Оксана СтепураAround IT
3 September 2026, 13:48
2026-09-03
Attackers have learned to hijack Claude sessions to bypass 2FA. Gmail and Drive may also be at risk
Attackers have started hijacking active sessions of Claude users using info-stealer programs. To log in to an account, they just need to steal a special cookie from the browser.
Attackers have started hijacking active sessions of Claude users using info-stealer programs. To log in to an account, they just need to steal a special cookie from the browser.
After a user logs into Claude, the browser stores a session cookie. Thanks to it, the service «remembers» that the person has already logged in and does not ask for a password every time. An info-stealer on an infected computer can steal this cookie. The attacker inserts it in his browser, and Claude perceives it as if the user is already logged in. Therefore, there is no need to go through 2FA again.
Anthropic identified several malware used in such attacks: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Mac. These programs can also steal saved passwords and other data from the browser.
The company noticed the problem due to unusual usage of Claude limits. They were replenished and quickly depleted while the account holders were not using the service. At that time, Anthropic terminated the affected users' sessions, deleted the stored payment data, and refunded the funds for the unauthorized charges found.
The problem could potentially be more serious if other services are connected to Claude’s personal account. Claude allows you to connect Google Workspace, including Gmail and Google Drive. The AI can then read information that the user has given it access to. So a hijacked session could open the way to data from connected services as well.
However, there is currently no confirmation that the attackers in this campaign actually accessed Gmail, Google Drive, chat history, or files of Claude users. Anthropic also did not say exactly how many accounts were affected.
In one known case, a user linked the infection of his computer to a pirated game. But this is not the only possible way to catch the infostyler. For example, previously, malicious programs were also disguised as fake Claude installers.
Previously, dev.ua published an interview with Dima Ashkinazi, founder of the leak monitoring service Alerts Bar, about why 80% of cyberattacks start with info-stylers.
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».