Infostealer Campaign Reportedly Targets Claude User Sessions
A threat actor has reportedly used multiple information-stealing malware families to obtain session data associated with Anthropic's Claude service, potentially enabling unauthorized access to affecte...
A threat actor has reportedly used multiple information-stealing malware families to obtain session data associated with Anthropic's Claude service, potentially enabling unauthorized access to affected user accounts.
Details about the scope of the activity, the malware involved, the period of the campaign, and the number of impacted users were not disclosed. It is also unclear how the victims were initially infected or whether the stolen sessions were used for follow-on activity.
How session theft works
Infostealers are malware programs designed to collect data from infected devices. They commonly search web browsers for saved passwords, authentication cookies, browser tokens, autofill data, cryptocurrency wallet information, and other credentials.
Session cookies and similar authentication artifacts can be particularly valuable because they may allow an attacker to impersonate a logged-in user without immediately needing the account password. Whether access succeeds can depend on a service's security controls, token expiration, device checks, and multifactor authentication requirements.
Steps users can take
- Review active sessions and connected devices for accounts containing sensitive data.
- Sign out of sessions that are unfamiliar or no longer needed, then change account passwords.
- Enable multifactor authentication where it is available.
- Keep browsers, operating systems, and endpoint security tools updated.
- Avoid installing unverified software, browser extensions, game cheats, cracked applications, and files received through unsolicited messages.
- Monitor account activity and investigate unexpected prompts, new sessions, or changes to account settings.
Organizations whose staff use AI services should consider browser and endpoint protections as part of account security planning. Limiting access from unmanaged devices, monitoring for credential-stealing malware, and providing phishing awareness training can reduce exposure to session-hijacking attempts.
