Fetches were blocked, so I’ll work from search snippets and the story summaries you already provided.TITLE: Infostealer Logs Expose Replayable AI Tokens Past MFA

Information stealers such as Lumma Stealer and Vidar now pull API keys and session tokens for Google, Anthropic, and other model providers off infected desktops, then dump them into criminal logs that buyers replay with no MFA challenge. Most cybersecurity programs still score those secrets as leftover browser debris. They function as standing access.

You already rotate the password after a stealer hit. You probably leave the ChatGPT, Gemini, or Claude session in the same profile untouched. Attackers noticed. The logs are full of what researchers are calling stolen keys: replayable tokens that walk into AI consoles and APIs as the user, long after the phishing page and the one-time code have finished their shift.

Cybersecurity Telemetry Treats Harvested AI Tokens as Browser Junk

Lumma, Vidar, and their cousins have always been good at vacuuming browsers. Cookies, saved logins, autofill, crypto wallets, the usual haul. The new inventory line is the AI stack. Session cookies and long-lived API tokens for model providers survive in the same Chrome and Edge profiles your staff use to summarize contracts and paste customer data into a prompt window.

Illustration of harvested session tokens and API keys sitting in criminal log dumps
Stealer logs now list AI provider sessions next to mailbox cookies. Buyers replay them as-is.

Replay is the part your threat detection was never asked to see. Nobody is running a brute-force campaign against the AI vendor. They paste a live token from a marketplace dump and inherit the employee’s context. Your firewall already allows that destination. The traffic is TLS to a sanctioned SaaS name your acceptable-use policy blessed last quarter. Endpoint threat-protection may catch the stealer on Tuesday and still miss the token reuse from a rented VPS on the following Wednesday.

This is a bad look for cyber security programs that close infostealer tickets at “password reset plus MFA re-enrollment.” The IdP did its job. The AI token never lived there. It lived in a browser origin, a local storage key, or an API secret a developer dropped into an env file that the stealer also reads. Until incident response treats that material as a credential class, you are rotating the lock on the front door and leaving the badge printer in the lobby.

Unauthenticated Workflow Identities Hijack Data With One Request

Human tokens are half of the identity mess. Dark Reading’s reporting on workflow identity hijacking describes the machine half: an attacker sends a basic request through an unauthenticated entry point and rides a workflow’s identity into systems that look locked down from the user’s side. No password prompt. No MFA push. The workflow already has permission to touch the data, so the request looks in-policy.

You built AI helpers that file tickets, fetch records, and summarize mailboxes. Those helpers authenticate as themselves, or they inherit a service identity you minted so the demo would stop failing. Standard controls sit in front of people. They do not sit in front of the webhook, the unauthenticated trigger, or the “internal only” automation URL someone exposed so a model could call it. Hijacking that identity is quieter than phishing the CFO, and it scales better.

The real problem here is enrollment. AI user sessions and AI workflow identities never got the same lifecycle you give VPN certs and admin roles. Short TTL, explicit owner, revocation path, anomaly alerts when the token shows up from a new ASN. Skip that work and defense in depth becomes a slide. The stack is deep in front of humans and empty in front of the agent.

Commodity YouTube Lures Drop Stealers; Extensions Can Proxy the Rest

Getting the stealer on the box still matters, and Unit 42’s PPI-network investigation is a reminder that the delivery layer has gone boring on purpose. Operators used YouTube gaming lures and SEO poisoning to push multi-payload malware into enterprise networks while hiding behind commodity infrastructure. Shared hosts, throwaway domains, traffic that looks like ads and game clips. Your hunting rules that still key on “known bad C2 families” will undercount this. The payload is custom enough to hurt. The pipe it rides is rented and forgettable.

Diagram-style graphic of malware categories delivered through commodity infrastructure
Unit 42 tracked multi-payload malware riding YouTube gaming lures and poisoned search results, not a flashy unique C2 fleet.

Once the browser is in play, you should assume more than cookies are in scope. Fortinet just patched critical, unauthenticated bugs in FortiMonitorOnSight and its Chrome extension. The flaws let an attacker bypass authentication and proxy a user’s browser traffic. A monitoring add-on with that reach is a wiretap waiting for a patch gap. Vendor-neutral translation: any extension that can see or proxy web requests sits on the same plane as the AI tokens you are trying to protect. Security-branded does not mean out of scope.

Put the week together and the path is short. SEO or a gaming video gets the stealer in. The stealer lifts AI sessions. A buyer replays them. A parallel path skips the human entirely and abuses a workflow identity that never asked for a login. A buggy extension can siphon the same traffic live. MFA on the IdP is a speed bump on a different road.

Same-Day Token Kills and Ongoing Security Hardening

Close the stealer incident when every AI secret is dead, not when the password hash rotates. Do the immediate work in the same hour you isolate the host, then keep the slower identity work on a calendar you actually honor.

  • Revoke AI provider sessions, OAuth grants, and API keys for the user in the same hour you reset the directory password; force a fresh login with a short token lifetime.
  • Search commercial stealer-log intel for corporate emails, key prefixes, and known AI vendor cookie names, then treat hits as confirmed credential theft.
  • Inventory unauthenticated workflow, webhook, and agent entry points; put authentication and least-privilege identities in front of anything that can read or export data.
  • Audit browser extensions with broad host or proxy permissions, including monitoring tools from security vendors, and patch or remove anything that can tap session traffic.

Ongoing, fold AI access into the identity program you already run. Named owners for service tokens. No long-lived keys in developer homedirs or browser profiles that also watch YouTube. Conditional access that cares where an AI API token is used, not only where the human SSO’d. Logging that can answer “which model calls left this tenant in the last hour, from which token, to which tool.” If you cannot answer that, threat-protection on the endpoint is doing work your identity layer refused.

Incident response needs a one-page playbook titled AI token leak. Containment is provider-side revocation plus workflow disable, not a hopeful reimage. Hunt for follow-on use: new API clients, unusual export volume, agents invoking tools the user never used. Notify the business owner that prompts and uploaded files may have left the tenant. Then fix the control that let a commodity lure plus a browser secret equal production access.

Security hardening here is unglamorous. Shorter sessions. Extension allow lists. Blocking the SEO-poisoned download paths your proxy already sees. Paying for stealer-log monitoring the way you pay for stolen-password monitoring. Your users will keep using AI tools. The job is to make a replayed token expire fast enough that a log dump from last week is a history lesson, not a skeleton key.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.