Hackers Are Abusing Claude to Deliver Malware That Steals Credentials and Login Sessions

BY
/
Aug 31, 2026

Attackers are abusing Anthropic’s Claude platform and branding to make malware campaigns appear legitimate, using features such as public Claude Artifacts and fake software downloads to steal browser credentials, session cookies and other sensitive information.

The campaigns are particularly relevant to users who access cryptocurrency exchanges, financial accounts or other high-value services from the same devices, as the malware families involved can collect information that may expose those accounts.

The most notable case emerged in July, when the cybersecurity firm Huntress tracked a campaign dubbed “FakeAgent” that used search-engine advertising to target people looking for the Claude Desktop application.

Instead of taking users directly to an official download, the campaign directed them to a malicious Claude Artifact hosted on the legitimate claude.ai domain.

The Artifact then redirected victims to attacker-controlled websites serving what appeared to be a Claude Desktop installer.

The downloaded file ultimately delivered SectopRAT, an information-stealing remote-access Trojan.

At least 29 organizations were compromised over July 21 and 22, according to Huntress, while the malicious Artifact accumulated roughly 7,100 views before Anthropic removed it after being notified.

The Trick Was Using Something Legitimate

The campaign did not require attackers to create a convincing imitation of Claude from scratch.

Instead, they used part of Claude’s legitimate infrastructure to establish credibility.

A user searching for Claude Desktop could encounter an advertisement leading toward the malicious Artifact. Because the Artifact was hosted on claude.ai, the first stage of the journey appeared to be associated with the legitimate AI service.

The Artifact itself was not the malware.

It functioned as part of the delivery chain, ultimately directing the user toward an external download.

That distinction is important.

Claude was not installing SectopRAT on users’ computers. Attackers were abusing Claude’s legitimate platform and branding as part of a malware campaign.

The downloaded “ClaudeDesktop.exe” file also demonstrated another common technique in modern malware campaigns: abusing legitimate software components.

Huntress found that the installer used a legitimate JetBrains binary that was manipulated through DLL sideloading to load the malicious payload.

In simple terms, attackers made a malicious program borrow the appearance or functionality of legitimate software components, making the infection harder to detect.

What the Malware Is Looking For

The ultimate target is not necessarily Claude.

Information-stealing malware is designed to search a compromised computer for valuable information, particularly data stored inside web browsers.

That can include:

  • saved usernames and passwords;
  • browser session cookies;
  • autofill information;
  • payment details;
  • files;
  • cryptocurrency-related credentials; and
  • other account information.

For crypto users, this creates a second layer of risk.

A malware infection does not necessarily have to directly access a Bitcoin or crypto wallet to cause financial damage. If it obtains credentials or browser session information for an exchange or financial service, attackers may be able to use that information to access accounts holding funds.

The risk is especially relevant when the same computer is used for everyday browsing, AI applications and financial activity.

The Bigger Problem: Your Password May Not Be the Only Thing at Risk

Anthropic has separately begun warning users about another consequence of information-stealing malware: the theft of already-authenticated browser sessions.

This works differently from simply stealing a password.

When a user logs into a website, the browser receives information that tells the service the user has already authenticated. That information can allow the session to remain active without requiring the user to enter a password on every page.

An attacker who steals the relevant session cookie may be able to reuse that authenticated session.

That means the attacker does not necessarily need to know the victim’s password.

In some cases, they may also avoid having to defeat two-factor authentication through a conventional login attempt because they are taking over a session that has already passed the authentication process.

Anthropic said that common infostealers including Vidar, LummaC2, StealC, RedLine and Acreed on Windows, as well as Atomic Stealer on some macOS systems, have been observed stealing Claude browser sessions.

The company has been signing affected users out, removing saved payment methods and refunding unauthorized charges.

But there is an important limitation: logging out of Claude does not remove malware from the computer.

If the underlying device remains infected, newly generated credentials or sessions can potentially be exposed again.

Why This Matters to Crypto Users

For someone holding crypto, the distinction between a stolen password and a stolen browser session can be significant.

A browser may contain access to multiple services at once: email, exchanges, payment platforms, cloud accounts and other applications.

An infostealer can therefore turn one infected computer into a source of information about several parts of a user’s digital financial life.

That does not mean every infection will result in stolen cryptocurrency.

It does mean that users should not treat browser credentials as low-value information simply because their crypto itself is stored elsewhere.

An exchange account, for example, can provide access to trading functions, withdrawal settings or other sensitive account information even when the underlying assets are held on the platform rather than directly in the browser.

Public Claude Features Can Also Become Part of the Attack Surface

The FakeAgent campaign highlights a broader problem for platforms that allow users to publish or share content.

Claude Artifacts are legitimate Claude functionality. The issue is that attackers can use legitimate user-facing features as part of a social-engineering or malware-delivery chain.

That makes the old rule of checking whether a website “looks legitimate” less useful on its own.

In this case, part of the journey actually was legitimate.

The user was interacting with a real Claude domain before being redirected elsewhere.

The same principle applies to shared conversations, downloadable files and other user-generated content: the fact that something appears inside a trusted platform does not automatically make the content itself trustworthy.

Anthropic Has Removed the Reported Threats

Anthropic removed the malicious Artifact after Huntress reported it.

The company has also been responding to the separate session-theft problem by invalidating affected sessions, removing saved payment methods and refunding unauthorized charges.

Huntress, meanwhile, documented the FakeAgent campaign and its SectopRAT payload, including technical indicators that organizations can use to investigate potential infections.

The incident also produced an unusual defensive lesson.

Huntress was able to use Claude in portions of its malware analysis, while Hugging Face’s security team has reported encountering situations where commercial AI models refused to process real attack commands and payloads during forensic work because their safety systems could not reliably distinguish defensive investigation from offensive activity.

That has strengthened the case for security teams maintaining locally deployable AI tools that can be used during an incident without sending sensitive attack data outside the organization’s environment.

What Users Should Do

The most practical defense remains controlling what reaches the device in the first place.

Users looking for Claude Desktop or other software should download it through Anthropic’s official channels rather than search advertisements or third-party download sites.

Public Claude Artifacts and shared content should also be treated as user-generated material, not automatically trusted software.

For people who regularly access financial or cryptocurrency accounts, separating those activities from general-purpose browsing can further reduce exposure.

If a device is suspected of being infected, changing passwords alone is not enough.

The safer sequence is to:

  1. Remediate the infected device.
  2. Revoke active account sessions.
  3. Rotate passwords and other credentials.
  4. Review recent account activity.
  5. Check cryptocurrency exchanges and financial services for unauthorized activity.
  6. Review browser extensions, downloaded files and other potential persistence mechanisms.

Users should also remember that some of the campaigns described by security researchers use persistence and anti-analysis techniques, including scheduled tasks and other mechanisms designed to survive or evade ordinary cleanup.

GET MORE OF IT ALL FROM
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Recommended reads from the metaverse