news.mlab.sh
Back to the feed
threat-intel

Anthropic Users Hit by Infostealer Attacks, Session Thefts

High
Summary

Anthropic users are experiencing infostealer attacks, where threat actors are stealing login sessions and accessing Claude accounts. The attacks stem from infostealers installed on users' systems, bypassing traditional password security measures. Anthropic has proactively signed affected users out of Claude and removed saved payment methods to mitigate the damage.

A threat actor is targeting Anthropic users with infostealer attacks, resulting in unauthorized access to Claude accounts. The attacks are facilitated by general-purpose infostealers installed on users' systems, likely through malicious apps or unofficial downloads. These infostealers, including Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on Macs, steal login sessions and access Claude accounts.

Anthropic proactively signed affected users out of Claude and removed their saved payment information to contain the damage. The company’s investigation revealed that the infostealers harvested Claude sessions, along with other sensitive information such as login cookies, saved passwords and credentials for other apps. This allowed the attackers to bypass authentication controls and access accounts without defeating MFA.

One user, who shared Anthropic’s email communication on Reddit, noted that the attacker stole their Google Chrome credentials, including cookies and session IDs, bypassing two-factor authentication. Anthropic has refunded unauthorized charges for users who had already used compromised payment cards to pay for Claude usage.

To prevent further attacks, Anthropic advises users to remove the infostealers from their systems, secure their email accounts with new passwords and MFA, and update saved passwords in browsers and other apps before re-adding payment methods to their Claude accounts.

Read the full article at Dark Reading