Anthropic has alerted a number of Claude users that they may have been caught up in a new malware campaign. The company issued warnings after discovering that criminals are using infostealer malware to hijack active Claude login sessions, record them, and then replay them remotely. Once inside, the attackers drain usage credits, leaving victims baffled about their disappearing balances. The campaign appears to be part of a growing trend: cybercriminals are now singling out artificial intelligence platforms, not just for login details, but for the very computational resources and usage credits tied to those accounts.
The email sent to affected users, which was also shared on Reddit, explains that a bad actor used common infostealer malware to steal Claude login sessions from personal computers. The attacker then used those sessions to access Claude accounts and consume usage. Anthropic has responded by signing out all affected users, removing payment information from the accounts, and issuing refunds for any unauthorized usage charges. The company also advised users to run malware scans on their devices to ensure the infection vector has been neutralized.
What are infostealers and why are they suddenly targeting AI platforms?
Infostealers are a well-established family of malicious software designed to quietly extract valuable data from infected systems. For years, these threats have focused on a predictable set of targets: browser passwords, cookies, stored credit card numbers, cryptocurrency wallet files, and even personal documents. The ultimate goal has traditionally been straightforward financial fraud or identity theft. But the current Anthropic alert marks a shift in focus: AI platform credentials and session tokens are now lucrative targets in their own right.
Claude, like many other AI assistants, operates on a usage-based or subscription-based model. Some users pre-purchase credits or connect a payment card for automatic refills. A stolen session token — a digital pass that lets a user remain logged in without repeatedly entering a password — can be replayed from another machine to access that account. For cybercriminals, this opens the door to free usage of expensive language models, or the ability to resell access on underground forums. In essence, the AI platform has become a digital wallet that can be drained at the victim's expense.
The Anthropic warning specifically names several infostealer families affecting Windows systems, including Vidar, Lumma, StealC, and RedLine. Mac users are not entirely safe, as a smaller number of infections have been linked to Atomic Stealer. These tools are often delivered through legitimate-looking software bundles, malvertising, or fake installers. They are also commonly distributed via pirated software cracks, keygens, and other illegal downloads. Once executed, they quietly harvest data from browsers and applications, then exfiltrate it to remote servers operated by the attackers.
What the hackers do with stolen Claude sessions
According to Anthropic's alert, the attackers are using the stolen sessions to log into Claude accounts and burn through the victim's usage allowances. In many cases, users first notice something is wrong when their usage limits appear to refill and then drain repeatedly without any action on their part. These anomalies can occur over a period of hours or days, making them difficult to detect early.
A Reddit user who posted the email admitted that their infection probably came from a cracked game downloaded from a less-than-reputable source. That user's experience underscores a hard truth: malware infections rarely originate from legitimate AI platforms. The attackers are not breaking into Claude's infrastructure or exploiting a vulnerability inside the service. Instead, they are profiting from security lapses on the user's own device. Anthropic made clear that it has no reason to believe the malware is related to Claude itself, was installed through Claude, or stems from any action taken inside the service. This is a classic supply-chain-like attack, but with the endpoint being the user's personal computer.
Cracking software or downloading pirated content is a common way for infostealers to find their way onto a machine. The same reckless practice that exposed users to malware in the era of Limewire and torrent sites is still highly dangerous today. Modern infostealers are far more sophisticated, often operating in the background with minimal system impact, making them invisible to users who are not actively running security tools.
What Anthropic did for affected users
In response to this campaign, Anthropic took several protective measures. The company force-signed out all users who may have been affected, which invalidates active session tokens. This is an effective mitigation tactic because even if the stolen token is replayed, the server will reject it after the sign-out. Additionally, Anthropic removed payment information from the affected accounts. This step prevents attackers from triggering new charges on linked credit cards or other payment methods.
The company also promised to refund any additional usage charges that appear unauthorized. This is a significant move, as it acknowledges that users may have already been billed for usage they did not personally incur. However, Anthropic is not obligated to refund charges that result from users engaging in illegal activities, such as downloading cracked software or pirating content. The company notes that it has no reason to believe the malware is related to Claude or anything users did with Claude, suggesting that reimbursement is a goodwill gesture rather than an admission of liability.
What Claude users should do now
For those who received an alert from Anthropic, the first step is to clean the device. Simply changing passwords or removing payment details is not enough if the infostealer remains active. Users should remove any newly installed, suspicious, or cracked software immediately. Running a full anti-malware scan is also essential. Many infostealers leave behind backdoors or additional payloads, so a thorough sweep with reputable security software is recommended. Advanced users may also want to check for unusual browser extensions, installed certificates, or network connections.
After the system is clean, affected users should sign back into Claude and re-add payment details if needed. Monitoring account usage for a few days can help ensure that no further unauthorized activity occurs. Any strange charges that have not been refunded should be reported to Claude support. It is also wise to revoke active session tokens across other important applications, especially those that may share the same browser environment.
Beyond immediate remediation, this incident highlights a broader issue: the growing value of AI account credentials to cybercriminals. While phishing emails and credential-stuffing attacks have long targeted conventional accounts, the rise of AI usage credits has created a new attack surface. Security experts anticipate that similar campaigns will target other AI platforms, including ChatGPT, Copilot, and Gemini. The monetization of stolen AI access is still an emerging black market, but it is already showing signs of becoming a lucrative business.
Protecting yourself in the age of AI credential theft
The lesson from this campaign is straightforward but worth repeating: users must be vigilant about what they download and where they download it from. Piracy remains one of the most dangerous online habits, as illegal software often arrives with hidden passengers. Cracks, keygens, and patch files are notorious for carrying infostealers that can strip a computer bare within minutes. Even a single mistake can expose passwords, financial data, and now AI usage accounts.
Strong authentication measures are also essential. While session hijacking does not always require a password, using a password manager, enabling two-factor authentication, and routinely checking account activity can limit the damage. For AI platforms like Claude, which may be linked to payment methods, users should consider using virtual cards or prepaid cards with low spending limits to minimize financial exposure.
Anthropic's response has been widely praised for its transparency and customer protection measures. By promptly informing users, remotely signing them out, wiping payment details, and refunding unauthorized usage, the company has set a positive example. Yet the ultimate responsibility lies with the user to maintain a clean and secure computing environment. As AI continues to become deeply integrated into daily work and life, securing access to these platforms must become a top priority. The threat landscape is evolving quickly, and no one can rely on a single layer of defense to keep their digital assets safe.
Source: ZDNET News