INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Anthropic Users Targeted by Infostealer Attacks and Session Thefts

| 2026-08-31 21:08 CRITICAL LOW DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
On August 31, 2026, Anthropic users were hit by infostealer attacks and session thefts, with an unknown number of users affected. The attackers used general-purpose infostealers installed on users' systems to steal Claude login sessions, which then allowed them to access the associated accounts without needing to defeat authentication controls. This type of attack is a shift from traditional credential theft, as it targets session artifacts and bypasses multifactor authentication (MFA). Anthropic signed affected users out of their Claude accounts, invalidating the stolen sessions, and removed saved payment methods to prevent further unauthorized charges. The attacks came to light via email alerts sent to affected users that were then posted on social media.
Technical Mitigations AI-generated
• Remove and patch Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows systems to prevent infostealer malware attacks. • Update or remove Atomic Stealer (AMOS) on Macs to stop the threat actor from stealing login sessions using this malicious app. • Enable two-factor authentication for Claude accounts after removing infostealers from users' systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Dark CaracalDark Caracal
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/08/31
Anthropic users were notified of and advised to take action against infostealer attacks that utilized various malware, including Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs.
threat_actor Dark Caracal
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources