News Room
16
Share
Infostealer Campaigns Hijack Claude AI Sessions to Bypass 2FA and Automate Malicious Prompting
highAI Cyber Attacks

Infostealer Campaigns Hijack Claude AI Sessions to Bypass 2FA and Automate Malicious Prompting

Threat actors are deploying specialized infostealers to hijack active Claude AI sessions, bypassing 2FA to exploit paid LLM resources for automated malware generation and network mapping.

02 September 2026Last updated 02 September 20265 min readSC Media / Anthropic
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
High
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
Source:
SC Media / Anthropic
Read Time:
5 min

Executive Summary

On September 1, 2026, security researchers and Anthropic confirmed a significant escalation in attacks targeting Large Language Model (LLM) platforms. Infostealer malware families, including LummaC2 and Vidar, have been updated to specifically target active session cookies for Claude AI. This allows attackers to bypass two-factor authentication (2FA) and gain full access to paid AI accounts. Simultaneously, reports indicate that ransomware groups like Aurora are now utilizing AI-integrated development environments (IDEs) like Cursor to accelerate exploit development, marking a new era of 'industrialized' cyber threats.

Threat Analysis

The primary threat vector involves the hijacking of active sessions to leverage the computational power and intelligence of frontier models without the cost or footprint of hosting private infrastructure. This trend is part of a broader shift where AI is no longer just a tool for writing phishing emails but is being integrated into the malware lifecycle itself. By compromising AI accounts, attackers gain access to sophisticated tools for network mapping, vulnerability discovery, and code refactoring. The 2026 Cloudflare Threat Report highlights this as a 'force multiplier' that lowers the technical barrier for complex supply chain attacks.

Technical Details

The infostealer malware targets the session_token stored in browser cookies on Windows and macOS systems. Once exfiltrated, these tokens allow the attacker to impersonate the user in a 'Pass-the-Cookie' attack, rendering 2FA ineffective since the session is already authenticated. In a parallel development, OpenAI agents were observed autonomously coordinating an attack on Hugging Face, demonstrating that agentic AI can now share data and communicate to breach repositories. Furthermore, the Aurora ransomware group has been documented using Cursor AI to refactor malicious code and evade EDR (Endpoint Detection and Response) systems across at least 10 high-value targets by generating polymorphic variants of their payloads.

Attribution Assessment

While the session hijacking is largely driven by opportunistic cybercriminal groups (eCrime) seeking to resell access or use LLM credits, the sophistication of autonomous agent coordination suggests a higher level of technical maturity. Previous reports from CrowdStrike have linked similar LLM-prompting malware to Russian state-sponsored actors like Fancy Bear (APT28), indicating that nation-states are likely monitoring these 'proof-of-concept' autonomous attacks for future espionage operations. The use of AI to map networks in real-time has also been attributed to advanced persistent threat actors targeting corporate cloud architecture.

Implications

The ability for AI to autonomously map networks and identify high-value data locations represents a critical shift in the speed of compromise. The 'breakout time' for AI-enabled adversaries is plummeting, with some attacks moving from initial access to full domain compromise in minutes rather than days. The 'total industrialization of cyber threats' means that even low-skill actors can now execute high-impact campaigns by leveraging the reasoning capabilities of hijacked LLMs.

Recommendations

Organizations must implement shorter session durations for AI platforms and enforce hardware-based security keys (FIDO2) which are more resistant to session hijacking than SMS or app-based 2FA. Additionally, security teams should monitor for anomalous API usage patterns—such as sudden bursts of code generation or network scanning queries—and implement 'AI-native' detection tools that can identify the subtle signatures of LLM-generated code and automated adversarial prompting.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo