Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are using information stealer logs to hijack AI accounts and replay stolen session tokens, JWTs, JWEs, and API keys from providers such as Google, Anthropic, OpenAI, and others. The findings show a growing underground market for AI access, where stolen credentials are resold for LLMjacking, espionage, extortion, and resource theft. #LummaStealer #Vidar #Google #Anthropic #OpenAI #Mandiant #ChatGPT #Claude #Gemini #Cursor #Poe #PikaAI

Keypoints

  • Infostealer logs are being used to collect AI account tokens and API keys.
  • Stolen session tokens can bypass password and MFA protections through replay attacks.
  • The analyzed dump contained data from 5,871 infected machines across 162 countries.
  • Valid API keys for Google Gemini, OpenAI, Groq, and OpenRouter were also found.
  • Cybercriminals are selling stolen AI access on underground forums and Telegram channels.

Read More: https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html