Malware

Infostealer malware compromises Claude accounts, bypassing 2FA

Claude, an artificial intelligence chatbot developed by Anthropic, based on a large language model LLM. Icon and logo isolated on a dark surface, 3D rendering

Anthropic has confirmed that infostealer malware is capable of hijacking active Claude login sessions, allowing attackers to exploit paid usage without needing user passwords. This issue primarily affects users on Windows and macOS, with phones and tablets appearing to be uninvolved, Security Affairs reports.

Infostealer malware, including families such as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS, is stealing active Claude session cookies from infected computers. This allows attackers to bypass multi-factor authentication and single sign-on, gaining unauthorized access to paid Claude accounts. Anthropic is actively revoking compromised sessions, removing saved payment methods to prevent further unauthorized charges, and refunding affected users.

The company advises users to run malware scans, change account passwords with two-factor authentication enabled, and exercise caution with unofficial downloads. The compromise highlights the risk of infostealers not only draining AI service usage but also potentially accessing more sensitive financial credentials.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds