Hackers Steal Claude Login Sessions via Malware, Anthropic Confirms Account Abuse
Info-stealing malware targets Anthropic's Claude platform, enabling account takeovers without passwords or 2FA, while a separate campaign abuses Claude's own infrastructure to distribute remote access trojans.

Cybersecurity firms report that hackers are targeting users of Anthropic's AI platform Claude with info-stealing malware designed to capture authenticated login sessions, allowing account takeover without passwords or two-factor authentication. According to Cyber Security News on Monday (Aug. 31), multiple malware families—including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer on macOS—are being used to harvest browser cookies, saved passwords, and other credentials.
Anthropic said it has identified cases where attackers continued to consume paid Claude usage even after account owners had stopped using the service. Because session cookies can be reused, traditional login protections such as multi-factor authentication may not prevent such takeovers.
In a separate campaign tracked by cybersecurity firm Huntress, attackers leveraged Claude's own infrastructure to distribute malware. Between July 21 and 22, threat actors used sponsored Bing ads to redirect users searching for the Claude desktop app to a malicious Claude Artifact hosted on the legitimate claude.ai domain. The fake installer deployed the SectopRAT remote access trojan, capable of stealing browser data.
Source: https://www.pymnts.com/news/artificial-intelligence/2026/hackers-target-claude-accounts-with-malware-that-steals-login-sessions/
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-09-01
- Last updated
- 2026-09-01
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Félix Raises $200M Led by a16z: Stablecoin Infrastructure Shifts from Remittances to Agent Economy Settlement
U.S. Congress Holds First Hearing on AI Agent Payment Rules: Authorization, Settlement, and Identity Take Center Stage
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

