Find notable cyber news and cases, enriched with sources, timelines, and signals.

Infostealer malware hijacks Claude sessions

Malware Activity
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

Anthropic warned that infostealer malware is stealing Claude login sessions from infected PCs, letting attackers reuse them for account access and consumption of usage. The company is signing out affected users, removing saved payment methods, and refunding charges it identifies as unauthorized. Anthropic tied the activity to Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer (AMOS), with infections likely arriving through downloads or malicious apps.

Related Happenings

SectopRAT fake Claude installer delivery

Malware Activity
H score19 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...

FakeAgent Bing malvertising campaign pushing fake Claude installer

Campaign
H score25 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The FakeAgent malvertising campaign is using Bing search ads and a malicious Claude Artifact to push a fake Claude desktop installer, exposing organizations to S...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

Timeline

  1. 30.08.2026 17:30 2 articles · 2h ago

    Anthropic warns that infostealer malware is stealing Claude login sessions

    Initial Disclosure

    Anthropic warned some Claude users that infostealer malware on their PCs stole active Claude login sessions, letting attackers access accounts and consume usage. The company said it is signing affected users out of Claude, removing saved payment methods, refunding charges it identifies as unauthorized, and urging users to change credentials, revoke other sessions, and remove the malware. Anthropic linked the activity to Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer (AMOS), and said the malware can arrive through downloads or malicious apps and steal browser passwords, login cookies, and other credentials.

    Show sources