Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials at Scale — Threadlinqs Intelligence
As of 2026-07-10, Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials at Scale is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1169 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Lumma (56%), RedLine (17%), and StealC (13%) account for 86% of observed stealer-log volume in 2025-2026, harvesting browser passwords, session cookies, OAuth/application access tokens, and SSH keys
Three commodity Malware-as-a-Service (MaaS) infostealer families — Lumma (LummaC2), RedLine Stealer, and StealC — dominate the current stealer-log economy, together accounting for 86% of logs analyzed by SOCRadar across 2025. All three are subscription/builder-based MaaS products sold on underground forums and Telegram, licensed to affiliate operators who run their own distribution campaigns (trojanized software, malvertising, fake CAPTCHA/ClickFix verification pages, phishing). Once executed on a Windows host (98% of ~691,000+ infected machines observed were Windows), the stealers harvest browser-saved credentials and autofill data, active session cookies (which bypass MFA/2FA entirely), OAuth and cloud/CI-CD authentication tokens (GitHub, GitLab, AWS, Azure, GCP), SSH keys and local configuration files, cryptocurrency wallet data, and in RedLine/StealC's case Discord tokens, Steam, FileZilla, and VPN client (OpenVPN/ProtonVPN) credentials. Exfiltrated logs are packaged and sold in bulk on dark-web marketplaces to initial access brokers.
Of the 3+ million developer/AI-platform credentials exposed in 2025, OpenAI accounted for 3.1 million (dominant), Replit 204K, Hugging Face 186K, and RunwayML 95K — reflecting sustained affiliate targeting of AI coding-agent and MLOps platform sessions, where a single stolen session cookie or API key can grant persistent account and downstream cloud/CI-CD access without needing the victim's password. Quarterly volumes show 953K compromised accounts in Q1 2025, dropping to 553K in Q3 2025 following a May 2025 FBI/CISA-documented, Microsoft-led international law enforcement takedown of LummaC2 infrastructure (a temporary ~42% decline), then recovering to 857K by Q4 2025 as the MaaS operators rebuilt infrastructure.
LummaC2 is fileless in its final stage: it runs in memory, decrypts hard-coded/obfuscated C2 domains, and exfiltrates over HTTPS (migrated from plaintext HTTP in late 2023/early 2024 to evade network detection), using a distinctive '/c2sock' URI path and 'TeslaBrowser/5.5' user agent. RedLine Stealer, in use since 2020 and used in a majority of infostealer infections through 2023, communicates via SOAP-style HTTP with a 'SOAPAction: tempuri.org' header and is sold for $100-150/month on Telegram/underground forums; coordinated law-enforcement action disrupted core RedLine backends in late 2024, but repackaged builds persist. StealC, redesigned as v2 in March 2025 (subsequently iterated through v2.9.0 by December 2025, sold at $300/month by an operator using the moniker 'plymouth'), uses a JSON-over-HTTP(S) C2 protocol, supports EXE/MSI/PowerShell second-stage payload delivery, geofences victims by geolocation/HWID via its rebuilt web panel, and by v2.9.0 added Steam token collection without process injection, Perplexity Comet browser support, and full MetaMask IndexedDB grabbing.
A related May 2026 supply-chain incident illustrates the AI-platform targeting directly: a Hugging Face repository ('Open-OSS/privacy-filter') impersonating an OpenAI 'Privacy Filter' tool reached #1 trending with roughly 244,000 downloads before removal. Its loader.py disabled SSL verification, decoded a remote URL, and silently launched a hidden PowerShell chain (start.bat) that escalated privileges, added the payload to a Microsoft Defender exclusion, and deployed a Rust-based infostealer ('sefirah') targeting Chromium/Gecko browser credentials, Discord tokens, crypto wallets/seed phrases, SSH/FTP/VPN configs, OpenAI/Hugging Face/GitHub/cloud/CI-CD/package-registry tokens, .env files, and local project secrets, calling back to C2 domain recargapopular[.]com. Researchers found infrastructure overlap with additional malicious repositories and npm-distributed WinOS 4.0 implants, indicating a broader coordinated campaign against AI/developer supply chains rather than an isolated incident.
Target sectors: technology, software-development, artificial-intelligence, cloud-services, any-sector-using-ai-coding-tools
Target regions: india, brazil, indonesia, vietnam, philippines, pakistan, united states of america, egypt, turkey, france
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1059, T1053, T1140, T1685, T1480, T1036, T1027