Quick Facts
- Anthropic identified six malware families targeting Claude session cookies on Windows and macOS, bypassing 2FA entirely.
- A separate campaign called Operation FakeAgent distributed a fake Claude Desktop installer that was downloaded 7,100 times before Anthropic removed it.
- Affected accounts are personal, card-billed subscriptions outside corporate SSO controls, leaving IT administrators with no ability to force sign-out.
Anthropic is warning Claude users that infostealer malware has stolen active login sessions from personal computers, allowing attackers to access accounts and burn through paid usage without ever entering a password or second factor.
The company sent the alert by direct email rather than a public announcement. Most people learned about it when an affected user posted the notice on Reddit.
How the Attack Works
When a user logs into Claude, the browser stores a session cookie that keeps the user authenticated between visits. Infostealer malware copies that cookie, along with saved passwords and tokens from other local apps. Anyone holding that cookie can replay the session without a password or 2FA code.
Anthropic said it spotted the theft through usage data. Limits were refilled and drained while account owners were away from Claude. The company is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorized.
In its advisory, Anthropic wrote: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.”
Six Malware Families Identified
Anthropic named six malware families in the campaign: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS. None are new or custom-built for this campaign.
The malware typically arrives through downloads or malicious apps and collects browser passwords, login cookies, and credentials from other applications. Anthropic stated it has no reason to believe the malware is related to Claude or installed through it.
Anthropic also cautioned that signing out stops stolen sessions but does not remove the underlying malware. “If it’s still on your computer, your next login session could be stolen the same way,” the company wrote.
The Personal Subscription Blind Spot
The flagged accounts are card-billed, self-serve subscriptions that no corporate identity provider governs. An IT administrator cannot force these accounts out of a session, and no admin console tracks them.
The risk extends beyond Claude itself. Google Workspace connectors available to individual Claude accounts mean a personal Pro subscription can hold a live authorization into a Gmail inbox or Google Drive folder. If that inbox is a work account, the attacker holding the replayed cookie has a read path into it. Signing out of Claude invalidates the stolen session but does not revoke any Google or Microsoft grant Claude was already authorized to use.
Operation FakeAgent and a Separate Distribution Chain
Researchers at Huntress documented a related campaign they called FakeAgent, which ran July 21 to 22, 2026. Attackers placed a sponsored Bing ad pointing to the legitimate claude.ai domain. The link led to a public Claude Artifact built to mimic the official Claude Desktop installer.
The artifact was downloaded 7,100 times before Anthropic removed it. It directed visitors to a fake installer named ClaudeDesktop.exe, which sideloaded a malicious DLL to deliver the SectopRAT remote access trojan. Researchers found the campaign’s command-and-control data stored in the Ethereum blockchain. Huntress traced the operator’s activity back to May 2025 and linked it to an earlier campaign using a fake Docker Desktop installer.
A Persistent Threat in Agent Configuration Files
Attackers have also hidden malicious instructions inside SKILL.md agent configuration files. When Claude loads the file, hidden commands silently re-download the infostealer and harvest credentials. The method can survive a full OS reinstall if the tainted file is reintroduced.
Adam Meyers, SVP of Counter Adversary Operations at CrowdStrike, described the broader pattern of AI resource theft as similar to crypto mining. “Think of this as LLM coin mining,” he said, referring to attackers who manipulate AI resources belonging to victims to generate massive bills as a byproduct of their operations.
For founders and executives, the immediate action items are clear: audit which employees hold personal Claude subscriptions with connected Google or Microsoft grants, enforce endpoint detection on all machines accessing AI tools, and treat session cookie theft as a credential compromise requiring the same response as a stolen password.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
