top of page

Alert: Hackers hijack Claude AI accounts using session-stealing infostealer malware

Anthropic’s Claude AI platform has become a prime target for cybercriminals. Malicious campaigns have found ways to hijack accounts, silently drain paid usage limits, and even automatically reinfect devices even after users clean up their systems.

How malware bypasses 2FA security barriers

Threat groups are leveraging a wide range of information-stealing malware (infostealers). On Windows operating systems, prominent strains include Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed, while macOS users face Atomic Stealer.

The mechanism of these malware strains is exceptionally dangerous:

  • Credential theft: They silently collect saved passwords, local storage data, and most importantly, browser cookies.

  • Bypassing Two-Factor Authentication (2FA) and Single Sign-On (SSO): Instead of guessing passwords, attackers hijack "session cookies" - essentially temporary authentication keys that keep you logged in. Armed with these cookies, hackers can "replay" your session without going through 2FA or SSO authentication steps.

  • Draining service usage limits: Anthropic detected anomalies after noticing numerous paid accounts repeatedly being refilled and then having their resources completely drained while the account owners were entirely inactive.

Sophisticated disguises via fake ads and poisoned configuration files

Another dangerous campaign dubbed FakeAgent (tracked by cybersecurity firm Huntress) demonstrates how hackers weaponized Claude’s own infrastructure to distribute malware.

Between July 21 and July 22, 2026, users searching for the keyword "Claude desktop app" on Bing were served sponsored ads. These links led to a publicly accessible feature (Claude Artifact) hosted directly on the legitimate claude.ai domain. Because it resided on the official domain, this link naturally inherited an SSL safety certificate and high search engine authority.

The specific attack chain unfolded as follows:

  • Users downloaded a fake installer named ClaudeDesktop.exe.

  • Launching this file triggered a DLL sideloading technique using a tampered system file libcef.dll paired with a JetBrains helper executable.

  • Ultimately, SectopRAT was installed on the system - a remote access trojan specialized in harvesting credit card data, cookies, files, and browser login credentials.

Statistics indicate that at least 29 organizations were compromised in just 48 hours, and the malicious page recorded approximately 7,100 downloads before Anthropic took it down.

Furthermore, attackers devised a persistent mechanism using SKILL.md files - configuration documentation files used for Claude’s agent skills. Hackers hid malicious commands under the guise of ordinary formatting instructions. Whenever Claude loaded this file, the hidden commands automatically triggered to re-download the malware. As a result, even if users completely reinstalled their operating system, the computer could still be reinfected if this file was restored.

In fact, a Web3 founder nearly lost their entire cryptocurrency wallet after executing a terminal command suggested by Claude in a chat window - a command that actually downloaded malware directly to the machine.

Anthropic’s response and mandatory protection measures

Upon discovering the incident, Anthropic immediately deployed emergency remediation measures:

  • Proactively signing out affected user sessions.

  • Removing saved payment method details to prevent unauthorized charges.

  • Refunding confirmed fraudulent transactions.

claude-notice
Claude Notice

However, Anthropic warned that server-side interventions cannot clean up malware on users' personal devices. If a computer remains infected, newly created login sessions will continue to be stolen.

To ensure security, cybersecurity experts recommend that users and organizations immediately take the following steps:

For Individual Users:

  • Perform a full system scan using anti-malware software before logging back into Claude.

  • Change the password of the linked email account, re-enable two-factor authentication (2FA), and update credentials saved in browsers.

  • Exercise maximum caution with links or terminal commands suggested by AI; scrutinize them thoroughly, just as you would when opening attachments from unknown emails.

For Organizations and Enterprises:

  • Establish secure sandboxing environments when deploying AI agents.

  • Thoroughly audit the contents of SKILL.md files or similar configuration files to detect hidden malicious instructions early.

This incident serves as a stark reminder that no matter how advanced AI tools are, they can still be exploited. Proactively checking your devices and maintaining vigilance when interacting with AI suggestions are the best ways to protect your digital assets.

Reference: Cyber Security News

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page