Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials at Scale
Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI (TL-2026-1169), also tracked as LummaC2, is a high-severity malware campaign, first published 2026-07-10. It has no confirmed attribution, affects Microsoft Windows, maps to 31 MITRE ATT&CK techniques (T1005, T1012, T1016), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1169
- Threat ID
- TL-2026-1169
- Also known as
- LummaC2, Lumma Stealer, RedLine Stealer, StealC, StealC2, sefirah
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, artificial-intelligence, cloud-services, any-sector-using-ai-coding-tools
- Target regions
- india, brazil, indonesia, vietnam, philippines, pakistan, united states of america, egypt, turkey, france
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
Malware and tooling: sefirah
Lumma (56%), RedLine (17%), and StealC (13%) account for 86% of observed stealer-log volume in 2025-2026, harvesting browser passwords, session cookies, OAuth/application access tokens, and SSH keys from Windows developer machines. Over 3 million compromised credentials targeted AI coding and developer platforms in 2025 (OpenAI 3.1M+, Replit 204K, Hugging Face 186K, RunwayML 95K), and a May 2026 supply-chain incident used a trending fake Hugging Face repository to deliver a Rust-based stealer to 244K downloaders.
How Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI works
Three commodity Malware-as-a-Service (MaaS) infostealer families — Lumma (LummaC2), RedLine Stealer, and StealC — dominate the current stealer-log economy, together accounting for 86% of logs analyzed by SOCRadar across 2025. All three are subscription/builder-based MaaS products sold on underground forums and Telegram, licensed to affiliate operators who run their own distribution campaigns (trojanized software, malvertising, fake CAPTCHA/ClickFix verification pages, phishing). Once executed on a Windows host (98% of ~691,000+ infected machines observed were Windows), the stealers harvest browser-saved credentials and autofill data, active session cookies (which bypass MFA/2FA entirely), OAuth and cloud/CI-CD authentication tokens (GitHub, GitLab, AWS, Azure, GCP), SSH keys and local configuration files, cryptocurrency wallet data, and in RedLine/StealC's case Discord tokens, Steam, FileZilla, and VPN client (OpenVPN/ProtonVPN) credentials. Exfiltrated logs are packaged and sold in bulk on dark-web marketplaces to initial access brokers.
Of the 3+ million developer/AI-platform credentials exposed in 2025, OpenAI accounted for 3.1 million (dominant), Replit 204K, Hugging Face 186K, and RunwayML 95K — reflecting sustained affiliate targeting of AI coding-agent and MLOps platform sessions, where a single stolen session cookie or API key can grant persistent account and downstream cloud/CI-CD access without needing the victim's password. Quarterly volumes show 953K compromised accounts in Q1 2025, dropping to 553K in Q3 2025 following a May 2025 FBI/CISA-documented, Microsoft-led international law enforcement takedown of LummaC2 infrastructure (a temporary ~42% decline), then recovering to 857K by Q4 2025 as the MaaS operators rebuilt infrastructure.
LummaC2 is fileless in its final stage: it runs in memory, decrypts hard-coded/obfuscated C2 domains, and exfiltrates over HTTPS (migrated from plaintext HTTP in late 2023/early 2024 to evade network detection), using a distinctive '/c2sock' URI path and 'TeslaBrowser/5.5' user agent. RedLine Stealer, in use since 2020 and used in a majority of infostealer infections through 2023, communicates via SOAP-style HTTP with a 'SOAPAction: tempuri.org' header and is sold for $100-150/month on Telegram/underground forums; coordinated law-enforcement action disrupted core RedLine backends in late 2024, but repackaged builds persist. StealC, redesigned as v2 in March 2025 (subsequently iterated through v2.9.0 by December 2025, sold at $300/month by an operator using the moniker 'plymouth'), uses a JSON-over-HTTP(S) C2 protocol, supports EXE/MSI/PowerShell second-stage payload delivery, geofences victims by geolocation/HWID via its rebuilt web panel, and by v2.9.0 added Steam token collection without process injection, Perplexity Comet browser support, and full MetaMask IndexedDB grabbing.
A related May 2026 supply-chain incident illustrates the AI-platform targeting directly: a Hugging Face repository ('Open-OSS/privacy-filter') impersonating an OpenAI 'Privacy Filter' tool reached #1 trending with roughly 244,000 downloads before removal. Its loader.py disabled SSL verification, decoded a remote URL, and silently launched a hidden PowerShell chain (start.bat) that escalated privileges, added the payload to a Microsoft Defender exclusion, and deployed a Rust-based infostealer ('sefirah') targeting Chromium/Gecko browser credentials, Discord tokens, crypto wallets/seed phrases, SSH/FTP/VPN configs, OpenAI/Hugging Face/GitHub/cloud/CI-CD/package-registry tokens, .env files, and local project secrets, calling back to C2 domain recargapopular[.]com. Researchers found infrastructure overlap with additional malicious repositories and npm-distributed WinOS 4.0 implants, indicating a broader coordinated campaign against AI/developer supply chains rather than an isolated incident.
MITRE ATT&CK techniques used in TL-2026-1169
Collection
T1005 Data from Local System; T1113 Screen Capture
Discovery
T1012 Query Registry; T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery; T1614 System Location Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding
discovery
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Initial Access
impact
Affected products and versions in Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
- Microsoft — Windows
Vulnerable versions: All supported Windows versions (endpoint OS targeted by malware)
Fixed in: N/A - not a software vulnerability; mitigated via endpoint detection and credential hygiene - OpenAI — OpenAI platform accounts/API keys
Vulnerable versions: Any account with browser-stored session/API credentials
Fixed in: N/A - Replit — Replit platform accounts
Vulnerable versions: Any account with browser-stored session credentials
Fixed in: N/A - Hugging Face — Hugging Face Hub accounts/API tokens
Vulnerable versions: Any account with browser-stored session/API credentials
Fixed in: N/A - RunwayML — RunwayML platform accounts
Vulnerable versions: Any account with browser-stored session credentials
Fixed in: N/A
Remediation for Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
Immediate actions
- Rotate all credentials, API keys, and session cookies on any machine suspected of infostealer infection (OpenAI, Replit, Hugging Face, RunwayML, GitHub, GitLab, AWS, Azure, GCP)
- Force re-authentication / invalidate active sessions and OAuth tokens on developer and AI-platform accounts rather than relying on password rotation alone
- Reimage confirmed-infected Windows developer endpoints; do not trust in-place cleanup given fileless/memory-resident stealer behavior
- Block known C2 indicators (siyatermi.duckdns.org:17044, 194.156.79.122:55615, 85.17.40.98:55615, 194.26.135.119:12432, 158.94.208.130, recargapopular[.]com) at perimeter/DNS/proxy
Workarounds
- Disable browser-based password/session storage on developer workstations; require a dedicated credential manager with MFA
- Restrict outbound HTTPS from developer endpoints to an allow-list to disrupt fileless C2 callbacks
Longer-term hardening
- Deploy EDR with behavioral detection for fileless, in-memory credential harvesting and browser-store access patterns (T1555.003, T1539)
- Enforce hardware-bound or short-lived session tokens for CI/CD and cloud platforms to blunt the value of stolen session cookies
- Monitor dark-web stealer-log marketplaces / underground forums for organizational domains appearing in fresh logs
- Require code/model provenance review before installing packages, models, or repositories from public hubs (Hugging Face, npm, PyPI) given demonstrated supply-chain abuse
Timeline of Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
- Lumma Stealer (LummaC2) first reported in use as a MaaS credential-theft product on underground forums.
- CISA/FBI joint advisory IOC window for LummaC2 infections begins (November 2023 through May 2025).
- Coordinated law-enforcement takedowns disrupt core RedLine Stealer backend infrastructure; repackaged builds persist in the wild.
- Q1 2025: approximately 953,000 compromised accounts observed in stealer logs (Lumma/RedLine/StealC combined).
- StealC developer releases version 2 with a redesigned JSON-based C2 protocol, rebuilt web control panel, and expanded EXE/MSI/PowerShell payload delivery.
- Microsoft-led global law enforcement operation disrupts LummaC2 infrastructure, causing a temporary ~42% decline in stealer-log volume.
- CISA and FBI publish joint advisory AA25-141B on threat actors deploying LummaC2 malware to exfiltrate sensitive organizational data.
- Q3 2025: stealer-log volume falls to approximately 553,000 accounts, the lowest point following the LummaC2 takedown.
- Q4 2025: stealer-log volume recovers to approximately 857,000 accounts as MaaS operators rebuild infrastructure.
- StealC campaign attributed to seller moniker 'plymouth' observed using C2 at 158.94.208.130; StealC v2.9.0 released with new Steam-token and MetaMask IndexedDB collection features.
- HiddenLayer discovers a fake OpenAI 'Privacy Filter' repository ('Open-OSS/privacy-filter') trending #1 on Hugging Face with ~244,000 downloads, delivering a Rust-based ('sefirah') infostealer via a Python/PowerShell loader chain.
- SOCRadar publishes 'The AI Agent Credential Crisis' analysis quantifying 2025 stealer-log targeting of OpenAI, Replit, Hugging Face, and RunwayML accounts.
Sources cited for Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
- The AI Agent Credential Crisis: From Stealer Log to Source Code
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
- CSA: Threat Actors Deploy LummaC2 Malware
- RedLine Stealer, Software S1240
- Lumma Stealer, Software S1213
- I StealC You: Tracking the Rapid Changes To StealC
- StealC V2 Malware Enhances Stealth and Expands Data Theft Features
- Fake OpenAI repository on Hugging Face pushes infostealer malware
- Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
- The Rise of MaaS & Lumma Info Stealer
- StealC Malware Profile & 7d C2 Tracker
Threats related to Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI
- Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)
- Fake OpenAI 'Privacy Filter' Repository on Hugging Face — Open-OSS/privacy-filter Drops sefirah Rust Infostealer
- FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning (Water Kurita)
- Typosquatted npm Package postcss-minify-selector-parser Delivers Nuitka-Compiled Windows RAT with RC4-Encrypted HTTP C2
- Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026
Detection coverage for TL-2026-1169
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1169 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.