Infostealer malware steals active Claude sessions: compromised accounts and refunds

Anthropic detected a targeted attack exploiting infostealer malware to steal active Claude sessions, allowing attackers to access accounts and consume remaining credit. The company is revoking compromised sessions, removing saved payment methods, and refunding unauthorized expenses.

Quick Response

The malware steals active Claude sessions without requiring passwords or 2FA again. Attackers exploit infostealers such as Vidar, LummaC2, and RedLine. Anthropic revokes compromised sessions and refunds unauthorized expenses. Users must remove the malware and change credentials.

Attack Mechanism and Vulnerability

The infostealers identified by Anthropic include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on some Macs. This malware typically arrives through malicious downloads or apps, stealing passwords, login cookies, and credentials for other applications.

Operational Impact and Residual Risks

Revoking compromised sessions blocks unauthorized access but does not remove the malware from the infected system. If the malware persists, subsequent login sessions could also be stolen. Affected users must take immediate measures to remove the malware and protect their accounts.

Prevention and Corrective Measures

Anthropic advises users to change credentials, revoke other sessions, and remove malware from their devices. The company emphasizes that the malware is not linked to Claude or its activities but was introduced through other sources, such as downloading pirated games.

Data Analysis and Simulations

The Blue Report 2026 measures technical defenses through 338 million simulations in customer production environments. The data reveals that prevention scores can hide vulnerabilities that emerge after initial access. Once attackers use valid credentials, the effectiveness of preventive measures significantly decreases.

Account Security Risks

Users must be aware that infostealers can copy already authenticated browser sessions, bypassing standard authentication processes such as passwords and 2FA. This means that even accounts protected by advanced security measures can be compromised if the device is infected.

Next Steps for Users

Affected users must follow Anthropic's instructions to protect their accounts. This includes removing the malware, changing credentials, and revoking all active sessions. Additionally, it is advisable to perform complete security scans to ensure the device is completely clean.

Implications for Business Security

This attack highlights the importance of robust cybersecurity for all companies handling sensitive data. Organizations must implement advanced preventive measures and continuously monitor suspicious activities to protect their customers from similar attacks.

Final Considerations

The incident underscores the need for greater awareness among users regarding the risks associated with downloading unofficial software or using malicious apps. Companies like Anthropic are working to improve security, but user collaboration is essential to prevent such attacks.

Additional Resources

For more information on security measures and to download the Blue Report 2026, users can visit Anthropic's official website.

The infostealer attack on Claude serves as a warning to all users to be vigilant about the security of their devices and accounts. By adopting adequate preventive measures and following the guidelines provided by companies, the risk of account compromise can be significantly reduced.

Market Trends: The Rise of Infostealer Attacks

The attack on Claude fits into a broader context of increasing infostealers, which, according to Kaspersky data, grew by 68% in 2023. This type of malware now represents 57% of all targeted cyberattacks aimed at credentials, surpassing even traditional phishing. The infostealer malware industry has become a thriving black market, with prices ranging from $5 to $250 for access to stolen data, depending on the sensitivity of the information.

Impact on the Business Sector: Hidden Costs and Loss of Trust

For companies using services like Claude, the impact goes beyond simply reimbursing unauthorized expenses. According to an IBM study, the average cost of a security incident involving compromised credentials is approximately $4.45 million, a 15% increase from the previous year. In addition to direct costs, companies must face the loss of user trust and potential reputational damage, which can have long-term market repercussions.

Practical Implications for Business Users

For professionals using artificial intelligence platforms like Claude, the attack underscores the importance of adopting proactive security measures. This includes implementing advanced multi-factor authentication (MFA) solutions, such as using hardware keys or authentication apps based on open standards like FIDO2. Additionally, it is crucial to continuously monitor account activities and set up immediate notifications for any suspicious access.

Future Trends: The Evolution of Infostealers

Security experts predict that infostealers will continue to evolve, becoming increasingly sophisticated. According to the Mandiant M-Tactics Report 2024, hacking groups are already experimenting with infostealers capable of bypassing even the most advanced security solutions, such as sandboxes and intrusion detection systems. This makes it essential for companies to invest in artificial intelligence and machine learning-based security solutions to stay one step ahead of attackers.

Mitigation Strategies for Organizations

For organizations, the response to this type of attack must be multi-phase. In addition to implementing advanced technical solutions, it is crucial to adopt a zero-trust security strategy, which assumes that any access could be compromised and requires continuous verification. Furthermore, companies should invest in continuous training programs for employees to raise awareness of the risks associated with downloading unofficial software and using malicious apps.

Towards a Safer Future

The attack on Claude users is a clear signal that cybersecurity must be an absolute priority for individuals and organizations. While companies like Anthropic continue to improve their defenses, collaboration between service providers, security experts, and end users will be fundamental to addressing future challenges. With the continuous evolution of infostealers, it is essential to adopt a proactive and integrated approach to security to protect not only sensitive data but also the trust and reputation of companies in the long term.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: the reader is invited to always inform themselves independently before making any decision.