Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Executive Summary
Cybercriminals harvest credentials, session tokens, and API keys from compromised systems using infostealers such as Lumma Stealer or Vidar. The stolen data is used to create replayable AI tokens that bypass MFA, granting illicit access to AI services from providers like Google and Anthropic.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-09T14:23:55+00:00 - Category: threat-intel
Original Description: Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
"A rolling stone gathers no moss."
— Publilius Syrus