Infostealer Logs Threaten AI Credentials and Tokens

Serdar HocamAuthor & Editor

Cybercriminals are bypassing multi-factor authentication to access AI accounts using data harvested from infostealer malware.

◉ 0 views
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are infiltrating AI user accounts through infostealer software logs, seizing tokens and keys that bypass multi-factor authentication.

The Target of Infostealers

Cybercriminals are leveraging infostealer logs to compromise AI user accounts, thereby generating keys that provide unauthorized access to AI tools.

Infostealer malware such as Lumma Stealer or Vidar collects credentials, session tokens, and API keys from compromised systems and sells them on underground forums.

Data Breach Shared on Telegram

According to a report by Jeremy Kirk of Okta, threat actors specifically target session tokens and API keys in order to bypass identity-based authentication.

Okta analyzed a 7 GB infostealer dump published on Telegram on August 2, 2026, finding data belonging to 5,871 infected machines across 162 countries.

Bypassing Multi-Factor Authentication

Valid JWT data, usernames, passwords, and multi-factor authentication can be abused to gain direct account access while bypassing security.

Furthermore, it was discovered that 17.7% of these JWTs contain personally identifiable information in plain text.

Threats to AI Services

Analysis conducted using TruffleHog uncovered 24 still-valid API keys belonging to AI services such as Google Gemini, OpenAI, Groq, and OpenRouter.

This situation facilitates LLMjacking activities, where attackers abuse the keys for espionage or resource theft purposes.

Methods to Evade Security Measures

Cybercriminals use specialized browsers like Camoufox to load stolen session data, configure proxies, and evade security controls.

Google noted an increase in the number of threat actors looking to purchase AI-related accounts, which are being advertised on underground forums.