Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Infostealers Hijack Claude Sessions, Draining Subscriptions and Exposing User Data




Infostealers, a type of malware, have been hijacking active Claude sessions, draining paid subscriptions, and exposing user data. Anthropic has detected multiple infostealer families and signed out users from Claude, removing their saved payment cards to prevent unauthorized charges. Users are advised to run a full malware scan, change their account password with 2FA enabled, and be cautious when using pirated downloads or malicious apps to protect themselves from this threat.

  • Infostealers, a type of malware, have been hijacking active Claude sessions, bypassing 2FA and draining paid subscriptions.
  • Attackers can access users' accounts without requiring their passwords, making it difficult to detect the malicious activity.
  • Infostealer malware can steal authenticated browser sessions, evading 2FA, MFA, and SSO.
  • Users are advised to run full malware scans, change passwords with 2FA enabled, and be cautious with pirated downloads and malicious apps.
  • The hijacking of Claude sessions is a serious security breach highlighting the importance of using strong passwords and enabling 2FA and SSO.



  • Infostealers, a type of malware, have been hijacking active Claude sessions, bypassing two-factor authentication (2FA) and draining paid subscriptions. This malicious activity has been identified by Anthropic, a company that provides AI-powered security solutions. The hijacking of Claude sessions allows attackers to access users' accounts without requiring their passwords, making it difficult for users to detect the malicious activity.

    Anthropic has detected multiple infostealer families affecting Windows and macOS, which steal authenticated browser sessions, allowing attackers to evade passwords, MFA (Multi-Factor Authentication), and SSO (Single Sign-On). This means that even if users have enabled 2FA and SSO, the attackers can still gain access to their accounts by exploiting the hijacked session.

    The malicious activity was first detected by Anthropic, which has since signed out users from Claude and removed their saved payment cards to prevent unauthorized charges. Anthropic has also refunded users for any charges it identifies as unauthorized.

    The infostealer malware is typically spread through unofficial downloads or malicious apps, and it quietly copies saved passwords, login cookies in browsers, and credentials for other apps running locally. The malware is general-purpose and can be used to steal data from various sources, including email attachments, pirated downloads, and unofficial app installers.

    Users who use Claude and haven't checked their usage history recently are advised to run a full malware scan before logging back in, change their account password with 2FA enabled, and treat any pirated download or unofficial app installer with suspicion. This is because the AI subscription being quietly drained by the infostealer malware is a reliable sign that something more serious, such as the user's actual banking credentials, might already be compromised.

    The hijacking of Claude sessions is a serious security breach that highlights the importance of using strong passwords, enabling 2FA and SSO, and being cautious when using pirated downloads or malicious apps. Anthropic's efforts to detect and mitigate this threat are a crucial step in protecting users from this type of malicious activity.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Infostealers-Hijack-Claude-Sessions-Draining-Subscriptions-and-Exposing-User-Data-ehn.shtml

  • https://securityaffairs.com/198166/ai/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions.html


  • Published: Mon Aug 31 04:27:15 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us