Wire Observer.
Technology

Anthropic’s Claude AI Platform Hit by Credential‑Stealing Malware Campaigns

Anthropic’s Claude AI Platform Hit by Credential‑Stealing Malware Campaigns

Anthropic, the creator of the Claude artificial‑intelligence chatbot, confirmed that its service is now being targeted by cyber‑criminals employing sophisticated malware to capture user login sessions and take control of paid accounts.

Security researchers have identified two separate attack chains that use an infostealer payload to harvest authentication tokens from users' browsers. Once the malware extracts the session cookies, attackers can log in as the victim, consume paid compute credits and, in some cases, deploy additional malicious code to the infected device.

The campaigns appear to be automated, with the stolen credentials being sold or reused across multiple Claude accounts. Researchers observed that even after users run standard cleanup tools, the malware can reinstall itself, allowing the threat actors to maintain persistent access and continue siphoning resources.

In response, Anthropic has begun forcibly signing out users whose sessions were identified as compromised. The company is also urging customers to enable any available multi‑factor authentication options and to monitor their usage dashboards for unexpected activity.

Industry observers note that the targeting of AI platforms reflects a broader trend: as generative‑AI services become more integral to business workflows, they present lucrative targets for attackers seeking to exploit paid APIs and the valuable data processed by these models.

Anthropic has not disclosed the exact number of affected accounts, but the incident underscores the importance of robust endpoint protection and vigilant credential management for organizations integrating AI tools into their operations. The firm says it will continue to work with security partners to track the threat actors and improve defensive measures.

Aarav Mehta — Technology desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related