Cybercriminals are targeting users of Anthropic’s Claude artificial intelligence (AI) platform with malware that can steal authenticated login sessions, potentially allowing attackers to access accounts without passwords or two-factor authentication.
Cyber Security News reported Monday (Aug. 31) that several information-stealing malware families, including Vidar, Lumma, StealC, RedLine and Acreed on Windows and Atomic Stealer on macOS, have been used to collect browser cookies, saved passwords and other credentials from infected devices.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The threat is particularly significant because stolen session cookies can allow attackers to impersonate an already-authenticated user. Anthropic identified cases in which attackers appeared to consume paid Claude usage after account owners had stopped using the service. Because the attackers can reuse an existing session, traditional login protections such as multifactor authentication may not prevent the takeover.
A separate campaign tracked by cybersecurity firm Huntress used Claude’s own infrastructure to distribute malware, according to Cyber Security News. Between July 21 and July 22, attackers reportedly used sponsored Bing advertisements to direct users searching for the Claude desktop application to a malicious Claude Artifact hosted on the legitimate claude.ai domain.
The fake installer deployed SectopRAT, a remote-access Trojan capable of harvesting browser credentials, cookies, files and payment-card information, the report said. Huntress identified at least 29 compromised organizations and roughly 7,100 downloads before Anthropic removed the malicious page.
The activity also highlights a broader security concern for businesses adopting AI tools. Cyber Security News reported that attackers have begun hiding malicious instructions in files used by Claude’s agent, potentially allowing malware to be downloaded again when compromised files are reintroduced.
Anthropic has responded by signing affected accounts out, removing stored payment methods and refunding confirmed fraudulent charges, according to Cyber Security News. The company has warned that those measures do not remove malware from infected devices.
The security concerns extend beyond stolen credentials. In July, Alibaba barred employees from using Anthropic’s AI tools at work and placed Claude Code on a high-risk software list, following Anthropic’s allegations that Alibaba had conducted a large-scale effort to extract capabilities from its models.