Infostealer Malware Targets Claude AI Users, Anthropic Warns of Session Hijacking
Security Threat Targets Claude AI Users
Anthropic has warned that infostealer malware is increasingly targeting users of its Claude AI assistant. The attackers are using the malware to hijack active sessions, effectively stealing usage from legitimate users and potentially accessing conversation history.
How the Attack Works
The infostealer malware gains access to a user's system and intercepts active Claude sessions. Once inside, it can drain usage quotas, extract data from ongoing conversations, and potentially use the stolen session to conduct further attacks or scrape additional information.
Recommendations for Users
Users of Claude and similar AI platforms are advised to:
- Enable multi-factor authentication where available
- Monitor account usage for any unexplained activity
- Keep security software up to date
- Avoid sharing session credentials or tokens
- Regularly review connected applications and active sessions
Broader Context
Infostealer malware has become a significant threat across the tech industry, targeting credentials and session tokens for various services. AI platforms have become attractive targets due to the value of conversation data and API access.
Anthropic continues to monitor the situation and is working on additional safeguards to protect Claude users from such attacks.