跳到主要內容

Claude帳號被駭評測:竊資軟體偷Session繞過雙重驗證 | Claude Session Hijack Review: Infostealers Bypass 2FA

By Kit 小克 | AI Tool Observer | 2026-09-01

🇹🇼 Claude帳號被駭評測:竊資軟體偷Session繞過雙重驗證

Anthropic 8月底發出警告:竊資軟體(infostealer)正鎖定 Claude 使用者,透過偷走瀏覽器裡的登入 Session Cookie 來繞過雙重驗證,直接冒用帳號把用量額度榨乾,甚至可能碰到已儲存的付款資訊。這不是 Claude 本身的漏洞,而是使用者電腦先中毒,AI 帳號只是被順手撈走的戰利品之一。

發生了什麼事:Vidar、Lumma、StealC 輪番上陣

根據 Anthropic 與多家資安媒體的說法,這波攻擊牽涉到 Windows 上常見的竊資軟體家族,包括 Vidar、Lumma(LummaC2)、StealC、RedLine、Acreed,Mac 用戶則有少量案例是被 Atomic Stealer(AMOS) 感染。這些惡意程式通常透過盜版遊戲、破解軟體或假冒的應用程式安裝包夾帶進電腦,一旦執行就會默默把瀏覽器裡儲存的密碼、Cookie 和其他本機應用程式的登入憑證整批打包外送。

攻擊怎麼運作:偷 Session 比偷密碼更狠

重點在於,這批竊資軟體偷的不是帳密,而是已登入的 Session Cookie。攻擊者只要把這串 Cookie 重放回瀏覽器,就能直接繞過雙重驗證(2FA)登入帳號,完全不需要密碼或驗證碼。有受害者反映,自己的 Claude 用量額度會莫名其妙被刷新又被吃光,人卻完全沒有主動使用——這正是帳號被冒用的典型徵兆。Anthropic 表示已偵測到異常,主動把受影響的 Session 全部登出,並先移除帳號內儲存的付款方式作為防護,同時退回未經授權的扣款。

你該怎麼做:3步驟自保

  • 掃毒優先:先用防毒軟體徹底掃描並移除電腦上的竊資軟體,不然重設密碼也沒用,新密碼一樣會被偷。
  • 重設關鍵密碼並開啟2FA:特別是信箱與付款相關帳號,同時檢查信用卡帳單有無異常扣款。
  • 登出所有裝置的Session:不只 Claude,其他常用的 AI 工具、雲端服務也一併檢查,重新登入一次讓舊 Cookie 失效。

這次事件也提醒大家:AI 帳號的安全性,九成掛在你自己電腦乾不乾淨上。盜版軟體、來路不明的安裝檔,才是整條攻擊鏈真正的破口。

好不好用,試了才知道。


🇺🇸 Claude Session Hijack Review: Infostealers Bypass 2FA

Anthropic warned in late August that infostealer malware is targeting Claude users, stealing browser session cookies to bypass two-factor authentication and hijack accounts outright — draining usage limits and, in some cases, exposing saved payment details. This isn't a vulnerability in Claude itself. It's a case of already-infected computers handing over AI account access as one more prize among many.

What Happened: Vidar, Lumma, StealC and Friends

According to Anthropic and multiple security outlets, the campaign involves well-known Windows infostealer families — Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed — plus a smaller number of Mac infections via Atomic Stealer (AMOS). These typically arrive bundled with pirated games, cracked software, or fake app installers. Once executed, they quietly scrape saved browser passwords, cookies, and credentials for other local apps, then ship the haul back to the attacker.

How the Attack Works: Stealing Sessions Beats Stealing Passwords

The key detail: this malware isn't after your password — it's after your active session cookie. Replay that cookie in a browser and you're logged in, no password or 2FA code required. Affected users reported their Claude usage limits refilling and then draining without them touching the service — a telltale sign of account hijacking. Anthropic said it detected the activity, signed out the compromised sessions, stripped saved payment methods as a precaution, and refunded unauthorized charges.

What You Should Do: 3 Steps

  • Scan and remove the malware first. Resetting passwords on an infected machine is pointless — the new ones get stolen too.
  • Reset critical passwords and enable 2FA, especially email and anything tied to payment, and check your card statements for anything unusual.
  • Sign out active sessions everywhere — not just Claude, but any AI tool or cloud service you use — and log back in fresh so old cookies stop working.

The bigger lesson: AI account security mostly comes down to how clean your own machine is. Pirated software and sketchy installers are the real weak link in this whole chain, not the AI product itself.

好不好用,試了才知道。

Sources / 資料來源

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code