Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
-
Cybercriminals are increasingly hijacking AI user accounts through information stealer logs, turning stolen credentials into "stolen keys" that provide illicit access to tools from model providers such as Google, Anthropic, and others.
Information stealers like Lumma Stealer and Vidar are built to harvest a broad range of data from compromised systems, including credentials, session tokens, and API keys. Because these tokens can be replayed, attackers may be able to bypass MFA protections and gain access to AI accounts without triggering typical authentication barriers.
Key points:
- Attackers rely on infostealer logs to obtain replayable AI tokens.
- Lumma Stealer and Vidar are cited as examples of malware capable of harvesting credentials, session tokens, and API keys.
- Affected providers include Google, Anthropic, and other model providers.
- Replayable tokens can allow access that circumvents MFA.
Source: The Hacker News
Has your organization reviewed AI account tokens and session logs for signs of replay-based access?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login