Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Imagine a world where the invisible gatekeepers of our digital lives—the keys that unlock our artificial intelligence accounts—are not as unique and unbreakable as we were led to believe. For years, the promise of AI has been guarded by complex security measures, including Multi-Factor Authentication, designed to ensure that only the rightful owner can wield these powerful tools. Yet, a disturbing new reality is emerging where cybercriminals are turning their attention to the very mechanisms meant to protect us, exploiting the trust placed in stolen credentials to bypass these defenses entirely.

At the heart of this threat lies the evolution of information stealers, sophisticated malware variants like Lumma Stealer and Vidar that have become the Swiss Army knives of the cybercrime underworld. These tools are no longer content with simply harvesting usernames and passwords; they are now programmed to siphon session tokens and API keys from the systems they infect. In the context of AI, these tokens represent the cryptographic signatures that prove a user's identity to providers like Google and Anthropic. When these stealers successfully extract them, they create what researchers are calling "stolen keys," effectively granting the attacker a temporary but potent passport into the AI ecosystem.

Read the full article →

Comments