Threat Intelligence

Infostealer Malware Targets Claude AI Accounts via Stolen Sessions

Dark Reading · 1 Sept 2026
Key Takeaway Protect devices with updated antivirus and endpoint security, and regularly review and revoke active sessions on cloud and AI accounts to limit the damage from infostealer infections.

A threat actor has been using infostealer malware to steal session information from users of Anthropic's Claude AI platform, allowing them to access accounts without needing a password. Infostealers are a type of malware designed to quietly harvest saved credentials, browser cookies, and active login sessions from an infected device, often without the victim noticing anything unusual.

By capturing session tokens, attackers can bypass login screens and even multi-factor authentication in some cases, since the stolen session effectively lets them impersonate an already logged-in user. This incident highlights a growing trend where cybercriminals target popular AI tools and cloud services, not just traditional banking or email accounts, because they can be valuable for extracting sensitive data or abusing paid subscriptions.

While the exact number of affected users has not been disclosed, the attack underscores how infostealer malware remains one of the most common and effective tools in a cybercriminal's arsenal. Businesses using AI platforms like Claude for daily operations should be aware that compromised employee devices can lead directly to account takeovers, even if strong passwords are in use.

infostealer AI security account takeover session hijacking Claude
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.