Infostealers Hijack Claude AI Accounts to Drain Usage Credits and Payment Methods
Anthropic has confirmed that threat actors are actively compromising Claude AI user accounts through session hijacking attacks powered by commodity infostealer malware. The campaign targets both individual and professional Claude subscribers, enabling attackers to consume victims' paid usage allowances and potentially trigger unauthorized charges through auto-reload features. Affected users received warnings that their payment methods were removed and sessions terminated after Anthropic's systems detected anomalous consumption patterns indicating account takeover. The attack represents a new monetization vector for infostealer operators, who are now targeting AI service subscriptions alongside traditional banking and cryptocurrency credentials.
The attack chain begins with victims becoming infected by common infostealer malware through methods not specified in the disclosure, though Anthropic emphasized the malware was not distributed through Claude itself or related to any Claude activity. Once deployed on a victim's system, the infostealer extracts active browser session cookies and authentication tokens that prove the user is already logged into Claude, completely bypassing traditional password and multi-factor authentication protections. Attackers then import these stolen session credentials into their own browsers, gaining immediate access to the victim's Claude account without triggering login prompts or security challenges. The threat actors systematically drain the account's included usage allowance and any prepaid Usage credits, and if auto-reload is enabled, they trigger additional purchases by continuing to consume capacity until the configured spending limit is reached or unlimited spending drains available payment methods.
This campaign illustrates the growing threat surface created by AI service adoption in enterprise and professional environments, where usage-based billing models create direct financial exposure beyond traditional data theft. Session hijacking attacks are particularly dangerous because they operate entirely within legitimate authentication frameworks, making detection difficult without behavioral analytics that flag unusual consumption patterns or geographic anomalies. The stolen Claude capacity provides criminals with free access to advanced AI capabilities that can be weaponized for generating sophisticated phishing content, developing and obfuscating malware, automating social engineering attacks, and analyzing previously stolen data at scale. While Anthropic has implemented abuse monitoring and disrupted identified malicious accounts, the reliance on commodity infostealers means the attack infrastructure is widely available and easily replicated across the cybercriminal ecosystem. Organizations using Claude for business operations face dual risks of financial loss through fraudulent usage charges and potential exposure of proprietary prompts, conversations, and uploaded documents that may contain sensitive business intelligence or customer data.
Attack Surface
Cloud Service, Endpoint, Web Browser
Tactics
Initial Access, Credential Access, Collection, Impact
Techniques
- T1539 – Steal Web Session Cookie
- T1555 – Credentials from Password Stores
- T1185 – Browser Session Hijacking
- T1530 – Data from Cloud Storage
- T1496 – Resource Hijacking
SuperPRO's Threat Countermeasures Procedures
- Scan all computers used to access Claude with updated anti-malware solutions and remove any detected infostealers before re-authenticating or changing passwords
- After malware removal, change the password for the email account associated with Claude, sign out all other devices, and enable two-factor authentication on the email account
- Change all sensitive passwords stored in the affected browser including banking credentials, work accounts, and cloud service logins
- Review credit card and bank statements for unauthorized charges if payment details were saved in the browser during the infection period
- Monitor Claude usage dashboards for consumption anomalies while the account is idle, particularly unexpected depletion of usage credits or triggered auto-reload purchases
- Disable auto-reload features for Claude Usage credits or set conservative monthly spending limits to cap potential financial exposure from account takeover
- Deploy endpoint detection and response solutions configured to alert on browser cookie theft, credential dumping from browser stores, and session token extraction behaviors associated with infostealers