Cybercriminals are increasingly leveraging information stealer logs to hijack high-value artificial intelligence (AI) user accounts. By harvesting session tokens, API keys, and JSON Web Tokens (JWTs) from compromised systems using malware like Lumma Stealer and Vidar, threat actors can bypass multi-factor authentication (MFA) and traditional login protocols. This technique, often referred to as "LLMjacking," allows unauthorized access to premium AI models from providers such as Google, OpenAI, and Anthropic, enabling resource theft, espionage, and phishing campaigns.
Security research from Okta and Google highlights a growing underground market for these "stolen keys," where discounted access to enterprise AI tools is sold on Telegram and dark web forums. To evade detection, attackers utilize specialized anti-detect browsers and automation tools to replay stolen credentials. Defense strategies require a shift toward session-bound credentials, IP allowlisting, and the implementation of short-lived OAuth 2.0 tokens to mitigate the risks posed by persistent token theft.
Top comments (0)