#4
BleepingComputer
general
August 30, 2026 at 14:30 UTC
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
By Mayank Parmar
AI Summary
Anthropic warned Claude users that infostealer malware on victim machines is harvesting active Claude session tokens, allowing attackers to hijack authenticated sessions and drain paid usage allocations without needing credentials. This attack vector bypasses MFA by targeting session cookies post-authentication, a technique commonly associated with stealers like Lumma and Redline. Claude users on shared or less-secured endpoints should rotate sessions and review active login activity.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →