DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Infostealer Malware Hijacks Claude Sessions via Cookie Theft

Forensic Summary

Anthropic has confirmed that infostealer malware families including Vidar, LummaC2, StealC, and RedLine are being used to steal authenticated Claude browser sessions, granting attackers API-level access without needing credentials or 2FA. The attack bypasses standard authentication controls entirely by harvesting session cookies from compromised endpoints, allowing threat actors to consume victims' Claude usage quotas and potentially access stored payment data. Anthropic is revoking sessions and issuing refunds, but the incident highlights a systemic risk for AI service accounts when endpoint security is weak.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/infostealer-malware-hijacks-claude-sessions-via-cookie-theft/

Top comments (0)