthropic emphasizes that these account-side fixes do not remove malware from an infected device. This means that a newly created session on a compromised machine remains vulnerable to immediate re-theft upon the next login.
What You Should Do
- Before logging back into Claude, perform a full malware scan of your device using reputable antivirus software.
- Reset the password for the email account linked to your Claude profile and ensure two-factor authentication (2FA) is enabled.
- Update any credentials saved within your web browsers.
- Exercise extreme caution with any AI-suggested links or terminal commands, treating them with the same scrutiny as unsolicited email attachments.
- For organizations deploying Claude at scale, consider sandboxing AI agent environments and regularly auditing SKILL.md or similar configuration files for hidden or suspicious instructions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.