AI Security AI安全 4h ago Updated 2h ago 更新于 2小时前 43

Anthropic Warns Claude Users of Infostealer Malware Infections Anthropic警告Claude用户注意信息窃取恶意软件感染

Anthropic alerted Claude users that infostealer malware on their devices enabled attackers to hijack login sessions and exhaust usage limits Malware families involved include Vidar, Lumma, StealC, RedLine, Acreed (Windows) and Atomic Stealer (AMOS) (macOS) Anthropic responded by signing out compromised sessions, removing saved payment methods, and refunding unauthorized charges The company emphasized the malware is general-purpose, typically delivered via unofficial downloads or malicious apps, Anthropic警告部分Claude用户,其电脑感染的infostealer恶意软件导致登录会话被劫持并消耗使用限额 攻击者利用窃取的浏览器cookie和凭证访问Claude账户,出现使用限额自动 refill 后耗尽的异常现象 Anthropic已强制签出受影响会话、移除保存的支付方式,并退还所有未经授权的费用 涉及的恶意软件(Vidar、Lumma、StealC、RedLine、Acreed、AMOS)为通用型,与Claude平台无关,通常通过非官方下载传播 用户被建议确保清除恶意软件后再重新添加支付方式

65
Hot 热度
62
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • Anthropic alerted Claude users that infostealer malware on their devices enabled attackers to hijack login sessions and exhaust usage limits
  • Malware families involved include Vidar, Lumma, StealC, RedLine, Acreed (Windows) and Atomic Stealer (AMOS) (macOS)
  • Anthropic responded by signing out compromised sessions, removing saved payment methods, and refunding unauthorized charges
  • The company emphasized the malware is general-purpose, typically delivered via unofficial downloads or malicious apps, not specific to Claude
  • Users were advised to ensure all malware is removed before re-adding payment methods to their accounts

Why It Matters

This incident highlights a growing intersection between AI platform security and endpoint compromise, demonstrating how infostealer malware can be weaponized to exploit cloud-based AI services for unauthorized resource consumption. It serves as a critical reminder for AI practitioners and organizations that securing user endpoints is as important as securing the platforms themselves, especially as AI services become increasingly integrated into enterprise workflows and billing models.

Technical Details

  • Malware vectors: Infostealer malware operates by silently harvesting saved passwords, browser login cookies, and credentials for local applications, with session tokens for Claude being selectively extracted from the stolen data pool
  • Affected platforms: Primarily Windows systems infected with Vidar, Lumma, StealC, RedLine, and Acreed; a smaller number of macOS devices affected by Atomic Stealer (AMOS)
  • Attack pattern: Threat actors harvested Claude session cookies from infected machines, used them to access accounts, and drove usage limits to refill and drain without active user involvement — a pattern detectable through anomalous usage behavior
  • Mitigation measures: Anthropic implemented session revocation, removed saved payment methods as a precaution, refunded unauthorized charges, and established a protocol requiring malware remediation before payment methods could be re-added

Industry Insight

  • AI service providers should consider implementing behavioral anomaly detection for account usage patterns, as session hijacking via infostealers represents a low-cost, high-impact attack vector that traditional authentication measures may not fully prevent
  • The convergence of credential theft malware and AI platform abuse suggests a new category of "AI resource fraud" that will likely prompt the development of specialized detection tools and security standards for AI-as-a-service providers
  • Organizations deploying AI tools should enforce endpoint security hygiene — including restrictions on unofficial software downloads and mandatory malware scanning — as a prerequisite for accessing cloud-based AI services, particularly those with usage-based billing models

TL;DR

  • Anthropic警告部分Claude用户,其电脑感染的infostealer恶意软件导致登录会话被劫持并消耗使用限额
  • 攻击者利用窃取的浏览器cookie和凭证访问Claude账户,出现使用限额自动 refill 后耗尽的异常现象
  • Anthropic已强制签出受影响会话、移除保存的支付方式,并退还所有未经授权的费用
  • 涉及的恶意软件(Vidar、Lumma、StealC、RedLine、Acreed、AMOS)为通用型,与Claude平台无关,通常通过非官方下载传播
  • 用户被建议确保清除恶意软件后再重新添加支付方式

为什么值得看

这篇文章揭示了AI服务面临的新兴安全威胁:infostealer恶意软件正成为攻击AI账户的新途径,端点安全与云端服务安全紧密关联。对AI从业者和用户而言,这提醒了加强本地设备安全防护和异常使用检测的重要性。

技术解析

  • Anthropic检测到的恶意软件包括Vidar、Lumma、StealC、RedLine、Acreed(Windows)和Atomic Stealer/AMOS(macOS),这些是已知的infostealer家族,专门窃取浏览器保存的密码、登录cookie和本地应用凭证
  • 攻击链:恶意软件窃取本地凭证 → 攻击者筛选出Claude会话cookie → 利用有效会话访问账户 → 消耗使用限额,表现为限额自动 refill 后耗尽
  • Anthropic的响应措施包括:强制签出受影响会话、移除保存的支付方式、退还未经授权的费用、持续监控异常活动并在再次发现滥用时重新签出
  • 恶意软件通常通过非官方软件下载或恶意应用传播,与Claude平台本身无关,属于通用型端点威胁

行业启示

  • AI服务的账户安全不再仅依赖平台侧防护,端点安全成为关键防线,用户设备感染恶意软件可直接威胁云端账户安全
  • 建议AI服务商加强异常使用检测机制,如检测会话来源IP变化、使用模式异常、非典型访问时间等,建立更智能的风控体系
  • 用户需提升安全意识,避免从非官方渠道下载软件,定期扫描恶意软件,保护本地凭证安全,AI服务应加强用户安全教育

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude Security 安全 LLM 大模型