Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyberattack Targets Claude AI with Infostealer Malware

Cyberattack Targets Claude AI with Infostealer Malware

Posted on August 31, 2026 By CWS

The Claude AI platform, developed by Anthropic, has recently become a significant target for cybercriminals, with confirmed reports of two distinct attack chains aimed at compromising user accounts. These attacks involve the theft of login credentials, unauthorized usage of paid services, and the reinfection of devices even after cleanup efforts.

The Extent of the Breach

Anthropic is actively responding to this threat by signing out affected accounts, removing stored payment methods, and issuing refunds for unauthorized transactions. The company is working diligently to mitigate the damage caused by these breaches.

According to Anthropic’s advisory, several infostealer malware families, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS, are involved. These malware variants are designed to quietly extract saved passwords, browser cookies, and locally stored credentials from infected systems.

Mechanics of the Attack

The infostealer malware operates by capturing already-authenticated session cookies, effectively bypassing two-factor authentication and single sign-on defenses. This allows attackers to replay the victim’s session, using their paid resources without needing direct login access. Anthropic identified this pattern after observing account usage limits being reset and depleted while account holders remained inactive.

In a related development, security firm Huntress has tracked a threat named FakeAgent, which exploits Claude’s infrastructure. Between July 21 and July 22, 2026, users searching for the “Claude desktop app” on Bing encountered sponsored ads leading to a malicious Claude Artifact hosted on the legitimate claude.ai domain. This malicious installer, disguised as ClaudeDesktop.exe, executed DLL sideloading to deploy SectopRAT, a remote access trojan that collects browser credentials and other sensitive data.

Ongoing Threats and Recommendations

Another emerging threat involves poisoned SKILL.md files, configuration files used by Claude’s agent skills. Attackers insert malicious instructions disguised as ordinary notes, enabling the persistent re-download of infostealer malware even after a full system reinstall if the tainted file is reintroduced.

Anthropic has taken steps to address these issues by signing out compromised sessions and removing stored payment methods. However, these measures do not eliminate malware from infected devices. Security experts recommend conducting thorough malware scans before logging back into Claude, resetting associated email passwords with two-factor authentication, and updating browser-stored credentials.

Organizations using Claude should also sandbox AI environments and audit SKILL.md or similar files for hidden commands. This incident highlights the importance of treating AI-suggested links or commands with the same caution as suspicious email attachments to prevent future breaches.

For comprehensive protection, integrating threat intelligence and auditing practices is crucial for organizations deploying AI technologies at scale.

Cyber Security News Tags:account hijacking, AI security, Anthropic, Claude AI, Cybersecurity, DLL Sideloading, FakeAgent threat, infostealer malware, malware prevention, Web3 security

Post navigation

Previous Post: TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Related Posts

BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters Cyber Security News
Microsoft Enhances Teams for iOS and Android Microsoft Enhances Teams for iOS and Android Cyber Security News
Microsoft October 2025 Security Update Causes Active Directory Sync Issues on Windows Server 2025 Microsoft October 2025 Security Update Causes Active Directory Sync Issues on Windows Server 2025 Cyber Security News
Fired Intel Engineer Stolen 18,000 Files Many of which Were Classified as “Top Secret” Fired Intel Engineer Stolen 18,000 Files Many of which Were Classified as “Top Secret” Cyber Security News
Banana RAT Targets Brazilian Financial Sector with NF-e Lures Banana RAT Targets Brazilian Financial Sector with NF-e Lures Cyber Security News
New LOSTKEYS Malware Linked to Russia State-Sponsored Hacker Group COLDRIVER New LOSTKEYS Malware Linked to Russia State-Sponsored Hacker Group COLDRIVER Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor
  • OpenAI Withdraws AI Models from Cursor Amid SpaceX Takeover
  • Critical WordPress Plugins, Themes Vulnerabilities Exposed
  • Hasbro Data Breach Risks Employee Information Exposure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor
  • OpenAI Withdraws AI Models from Cursor Amid SpaceX Takeover
  • Critical WordPress Plugins, Themes Vulnerabilities Exposed
  • Hasbro Data Breach Risks Employee Information Exposure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark