Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
AI Summary
Information stealer malware such as Lumma Stealer and Vidar are harvesting session tokens and API keys from compromised systems, enabling threat actors to replay these credentials and gain unauthorized access to AI services like Google Gemini, OpenAI, Anthropic, and others, bypassing multi-factor authentication. A 7 GB infostealer dump analyzed by Okta contained 44,791 unique JSON Web Tokens (JWTs), 555 of which were likely tied to AI service authentication, along with 2,937 encrypted JWE structures, primarily from OpenAI. Attackers are using stolen tokens to access premium AI models and sell access on underground forums, leveraging anti-detect browsers like Camoufox to avoid detection. The abuse of valid, unexpired API keys and tokens—termed 'LLMjacking'—allows attackers to conduct espionage, resource theft, or run up AI service bills on victims.
AI-extracted · verify before operational use