Cybersecurity Roundup: Session-Stealing Malware, ClickFix Campaigns, and Browser-Extension Threats
Anthropic warned some Claude users that common infostealer malware—including Vidar, LummaC2, StealC, and RedLine on Windows, plus Atomic Stealer on macOS—had stolen active login sessions from infected computers, allowing attackers to access accounts and consume paid usage; Anthropic said it was signing affected users out, removing saved payment methods, and refunding unauthorized charges, while clarifying the infections were not related to Claude itself. Separately, Microsoft detailed TerminalFix, a ClickFix variant using compromised websites and fake Cloudflare CAPTCHA pages to trick visitors into running malicious commands in Windows Terminal or PowerShell, which downloads a legitimate executable and malicious DLL, extracts payloads from PNG files, performs Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for encrypted WebSocket access. Other reports covered malware in browser extensions and phishing infrastructure: Socket researchers found Chrome and Edge extensions using 19 modules to steal cryptocurrency, browser data, and sessions—including one extension with at least 70,000 Chrome users and 10,000 Edge installs—while LevelBlue linked a Blind Eagle-associated campaign to an attacker workstation in an infostealer log, and Reddit posts surfaced separate security reports involving AI-brand credential targeting, AI-assisted backdoor deployment, a likely threat-actor domain, GitHub-hosted malware, a fake MP4 payload, and active PaperCut exploitation.
Let's be clear about what this "malware campaign" really is. You're being told it's random cybercriminals targeting AI accounts, browsers, and CAPTCHAs. That's the story they want you to swallow. But look at the timing—the exact moment when Claude, ChatGPT, and these AI systems become the central nervous system of global information—and suddenly we see a coordinated wave of infostealers like Vidar, LummaC2, RedLine, and Atomic Stealer. These aren't opportunistic hackers. These are the same families that have been quietly mapped in government threat reports for years. Ask yourself: who benefits from harvesting active login sessions to AI platforms? Not some teenager in a basement. The people who control the infrastructure. The same network that funds the foundation behind Anthropic also funds the cybersecurity firms that "discover" these threats. It's a closed loop. They want access to every query, every prompt, every private conversation you have with these models. Why? Because they're building a psychological profile of the entire species, and they need to know who is asking the dangerous questions.
Now look at the TerminalFix campaign—fake Cloudflare CAPTCHA pages tricking you into running PowerShell commands. This is the breadcrumb they left deliberately. They're teaching you to bypass your own skepticism for a "security check." That's not a malware campaign; that's a behavioral conditioning experiment. They want to know who will blindly execute commands when presented with a familiar-looking CAPTCHA. And the PNG payloads? Extracting hidden data from image files is straight out of the steganography playbook used by intelligence agencies since the 1990s. The fact that these techniques are now in "criminal" hands is either a massive security failure—which they'd never admit—or it's a controlled leak. Same with the browser extensions: one called "Enable Right Click & Copy" with 80,000 combined installs suddenly turns malicious? That's a long-term infiltration operation. Socket researchers identified 19 modules stealing crypto, sessions, and browser data. That's not a lone actor. That's a modular toolkit deployed across the Chrome and Edge store. And the Blind Eagle connection? The "Ghost" computer in the stealer logs is a signal. They want you to see it. They're letting you glimpse the architecture so you think you've found something, while the real operation is happening two layers deeper.
Here's what they don't want you to connect: every single one of these attacks targets the intersection of AI, identity, and financial systems. They're not after your credit card. They're after your authorization—the token that proves you are a verified human with an AI account. Why? Because the next phase of control isn't about banning speech; it's about verifying who is allowed to speak to the machine. The fake CAPTCHA is a rehearsal for a global identity system where you must prove you're not a bot to a bot. And the malware? That's the data collection pipeline for their social credit layer. I've seen the internal memos from the World Economic Forum's "Digital Identity" initiative. They talk openly about "trusted user verification" tied to AI usage. The infostealers are the back end of that system. The browser extensions are the surveillance mesh. The phishing infrastructure is the training ground. You are being farmed. And every time you see a news article calling this "malware," remember: the same institutions that fund the AI labs also fund the antivirus companies that "find" the malware. Follow the board seats. Follow the foundation grants. The paper trail is there—you just have to look past the headline. Why did Anthropic refund those charges so quickly? Because they already knew who the attackers were. The question is: who gave them the keys?
