Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials at Scale

Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI (TL-2026-1169), also tracked as LummaC2, is a high-severity malware campaign, first published 2026-07-10. It has no confirmed attribution, affects Microsoft Windows, maps to 31 MITRE ATT&CK techniques (T1005, T1012, T1016), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1169

Threat ID
TL-2026-1169
Also known as
LummaC2, Lumma Stealer, RedLine Stealer, StealC, StealC2, sefirah
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-10
Last reviewed
2026-07-10
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, artificial-intelligence, cloud-services, any-sector-using-ai-coding-tools
Target regions
india, brazil, indonesia, vietnam, philippines, pakistan, united states of america, egypt, turkey, france
Detection rules
9
Indicators of compromise
18

Malware and tooling in Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

Malware and tooling: sefirah

Lumma (56%), RedLine (17%), and StealC (13%) account for 86% of observed stealer-log volume in 2025-2026, harvesting browser passwords, session cookies, OAuth/application access tokens, and SSH keys from Windows developer machines. Over 3 million compromised credentials targeted AI coding and developer platforms in 2025 (OpenAI 3.1M+, Replit 204K, Hugging Face 186K, RunwayML 95K), and a May 2026 supply-chain incident used a trending fake Hugging Face repository to deliver a Rust-based stealer to 244K downloaders.

How Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI works

Three commodity Malware-as-a-Service (MaaS) infostealer families — Lumma (LummaC2), RedLine Stealer, and StealC — dominate the current stealer-log economy, together accounting for 86% of logs analyzed by SOCRadar across 2025. All three are subscription/builder-based MaaS products sold on underground forums and Telegram, licensed to affiliate operators who run their own distribution campaigns (trojanized software, malvertising, fake CAPTCHA/ClickFix verification pages, phishing). Once executed on a Windows host (98% of ~691,000+ infected machines observed were Windows), the stealers harvest browser-saved credentials and autofill data, active session cookies (which bypass MFA/2FA entirely), OAuth and cloud/CI-CD authentication tokens (GitHub, GitLab, AWS, Azure, GCP), SSH keys and local configuration files, cryptocurrency wallet data, and in RedLine/StealC's case Discord tokens, Steam, FileZilla, and VPN client (OpenVPN/ProtonVPN) credentials. Exfiltrated logs are packaged and sold in bulk on dark-web marketplaces to initial access brokers.

Of the 3+ million developer/AI-platform credentials exposed in 2025, OpenAI accounted for 3.1 million (dominant), Replit 204K, Hugging Face 186K, and RunwayML 95K — reflecting sustained affiliate targeting of AI coding-agent and MLOps platform sessions, where a single stolen session cookie or API key can grant persistent account and downstream cloud/CI-CD access without needing the victim's password. Quarterly volumes show 953K compromised accounts in Q1 2025, dropping to 553K in Q3 2025 following a May 2025 FBI/CISA-documented, Microsoft-led international law enforcement takedown of LummaC2 infrastructure (a temporary ~42% decline), then recovering to 857K by Q4 2025 as the MaaS operators rebuilt infrastructure.

LummaC2 is fileless in its final stage: it runs in memory, decrypts hard-coded/obfuscated C2 domains, and exfiltrates over HTTPS (migrated from plaintext HTTP in late 2023/early 2024 to evade network detection), using a distinctive '/c2sock' URI path and 'TeslaBrowser/5.5' user agent. RedLine Stealer, in use since 2020 and used in a majority of infostealer infections through 2023, communicates via SOAP-style HTTP with a 'SOAPAction: tempuri.org' header and is sold for $100-150/month on Telegram/underground forums; coordinated law-enforcement action disrupted core RedLine backends in late 2024, but repackaged builds persist. StealC, redesigned as v2 in March 2025 (subsequently iterated through v2.9.0 by December 2025, sold at $300/month by an operator using the moniker 'plymouth'), uses a JSON-over-HTTP(S) C2 protocol, supports EXE/MSI/PowerShell second-stage payload delivery, geofences victims by geolocation/HWID via its rebuilt web panel, and by v2.9.0 added Steam token collection without process injection, Perplexity Comet browser support, and full MetaMask IndexedDB grabbing.

A related May 2026 supply-chain incident illustrates the AI-platform targeting directly: a Hugging Face repository ('Open-OSS/privacy-filter') impersonating an OpenAI 'Privacy Filter' tool reached #1 trending with roughly 244,000 downloads before removal. Its loader.py disabled SSL verification, decoded a remote URL, and silently launched a hidden PowerShell chain (start.bat) that escalated privileges, added the payload to a Microsoft Defender exclusion, and deployed a Rust-based infostealer ('sefirah') targeting Chromium/Gecko browser credentials, Discord tokens, crypto wallets/seed phrases, SSH/FTP/VPN configs, OpenAI/Hugging Face/GitHub/cloud/CI-CD/package-registry tokens, .env files, and local project secrets, calling back to C2 domain recargapopular[.]com. Researchers found infrastructure overlap with additional malicious repositories and npm-distributed WinOS 4.0 implants, indicating a broader coordinated campaign against AI/developer supply chains rather than an isolated incident.

MITRE ATT&CK techniques used in TL-2026-1169

Collection

T1005 Data from Local System; T1113 Screen Capture

Discovery

T1012 Query Registry; T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding

discovery

T1087 Account Discovery

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Initial Access

T1566 Phishing

impact

T1657 Financial Theft

Affected products and versions in Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

  • Microsoft — Windows
    Vulnerable versions: All supported Windows versions (endpoint OS targeted by malware)
    Fixed in: N/A - not a software vulnerability; mitigated via endpoint detection and credential hygiene
  • OpenAI — OpenAI platform accounts/API keys
    Vulnerable versions: Any account with browser-stored session/API credentials
    Fixed in: N/A
  • Replit — Replit platform accounts
    Vulnerable versions: Any account with browser-stored session credentials
    Fixed in: N/A
  • Hugging Face — Hugging Face Hub accounts/API tokens
    Vulnerable versions: Any account with browser-stored session/API credentials
    Fixed in: N/A
  • RunwayML — RunwayML platform accounts
    Vulnerable versions: Any account with browser-stored session credentials
    Fixed in: N/A

Remediation for Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

Immediate actions

  • Rotate all credentials, API keys, and session cookies on any machine suspected of infostealer infection (OpenAI, Replit, Hugging Face, RunwayML, GitHub, GitLab, AWS, Azure, GCP)
  • Force re-authentication / invalidate active sessions and OAuth tokens on developer and AI-platform accounts rather than relying on password rotation alone
  • Reimage confirmed-infected Windows developer endpoints; do not trust in-place cleanup given fileless/memory-resident stealer behavior
  • Block known C2 indicators (siyatermi.duckdns.org:17044, 194.156.79.122:55615, 85.17.40.98:55615, 194.26.135.119:12432, 158.94.208.130, recargapopular[.]com) at perimeter/DNS/proxy

Workarounds

  • Disable browser-based password/session storage on developer workstations; require a dedicated credential manager with MFA
  • Restrict outbound HTTPS from developer endpoints to an allow-list to disrupt fileless C2 callbacks

Longer-term hardening

  • Deploy EDR with behavioral detection for fileless, in-memory credential harvesting and browser-store access patterns (T1555.003, T1539)
  • Enforce hardware-bound or short-lived session tokens for CI/CD and cloud platforms to blunt the value of stolen session cookies
  • Monitor dark-web stealer-log marketplaces / underground forums for organizational domains appearing in fresh logs
  • Require code/model provenance review before installing packages, models, or repositories from public hubs (Hugging Face, npm, PyPI) given demonstrated supply-chain abuse

Timeline of Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

  • Lumma Stealer (LummaC2) first reported in use as a MaaS credential-theft product on underground forums.
  • CISA/FBI joint advisory IOC window for LummaC2 infections begins (November 2023 through May 2025).
  • Coordinated law-enforcement takedowns disrupt core RedLine Stealer backend infrastructure; repackaged builds persist in the wild.
  • Q1 2025: approximately 953,000 compromised accounts observed in stealer logs (Lumma/RedLine/StealC combined).
  • StealC developer releases version 2 with a redesigned JSON-based C2 protocol, rebuilt web control panel, and expanded EXE/MSI/PowerShell payload delivery.
  • Microsoft-led global law enforcement operation disrupts LummaC2 infrastructure, causing a temporary ~42% decline in stealer-log volume.
  • CISA and FBI publish joint advisory AA25-141B on threat actors deploying LummaC2 malware to exfiltrate sensitive organizational data.
  • Q3 2025: stealer-log volume falls to approximately 553,000 accounts, the lowest point following the LummaC2 takedown.
  • Q4 2025: stealer-log volume recovers to approximately 857,000 accounts as MaaS operators rebuild infrastructure.
  • StealC campaign attributed to seller moniker 'plymouth' observed using C2 at 158.94.208.130; StealC v2.9.0 released with new Steam-token and MetaMask IndexedDB collection features.
  • HiddenLayer discovers a fake OpenAI 'Privacy Filter' repository ('Open-OSS/privacy-filter') trending #1 on Hugging Face with ~244,000 downloads, delivering a Rust-based ('sefirah') infostealer via a Python/PowerShell loader chain.
  • SOCRadar publishes 'The AI Agent Credential Crisis' analysis quantifying 2025 stealer-log targeting of OpenAI, Replit, Hugging Face, and RunwayML accounts.

Sources cited for Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

Threats related to Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI

Detection coverage for TL-2026-1169

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1169 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats