Infostealers Are Replaying Claude Sessions to Burn Paid Usage. The Loot Is Not Your Data, It Is Your Compute. Here Is What Our Feed Carries on All Five Families, and the One We Have Nothing On.
- Patrick Duggan
- 1 day ago
- 5 min read
Anthropic began contacting affected Claude users on August 30 after finding that infostealer malware on their machines had siphoned active login session cookies. Attackers replayed those sessions and burned through the victims' paid usage. No password was needed. No login happened. Two-factor authentication and single sign-on were not defeated so much as skipped, because a valid session cookie is what you get after all of that.
Anthropic named the families: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs. It revoked the affected sessions, forced re-authentication, and removed saved payment methods so nobody could be charged for the ride.
Every one of those is a commodity stealer that has been in circulation for years. Nothing about the malware is new. What is new is what it was pointed at.
The Loot Is the Compute
Infostealers exist to monetize. The established paths are credentials for resale, crypto wallets, browser-stored card data, and session cookies for account takeover on services worth taking over. This campaign monetizes something that did not exist as a target three years ago: a paid inference budget.
The attacker does not want your files. They want the thing your subscription entitles you to do, and they want it billed to you. That is closer to cryptojacking than to credential theft, except the resource being stolen is not your CPU cycles, it is your quota with somebody else's model.
It is worth being precise about why this is cheap for them and expensive for you. Renting frontier-model capacity legitimately costs real money and increasingly requires identity, payment history and rate-limit reputation. A stolen session inherits all of that for free. The victim absorbs the spend, the rate limits, and eventually the questions about why their usage curve looks strange.
Any organization that has added an AI line to its budget in the last two years has created an asset class that can be stolen without a single byte of company data leaving the building. Most have no monitoring on it at all.
The Detection Was Behavioral, Not a Signature
The part of Anthropic's account we would underline is how it surfaced. Reporting says the pattern was noticed when usage limits refilled and then drained while the account owners were inactive.
That is not a malware signature and no endpoint agent produced it. It is a behavioral anomaly on a usage curve, spotted server-side by the party who could see the shape of normal. The account looked authenticated the entire time, because it was authenticated. Every credential control in the chain was working exactly as designed.
We keep arriving at the same conclusion from different directions, so we will state it again: when the credential is valid and the session is real, reputation and signature checks have nothing to say. The only tell left is behavior, and behavior is only legible to whoever holds the baseline. This is the same reason our own edge shield blocks on shape rather than on a list, and the same reason a stolen-but-valid session is the hardest thing in this business to catch from the outside.
If you run any AI spend, the actionable version is short. Your usage curve is a security signal. Somebody should own it.
What Our Feed Actually Carries on These Five
We hold indicators for four of the six named families. Here are the honest counts, and the method matters more than the numbers.
Searching our index for these family names returns wildly inflated totals, because the search estimate matches substrings and the same indicator can appear as several documents. A raw query for Vidar reports 9,411 hits. Counting only distinct indicator values whose malware family field actually matches Vidar gives 294. That is roughly a thirty-two-fold difference between the number that looks impressive and the number that is true, and we have written before about why we never quote the first one.
So, distinct indicator values, family field confirmed, deduplicated. Vidar: at least 294. StealC: at least 299. RedLine: at least 297. LummaC2: 38. Atomic Stealer: 1. Acreed: zero.
Three of those say "at least" because our pagination stopped at three hundred per query and the true figures are higher. We would rather publish a floor we can stand behind than an estimate we cannot.
Two of them are honest gaps. We carry exactly one Atomic Stealer indicator, a macOS payload URL, which is thin coverage of the family that hit the Mac users in this campaign. And on Acreed we have nothing. The twenty-five results a naive search returns for Acreed are npm packages with "agreed" in the name, matched on a substring. Zero of them are the stealer. If you were counting badly you would have reported coverage we do not have, which is exactly the failure mode we built the counting method to prevent.
Where Those Indicators Came From, Because It Is Not Us
Every single one of them is redistributed from somebody else's work. The sources are abuse.ch urlhaus and SSLBL. Not one indicator for any of these six families is a first-party DugganUSA observation.
We say that plainly because the alternative is laundering. urlhaus and SSLBL are free, excellent and universally available, and any defender pulling them directly had identical coverage on the same day we did. The credit for finding these payloads belongs to those projects and to the researchers who submit to them.
What we add is distribution and shape: the indicators arrive in one STIX feed with everything else, already deduplicated, already scored, already usable by a shop that does not have an analyst to babysit six feeds. For an under-resourced defender that is worth something. It is not a scoop and we are not going to dress it up as one.
What To Actually Do
Treat this as an endpoint incident, because it is one. A stealer got execution on a machine. The Claude session was one of the things it took, and it will not have been the only thing. Everything else that machine was signed into should be considered compromised: the browser cookie jar does not have a special protected section for the things you care about.
Rotate sessions rather than just passwords. A password change does not invalidate an already-stolen cookie unless the service explicitly revokes sessions, which is precisely why Anthropic forced re-authentication rather than just telling people to reset.
Pull saved payment methods out of anything that will let you. Anthropic did this for affected users automatically and it is a reasonable default for any account whose spend can be driven by an attacker.
And watch the usage curve. Refill-then-drain while the owner is asleep is the shape here. If you have a team AI spend, that curve is now part of your attack surface and somebody on your side should be looking at it, because the vendor will not always catch it first.
Sources and Credit
The disclosure is Anthropic's and the family list is theirs. Reporting from BleepingComputer, Help Net Security, SecurityWeek, Security Affairs and The Cyber Express. The indicators we hold for these families come from abuse.ch urlhaus and SSLBL and the credit for them is theirs, not ours.
We disclose our own interest plainly: we build on Anthropic's models and have said so in public for a year. That is a reason to be careful here, not a reason to be quiet, so the numbers above include the two families where our coverage is thin or absent.
We cap confidence at 95 percent. Something in here is probably wrong. If you find it, there is a security.txt at analytics.dugganusa.com and it works.
Our feed is free and carries these indicators along with about 1.7 million others. If you want the counting method rather than the marketing number, that is the whole point of this post.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=infostealers-are-replaying-claude-sessions-to-burn-paid-usage-the-loot-is-not-your-data-it-is-your




Comments