Security1 distinct publisher2 min readPublished
Vidar, LummaC2, RedLine and Atomic Stealer are pulling session material that authenticates without a login prompt, so the usual reset-and-enroll response can leave the intruder inside and spending the victim's paid usage.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
An infostealer takes what is already sitting on the machine. Cookie stores and local tokens leave with the browser profile, and a session replayed by the thief arrives at the service as an already-authenticated user, so the login flow never runs and the second-factor prompt never fires [2]. That is what makes the ordering of a standard credential-theft response wrong here. Reset the password, enroll a factor, and the holder of a live session is still inside until the session itself is killed. The roundup does not say whether changing a Claude password terminates existing sessions [11], and that one detail decides how much of the usual playbook survives contact.
Delivery is unglamorous. Anthropic points at pirated software and illicit downloads [4], which means consumer-grade infection on machines that also hold work sessions. None of the four named families [9] was written for AI platforms. Vidar, LummaC2, RedLine and Atomic Stealer [3] collect whatever a profile holds, and Claude sessions are now part of what they collect [1].
The billing consequence is specific in a way the access itself is not. Attackers may consume the victim's paid AI usage [5], so a stolen session has a meter attached and spends money for as long as it stays valid.
Two items in the same weekly roundup were about the authentication layer rather than about code [10]. Alongside the Claude sessions, the Department of Justice is investigating a campaign that went at hundreds of thousands of X accounts through that platform's password-recovery system [6]; Attorney General Todd Blanche said X detected and disrupted it before the targeted accounts could be captured [7]. Different platforms, and in both cases the way in was the credential and recovery path.
The source stops short of establishing scope. It offers no dates, no victim count, no affected product tiers and no indicators [8], and the warning reaches the record through a publisher's roundup attributing it to Anthropic [10]. On that evidence this is a statement about what stealer operators now collect, not an incident whose blast radius anyone outside Anthropic can bound. Without waiting on Anthropic, a customer can check whether an administrator can force session revocation across a tenancy, and whether reuse of a session from an unfamiliar address shows up in any log they can actually read.
Ranked by verification strength, evidence, and original report placement.
Anthropic has warned that common infostealer malware is being used to steal active Claude sessions.
Stolen active Claude sessions potentially allow attackers to bypass passwords and two-factor authentication.
The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer.
The malware involved is often distributed through pirated software and illicit downloads.
The U.S. Department of Justice is investigating a large-scale attack targeting hundreds of thousands of X accounts through the platform's password-recovery system.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
security
Commodity infostealers are now cashing out stolen Claude sessions7 distinct publishers
leadership
Anthropic watermarks Claude everywhere because it cannot yet watermark only Europe3 distinct publishers
security
NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week5 distinct publishers
product
Anthropic wipes saved cards after infostealers copy Claude login sessions1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One summarized paragraph, vendor-attributed
Every load-carrying fact about Claude session theft comes from four sentences in a Cyber Express digest, attributed to Anthropic but not quoting it, and Anthropic's own advisory is not part of our coverage. The malware families are real and well documented elsewhere; what is thin is this specific campaign, which arrives without a date, a count, a tier or a single artefact a defender could search for.
No scale disclosed on the Claude side
Scale is precisely what this reporting withholds. There are no dates, no victim numbers, no affected Claude tiers. The 'hundreds of thousands' in the same digest belongs to the X password-recovery campaign, and importing it here would be a category error. A campaign is reported, but our coverage gives no way to measure how far it has spread.
Our framing runs slightly ahead of the source
The Cyber Express is dry to the point of understatement, hedging with 'potentially' and 'may'. Our own headline and standfirst go further, treating reset-and-enroll as a response that leaves the intruder in place. That follows from how session material works, but nobody in this reporting says whether a Claude password change invalidates live sessions, so that inference is ours, not something stated on the page.
Vendor warning plus aggregator format
Anthropic's warning locates the failure on the victim's machine and in pirated installers, which is where these stealer families genuinely live and also the least costly place for a platform to put a problem; nothing in this reporting tests whether Claude's session handling makes stolen material more useful than it needs to be. The digest has an incentive of its own visible in its shape, since each of its five items stops at a link to longer coverage.
Low, and limited by sourcing rather than plausibility
Commodity stealers scraping browser session data is ordinary enough to accept on sight, so the mechanism is not in doubt. What is in doubt is everything specific: one publisher, one paragraph, no primary document, and the operational detail a team would act on absent. Confidence sits where the sourcing sits.