Bỏ qua đến nội dung chính
Back to home
AI tools-ai 2 min read

Infostealer Malware Hijacks Claude Cookies, Threatening Enterprise Data

Infostealer malware is hijacking self-paid Claude sessions to bypass two-factor authentication, posing severe data breach risks for integrated enterprise Google Workspace accounts.

Tier 2 · sources 99% confidence Reviewed
Sources venturebeat.com

Anthropic has issued a warning to users after identifying a wave of information-stealing malware (infostealers) harvesting Claude session cookies from personal computers and replaying them to hijack paid accounts. The identified malware strains include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer on macOS. After detecting abnormal usage limits being depleted, Anthropic forced logouts on affected sessions, removed stored payment methods, and refunded unauthorized charges incurred by users.

This campaign primarily targets self-paid accounts funded via personal payment cards rather than enterprise tiers protected by Single Sign-On (SSO). Once malware successfully extracts a session cookie from a browser, attackers can directly access the service without passing two-factor authentication (2FA) prompts. According to a technical report from Help Net Security, session hijacking has become a particularly dangerous attack vector because servers recognize the attacker as an authenticated, legitimate user.

Data Leakage Risks via Google Workspace Integrations

Financial losses from compute usage represent only a fraction of the danger compared to internal data exposure. A compromised Claude session inherits full access to chat history, uploaded project files, and connected integrations. According to Anthropic documentation, the Google Workspace connector allows personal Claude accounts to automatically read and query Gmail mailboxes or Google Drive files without requiring per-action confirmation.

If employees use personal accounts on corporate machines and grant access to their work inboxes, attackers holding the cookies can view sensitive corporate data undetected by IT administrators. Data from LayerX, published by Akamai, reveals that 47% of enterprise AI interactions occur via personal accounts, surging to 61% specifically for Claude. Speaking to Axios, Adam Meyers, Senior Vice President at CrowdStrike, stated that cybercriminal groups routinely trade ChatGPT, Claude, and Gemini credentials on dark web marketplaces to exploit compute resources (LLMjacking).

Anthropic Limits and Expert Recommendations

Anthropic emphasized that the malware does not originate from Claude's infrastructure or vulnerabilities within its platform, but resides directly on end-user devices. The vendor's forced logouts only temporarily invalidate the stolen session and cannot remediate malware on the infected endpoint. Furthermore, logging out of Claude does not automatically revoke third-party OAuth permissions previously granted to services like Google or Microsoft.

Speaking with VentureBeat, Kayne McGladrey, Senior Member of IEEE, noted that technical defense solutions are readily available, but the challenge lies in corporate prioritization and visibility over personal accounts operating outside security oversight. To mitigate these risks, experts recommend that organizations block personal AI accounts from connecting to corporate Google Workspace or Microsoft 365 environments, while conducting immediate audits to revoke lingering OAuth authorizations.