INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Infostealer to Steal Replayable AI Tokens

| 2026-09-09 14:23 LOW HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
On September 9, 2026, cybercriminals hijacked artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that granted illicit access to tools from model providers like Google, Anthropic, and others. The attackers harvested credential, session tokens, and API keys from compromised systems, which were then sold on underground forums in the form of stealer logs. According to Jeremy Kirk, director of threat intelligence at Okta, these stolen session tokens and API keys can be replayed to bypass credential-based authentication, allowing threat actors to gain access to AI services without actually logging in. The infostealer dump contained data from 5,871 infected machines across 162 countries, including thousands of unexpired authentication tokens corresponding to various AI services, with 555 JWTs likely related to authentication for these services.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

po•••••.com
Ne•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lumma StealerLumma Stealer
Target & Sectors
Global Scope
Incident Timeline
‎August 2, 2026
Threat actors used stolen session tokens and API keys to bypass multi-factor authentication (MFA) and access AI services.
organisation Telegram
data_breach 7 GB infostealer dump
infrastructure 5,871 infected machines
general_metric 162 countries
infrastructure Cursor
organisation Google
organisation Microsoft
organisation Amazon
organisation Character.ai
organisation Poe.com
organisation Claude
organisation OpenAI
organisation JWT
organisation MFA
organisation PII
organisation IP
organisation Device Bound Session
organisation Google Gemini
organisation Groq
organisation OpenRouter
organisation Poison Claude
organisation SeleniumBase
organisation GitHub Personal Access Token
organisation PAT
‎2026/09/09
Threat actors used information stealers to harvest AI tokens and API keys from compromised systems, which can be replayed to bypass multi-factor authentication.
organisation Infostealer Logs Expose Replayable
organisation API
organisation LLM
Tactical Metrics
Metrics
infrastructure
‎Cursor
Affected Product
Metrics
data_breach
7
Gb Infostealer Dump
Metrics
infrastructure
5,871
Infected Machines
Intelligence Sources