OceanAltOceanAlt
Agent Economy2026-09-01Event 2026-08-312 min read

Hackers Steal Claude Login Sessions via Malware, Anthropic Confirms Account Abuse

Info-stealing malware targets Anthropic's Claude platform, enabling account takeovers without passwords or 2FA, while a separate campaign abuses Claude's own infrastructure to distribute remote access trojans.

OOceanAlt EditorialSource

Cybersecurity firms report that hackers are targeting users of Anthropic's AI platform Claude with info-stealing malware designed to capture authenticated login sessions, allowing account takeover without passwords or two-factor authentication. According to Cyber Security News on Monday (Aug. 31), multiple malware families—including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer on macOS—are being used to harvest browser cookies, saved passwords, and other credentials.

Anthropic said it has identified cases where attackers continued to consume paid Claude usage even after account owners had stopped using the service. Because session cookies can be reused, traditional login protections such as multi-factor authentication may not prevent such takeovers.

In a separate campaign tracked by cybersecurity firm Huntress, attackers leveraged Claude's own infrastructure to distribute malware. Between July 21 and 22, threat actors used sponsored Bing ads to redirect users searching for the Claude desktop app to a malicious Claude Artifact hosted on the legitimate claude.ai domain. The fake installer deployed the SectopRAT remote access trojan, capable of stealing browser data.

Source: https://www.pymnts.com/news/artificial-intelligence/2026/hackers-target-claude-accounts-with-malware-that-steals-login-sessions/

Provenance & status

Byline
OceanAlt Editorial
First published
2026-09-01
Last updated
2026-09-01
Content type
Newsflash
Source material
View original ↗

Cite this piece

OceanAlt Editorial (2026). "Hackers Steal Claude Login Sessions via Malware, Anthropic Confirms Account Abuse". OceanAlt. https://oceanalt.com/en/articles/flash-auto-mths8gfg-t02u (accessed 2026-09-16)

This piece follows our editorial and fact-checking standards. Found an error? tell us — once verified, the correction will be published right here.

TRY IT · FREE, NO SIGNUP

Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.

This judgement can sit inside your own product

One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

The widget collects no reader identity. Integrating does not mean OceanAlt endorses your product, or any address on your page.