Interestana
Home/News/AI Tokens Stolen Via Infostealer Logs Bypass MFA
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

AI Tokens Stolen Via Infostealer Logs Bypass MFA

AI Tokens Stolen Via Infostealer Logs Bypass MFA

Cybercriminals are actively compromising artificial intelligence (AI) user accounts by leveraging information stealer malware to harvest session tokens. These "stolen keys" can grant illicit access to AI tools and services from prominent providers, including Google and Anthropic, bypassing standard security measures like multi-factor authentication (MFA). Information stealer malware, such as Lumma Stealer and Vidar, are sophisticated tools designed to extract a broad spectrum of sensitive data from infected systems. This data frequently includes user credentials, active session tokens, and API keys, which are critical for programmatic access to AI models and platforms.

The primary mechanism of this attack involves the malware infecting a user's device and then systematically searching for and exfiltrating specific types of data. Session tokens, in particular, are highly valuable because they represent an authenticated state for a user's session with a web service or application. When these tokens are stolen, an attacker can often impersonate the legitimate user without needing to know their password or pass through MFA prompts. This is because the token itself serves as proof of authentication for the duration of its validity.

This exploitation poses a significant threat to the security of AI platforms and the data processed by them. AI models and services often handle sensitive information, and unauthorized access could lead to data breaches, intellectual property theft, or the misuse of AI capabilities for malicious purposes. The ability of these stolen tokens to circumvent MFA highlights a critical vulnerability in how session management is implemented and secured within the AI ecosystem. Security researchers have observed an increase in the use of these techniques, indicating a growing trend in cybercriminal activity targeting AI users.

To mitigate these risks, AI service providers and users alike must implement robust security practices. This includes enhancing endpoint security to prevent malware infections, employing more secure session management techniques that limit token lifespan and scope, and educating users about the dangers of phishing and malware. Furthermore, continuous monitoring for anomalous access patterns and prompt revocation of compromised tokens are essential steps in defending against such sophisticated attacks. The evolving threat landscape necessitates a proactive approach to cybersecurity, especially as AI tools become more integrated into critical business operations and personal workflows.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next