INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys Infostealer to Steal Replayable AI Tokens
| 2026-09-09 14:23 LOW HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
On September 9, 2026, cybercriminals hijacked artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that granted illicit access to tools from model providers like Google, Anthropic, and others. The attackers harvested credential, session tokens, and API keys from compromised systems, which were then sold on underground forums in the form of stealer logs. According to Jeremy Kirk, director of threat intelligence at Okta, these stolen session tokens and API keys can be replayed to bypass credential-based authentication, allowing threat actors to gain access to AI services without actually logging in. The infostealer dump contained data from 5,871 infected machines across 162 countries, including thousands of unexpired authentication tokens corresponding to various AI services, with 555 JWTs likely related to authentication for these services.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
po•••••.com
Ne•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lumma StealerLumma Stealer
Target & Sectors
Global Scope
Incident Timeline
August 2, 2026
Threat actors used stolen session tokens and API keys to bypass multi-factor authentication (MFA) and access AI services.
Click on any entity below to view its context and source!
organisation
Telegram
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
data_breach
7 GB infostealer dump
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
infrastructure
5,871 infected machines
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
general_metric
162 countries
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
infrastructure
Cursor
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
In one Telegram post flagged by Okta, an unspecified vendor has been spotted selling access to Claude, Cursor, ChatGPT, and Gemini at a discounted price, in addition to offering 24x7 support and money-back guarantees.
Posts on these forums have indicated buyer demand for Claude and Gemini credentials, in conjunction with autonomous coding IDEs like Cursor Pro and Devin.
organisation
Google
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
organisation
Microsoft
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
organisation
Amazon
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
organisation
Character.ai
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
organisation
Poe.com
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
organisation
Claude
In one Telegram post flagged by Okta, an unspecified vendor has been spotted selling access to Claude, Cursor, ChatGPT, and Gemini at a discounted price, in addition to offering 24x7 support and money-back guarantees.
organisation
OpenAI
Most of these tokens are said to have been set by OpenAI, which uses NextAuth.js.
organisation
JWT
Similar to a session token, a valid JWT can be
abused to obtain direct account access
, while bypassing regular authentication using a username and password, as well as multi-factor authentication (MFA).
organisation
MFA
Similar to a session token, a valid JWT can be
abused to obtain direct account access
, while bypassing regular authentication using a username and password, as well as multi-factor authentication (MFA).
organisation
PII
Worryingly, 17.7% of the 44,791 JWTs have been found to include plaintext personally identifiable information (PII), such as name, phone number, or email address.
organisation
IP
One key aspect worth mentioning here is that session replay attacks may not work in scenarios where an organization uses IP allowlisting, a security feature that blocks all network traffic except for specific, approved IP addresses or ranges.
organisation
Device Bound Session
In addition, Google has added support for Device Bound Session Credentials (
DBSC
) to Chrome to cryptographically link a session token to a device so that a stolen token cannot be used on another system.
organisation
Google Gemini
Besides credentials and tokens, an analysis of the stealer dump using
TruffleHog
has unearthed 24 still-valid API keys for four AI-related services, such as Google Gemini, OpenAI, Groq, and OpenRouter.
organisation
Groq
Besides credentials and tokens, an analysis of the stealer dump using
TruffleHog
has unearthed 24 still-valid API keys for four AI-related services, such as Google Gemini, OpenAI, Groq, and OpenRouter.
organisation
OpenRouter
Besides credentials and tokens, an analysis of the stealer dump using
TruffleHog
has unearthed 24 still-valid API keys for four AI-related services, such as Google Gemini, OpenAI, Groq, and OpenRouter.
organisation
Poison Claude
Another service called Poison Claude claims to provide access to Anthropic's Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6 models.
organisation
SeleniumBase
"So-called 'anti-detect' browsers have features designed to use stolen authentication data and avoid security controls."
"Other tools, such as the open-source anti-detect browser Camoufox or the automation tool SeleniumBase, can load data stolen from a browser's sessionStorage and localStorage easily from a file.
organisation
GitHub Personal Access Token
In at least one incident response engagement handled by Google's Mandiant team, a threat actor was found to have gained initial access to a victim's cloud environment through an exposed GitHub Personal Access Token (PAT) and leveraged it to deploy unauthorized AI infrastructure and scale high-performance compute resources.
organisation
PAT
In at least one incident response engagement handled by Google's Mandiant team, a threat actor was found to have gained initial access to a victim's cloud environment through an exposed GitHub Personal Access Token (PAT) and leveraged it to deploy unauthorized AI infrastructure and scale high-performance compute resources.
2026/09/09
Threat actors used information stealers to harvest AI tokens and API keys from compromised systems, which can be replayed to bypass multi-factor authentication.
Click on any entity below to view its context and source!
organisation
Infostealer Logs Expose Replayable
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA.
organisation
API
This can include credential, session tokens, and API keys.
organisation
LLM
"Once successfully replayed, a threat actor is effectively logged in to an LLM service without actually logging in.
Tactical Metrics
Metrics
infrastructure
Cursor
Affected Product
Click for context!
Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.
In one Telegram post flagged by Okta, an unspecified vendor has been spotted selling access to Claude, Cursor, ChatGPT, and Gemini at a discounted price, in addition to offering 24x7 support and money-back guarantees.
Posts on these forums have indicated buyer demand for Claude and Gemini credentials, in conjunction with autonomous coding IDEs like Cursor Pro and Devin.
Metrics
data_breach
7
Gb Infostealer Dump
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
Metrics
infrastructure
5,871
Infected Machines
"
The identity services provider said it analyzed a 7 GB infostealer dump released on a Telegram channel on August 2, 2026, and found that the stealer log contained data belonging to 5,871 infected machines across 162 countries.
Intelligence Sources
The Hacker News
2026-09-09
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
The Hacker News
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T10:37
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
Google
entity
5x
tactic
Cyber Operation Type
Social Engineering
tactic
3x
attribution
Attributing Entity
Google
authority
3x
general metric
Opus
5
opus
2x
general metric
Jwts
44,791
jwts
Contextual Telemetry
Context Block
12 METRICS
timeline
Temporal Reference
August 2, 2026
date
infrastructure
Affected Product
Cursor
software
malware
Malware Payload
Lumma Stealer
tool
data breach
Gb Infostealer Dump
7
gb infostealer dump
infrastructure
Infected Machines
5,871
infected machines
general metric
Countries
162
countries
general metric
%
18
%
tactic
MITRE ATT&CK Technique
T1589.001 - Credentials
technique
general metric
Valid Api Keys
24
valid api keys
general metric
Related Json Web Encryption
2,937
related json web encryption
general metric
Unexpired Jwts
1,843
unexpired jwts
general metric
Oauth
2
oauth
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.