Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Executive Summary

Cybercriminals harvest credentials, session tokens, and API keys from compromised systems using infostealers such as Lumma Stealer or Vidar. The stolen data is used to create replayable AI tokens that bypass MFA, granting illicit access to AI services from providers like Google and Anthropic.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-09T14:23:55+00:00 - Category: threat-intel

Original Description: Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

"A rolling stone gathers no moss."

— Publilius Syrus
Source: The Hacker News