Claude帳號被駭評測:竊資軟體偷Session繞過雙重驗證 | Claude Session Hijack Review: Infostealers Bypass 2FA
By Kit 小克 | AI Tool Observer | 2026-09-01
🇹🇼 Claude帳號被駭評測:竊資軟體偷Session繞過雙重驗證
Anthropic 8月底發出警告:竊資軟體(infostealer)正鎖定 Claude 使用者,透過偷走瀏覽器裡的登入 Session Cookie 來繞過雙重驗證,直接冒用帳號把用量額度榨乾,甚至可能碰到已儲存的付款資訊。這不是 Claude 本身的漏洞,而是使用者電腦先中毒,AI 帳號只是被順手撈走的戰利品之一。
發生了什麼事:Vidar、Lumma、StealC 輪番上陣
根據 Anthropic 與多家資安媒體的說法,這波攻擊牽涉到 Windows 上常見的竊資軟體家族,包括 Vidar、Lumma(LummaC2)、StealC、RedLine、Acreed,Mac 用戶則有少量案例是被 Atomic Stealer(AMOS) 感染。這些惡意程式通常透過盜版遊戲、破解軟體或假冒的應用程式安裝包夾帶進電腦,一旦執行就會默默把瀏覽器裡儲存的密碼、Cookie 和其他本機應用程式的登入憑證整批打包外送。
攻擊怎麼運作:偷 Session 比偷密碼更狠
重點在於,這批竊資軟體偷的不是帳密,而是已登入的 Session Cookie。攻擊者只要把這串 Cookie 重放回瀏覽器,就能直接繞過雙重驗證(2FA)登入帳號,完全不需要密碼或驗證碼。有受害者反映,自己的 Claude 用量額度會莫名其妙被刷新又被吃光,人卻完全沒有主動使用——這正是帳號被冒用的典型徵兆。Anthropic 表示已偵測到異常,主動把受影響的 Session 全部登出,並先移除帳號內儲存的付款方式作為防護,同時退回未經授權的扣款。
你該怎麼做:3步驟自保
- 掃毒優先:先用防毒軟體徹底掃描並移除電腦上的竊資軟體,不然重設密碼也沒用,新密碼一樣會被偷。
- 重設關鍵密碼並開啟2FA:特別是信箱與付款相關帳號,同時檢查信用卡帳單有無異常扣款。
- 登出所有裝置的Session:不只 Claude,其他常用的 AI 工具、雲端服務也一併檢查,重新登入一次讓舊 Cookie 失效。
這次事件也提醒大家:AI 帳號的安全性,九成掛在你自己電腦乾不乾淨上。盜版軟體、來路不明的安裝檔,才是整條攻擊鏈真正的破口。
好不好用,試了才知道。
🇺🇸 Claude Session Hijack Review: Infostealers Bypass 2FA
Anthropic warned in late August that infostealer malware is targeting Claude users, stealing browser session cookies to bypass two-factor authentication and hijack accounts outright — draining usage limits and, in some cases, exposing saved payment details. This isn't a vulnerability in Claude itself. It's a case of already-infected computers handing over AI account access as one more prize among many.
What Happened: Vidar, Lumma, StealC and Friends
According to Anthropic and multiple security outlets, the campaign involves well-known Windows infostealer families — Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed — plus a smaller number of Mac infections via Atomic Stealer (AMOS). These typically arrive bundled with pirated games, cracked software, or fake app installers. Once executed, they quietly scrape saved browser passwords, cookies, and credentials for other local apps, then ship the haul back to the attacker.
How the Attack Works: Stealing Sessions Beats Stealing Passwords
The key detail: this malware isn't after your password — it's after your active session cookie. Replay that cookie in a browser and you're logged in, no password or 2FA code required. Affected users reported their Claude usage limits refilling and then draining without them touching the service — a telltale sign of account hijacking. Anthropic said it detected the activity, signed out the compromised sessions, stripped saved payment methods as a precaution, and refunded unauthorized charges.
What You Should Do: 3 Steps
- Scan and remove the malware first. Resetting passwords on an infected machine is pointless — the new ones get stolen too.
- Reset critical passwords and enable 2FA, especially email and anything tied to payment, and check your card statements for anything unusual.
- Sign out active sessions everywhere — not just Claude, but any AI tool or cloud service you use — and log back in fresh so old cookies stop working.
The bigger lesson: AI account security mostly comes down to how clean your own machine is. Pirated software and sketchy installers are the real weak link in this whole chain, not the AI product itself.
好不好用,試了才知道。
Sources / 資料來源
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage - BleepingComputer
- Anthropic locks out Claude users after infostealers hijack login sessions - Help Net Security
- Anthropic Warns Claude Users of Infostealer Malware Infections - SecurityWeek
延伸閱讀 / Related Articles
- AI推理外洩評測:三大廠共用金鑰爆重大漏洞 | AI Reasoning Leak Review: One Shared Key Burns 3 Labs
- Tencent Hy4評測:770B開源模型贏過GLM-5.3與Kimi K3 | Tencent Hy4 Review: 770B Open Model Beats GLM-5.3
- DeepSeek融資評測:估值兩個月翻倍衝上750億美元 | DeepSeek Funding Review: Valuation Doubles to $74B in Two Months
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言