Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)
Infostealers Target Corporate AI Accounts, Sessions and API (TL-2026-2752), also tracked as LLMjacking, is a high-severity malware campaign, first published 2026-09-28. It has no confirmed attribution, affects OpenAI ChatGPT / OpenAI API (sessions, NextAuth.js JWEs, API keys), maps to 13 MITRE ATT&CK techniques (T1005, T1078, T1078.004), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-2752
- Threat ID
- TL-2026-2752
- Also known as
- LLMjacking, AI identity exposure
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, internet services, enterprise
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Infostealers Target Corporate AI Accounts, Sessions and API
Malware and tooling: Acreed, Atomic Stealer (AMOS), Lumma Stealer - S1213, RedLine, Remus, Stealc, Vidar, telegram, Camoufox, SeleniumBase
SOCRadar's AI Identity Exposure Report found 482 major enterprises with AI-platform credentials or sessions in 5,434 infostealer log records (295 of them in logs from the last 90 days), dominated by ChatGPT/OpenAI. Replayed session cookies and stolen API keys bypass passwords and MFA and enable data access and LLMjacking, where AI compute is consumed at the victim's expense or resold.
How Infostealers Target Corporate AI Accounts, Sessions and API works
SOCRadar's AI Identity Exposure Report 2026 (published 2026-09-28, covered by Security Affairs and BleepingComputer) mapped more than one million infostealer records tied to AI services across 80,000+ corporate domains, then narrowed the analysis to 482 major, established enterprises (about 68% billion-dollar organizations, 36 countries, eight sectors, concentrated in North America). Those 482 companies map to 5,434 stealer-log records and roughly 1,500 distinct corporate email addresses; 295 of the 482 surfaced in logs from the previous 90 days. Technology and internet-services firms are the largest group (144 companies, 40% of records). A captured ChatGPT/OpenAI session appears for 358 of 482 companies (74.3%) and those companies carry roughly 90% of all records. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs trail far behind, and Claude and Gemini rank low, which SOCRadar reads as a shadow-AI adoption skew (employees signing up with work email on personal devices) rather than a verdict on any vendor's security. The article cited by the hunt also lists Cursor among the exposed services.
The attack chain is commodity: general-purpose infostealer malware, typically delivered through phishing, fake installers, pirated or trojanized software and malicious extensions, harvests the whole browser profile of an infected machine, including saved passwords, live session cookies, JWTs and any API keys pasted into notes apps, configuration files or workspace settings. Session tokens can be replayed to bypass credential-based authentication, so rotating the password alone leaves the intruder signed in ('a stolen cookie is a live session'). Conversation histories are effectively corporate data stores, because employees paste source code, customer data, contracts and unreleased plans into prompts. Agent and automation platforms such as Zapier can additionally hold standing OAuth authorization into CRM, email and file storage. The source describes LLMjacking as attackers stealing keys from notes, configuration files or workspace settings and using them to run AI workloads at the victim's expense, or reselling the access.
Okta Threat Intelligence ('Signing in without actually signing in', 2026-09-09) independently analyzed a 7 GB stealer-log dump posted to a Telegram channel on 2026-08-02: 5,871 folders, one per infected machine, across 162 countries. It contained 44,791 unique JWTs (555 tied to AI services, 17.7% with plaintext PII), 2,937 JWEs (mostly OpenAI NextAuth.js), 1,843 unexpired JWTs/JWEs on the dump date, and thousands of still-valid provider tokens (Google 9,213 unexpired of 9,829; Microsoft 1,763 of 2,491; Anthropic 164 of 561 across 404 machines; Amazon 254 of 349; Gamma 131 of 160; Notion 79 of 90; Character.ai 31 of 38; Cursor 16 of 32; Poe.com 25 of 28; Pika AI 17 of 20). TruffleHog found 24 still-valid API keys for Google Gemini, OpenAI, Groq and OpenRouter. Okta observed replay tooling built around anti-detect browsers (Camoufox) and SeleniumBase that loads sessionStorage/localStorage data from file and configures proxies to defeat impossible-travel detection, and noted it saw no stolen Okta sessions in the dump. The single stealer family Okta names is Remus, seen on one Windows 11 machine in Israel after a trojanized Hearts of Iron IV download.
The risk is already operational. On 2026-08-30 Anthropic emailed affected users that a bad actor was using common infostealer malware to steal Claude login sessions and consume their usage; families named were Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows and Atomic Stealer (AMOS) on a small number of Macs. Anthropic signed users out, removed saved payment methods and refunded unauthorized charges, and stated its platform was not breached and that signing out does not remove the malware. Okta also reported Telegram vendors selling discounted Claude, Cursor, ChatGPT and Gemini access with 24x7 support and money-back guarantees, including a service branded Poison Claude that advertises Opus 4.8/4.7/4.6 and Sonnet 4.6 at 5-15% of official per-token prices. Poison Claude's pricing is attributed to pooled fraudulent cloud accounts with free promotional credits (for example AWS Bedrock new-user credits) rather than to stolen sessions, and because it is a gateway proxy its operator sees every customer prompt; it is documented here as adjacent gray-market context, not as proven consumer of the SOCRadar or Okta datasets.
Limits of the evidence: neither the SOCRadar article nor Okta attributes the logs to a single stealer family or threat actor, no IOCs are published for the dump itself, and SOCRadar's own figures are exposure counts rather than confirmed account takeovers. Lumma and Vidar are named by Anthropic for the Claude campaign and by secondary reporting as capable of this collection; they are not established as the source of the SOCRadar or Okta datasets. The Cloud Security Alliance issued a v1.1 revision of its research note on 2026-09-11 correcting scale-inflation errors in early coverage, so secondary figures should be checked against the primary SOCRadar and Okta numbers used here.
MITRE ATT&CK techniques used in TL-2026-2752
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Initial Access
T1078 Valid Accounts; T1078.004 Cloud Accounts
Command and Control
Execution
Impact
T1496.004 Cloud Service Hijacking
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers
lateral-movement
Resource Development
Affected products and versions in Infostealers Target Corporate AI Accounts, Sessions and API
- OpenAI — ChatGPT / OpenAI API (sessions, NextAuth.js JWEs, API keys)
- Anthropic — Claude (browser sessions)
- Google — Gemini and Google account tokens (Gemini API keys)
- Cursor — Cursor (sessions)
- Hugging Face — Hugging Face accounts
- Zapier — Zapier automation sessions (OAuth grants into CRM, email, file storage)
- Notion — Notion workspace sessions
- Replit — Replit accounts
- Lovable — Lovable accounts
- ElevenLabs — ElevenLabs accounts
Remediation for Infostealers Target Corporate AI Accounts, Sessions and API
Immediate actions
- Treat any corporate AI-account hit in stealer-log intelligence as an endpoint compromise, not a password reset: isolate and reimage or clean the infected device before re-issuing credentials
- Revoke active sessions and force sign-out on affected AI/SaaS accounts (signing out stops stolen sessions but does not remove the malware); use Universal Logout or equivalent where available
- Rotate all AI provider API keys found on or reachable from infected endpoints (OpenAI, Anthropic, Google Gemini, Groq, OpenRouter, Hugging Face) and review billing and usage for anomalies
- Review AI-platform and connected SaaS audit logs for logins or API calls from unfamiliar geographies, device fingerprints or off-hours activity
- Check Zapier, Notion and other agent/automation platforms for unexpected OAuth grants, scheduled jobs and connected-system access
Workarounds
- No vendor patch applies (account and session exposure, not a product flaw); remove saved payment methods and disable API keys that cannot be rotated immediately
- Where a provider cannot bind sessions to devices, shorten session lifetime and require re-authentication for sensitive actions
Longer-term hardening
- Put AI platforms behind SSO with short-lived sessions and refresh-token rotation (OAuth 2.0/OIDC short-lived access tokens)
- Adopt Device-Bound Session Credentials where supported and deploy session-token re-use detection (for example Okta Identity Threat Protection session protection)
- Set usage caps and IP allowlists on API keys, scope keys narrowly, and keep them in a secrets manager rather than plaintext notes, config files or environment variables
- Inventory shadow AI accounts (work email on personal devices) using stealer-log exposure monitoring before attackers do
- Move to phishing-resistant authentication such as passkeys and add anomaly and cross-device session-reuse monitoring
- Harden endpoints against commodity stealers: block unofficial and pirated software, restrict browser extensions, and deploy EDR with infostealer behavioral detection
Timeline of Infostealers Target Corporate AI Accounts, Sessions and API
- Remus, a 64-bit stealer reported as a Lumma successor that emphasizes cookie and session-token theft, is first commercially promoted on underground forums (month-level precision; the only stealer family Okta names in its later dump analysis)
- A 7 GB infostealer log dump (5,871 infected machines across 162 countries, containing thousands of unexpired AI and SaaS session tokens) is released on a Telegram channel; Okta later analyzes it
- Adaptive Security publishes analysis of the Poison Claude gray-market reseller uncovered by Okta researchers, which sells Claude access at 5-15% of official prices via pooled fraudulent cloud accounts and sees every customer prompt
- Anthropic emails affected users that infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; AMOS on some Macs) is stealing Claude login sessions to consume their usage; it signs users out, removes saved payment methods and refunds unauthorized charges
- Help Net Security reports Anthropic's remediation and guidance, including that signing out stops stolen sessions but does not remove the malware and that one victim traced infection to a pirated game
- Okta Threat Intelligence publishes 'Signing in without actually signing in': 44,791 unique JWTs, 2,937 JWEs, 1,843 unexpired tokens and 24 still-valid AI API keys found in the Telegram dump, plus Camoufox/SeleniumBase replay tooling
- Cloud Security Alliance research note on AI token replay is revised (v1.1) to correct scale-inflation errors in early coverage
- SOCRadar publishes its AI Identity Exposure Report 2026 (482 enterprises, 5,434 stealer-log records, 295 active in the last 90 days, ChatGPT/OpenAI exposed at 358 companies); Security Affairs and BleepingComputer cover it
Sources cited for Infostealers Target Corporate AI Accounts, Sessions and API
- AI Accounts Are Becoming the New Target for Infostealers (Security Affairs)
- 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking (BleepingComputer)
- New SOCRadar AI Identity Exposure Report Reveals 80,000+ Enterprises Had Employee AI Logins Stolen (The IT Nerd)
- Signing in without actually signing in (Okta Threat Intelligence)
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA (The Hacker News)
- Stolen AI Session Tokens Are Bypassing MFA (Cloud Security Alliance research note, v1.1)
- There's a New Black Market Just for Stolen ChatGPT and Claude Logins (Gizmodo)
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage (BleepingComputer)
- Anthropic locks out Claude users after infostealers hijack login sessions (Help Net Security)
- Infostealers Are Hijacking Claude Sessions and Draining Subscriptions (Security Affairs)
- Infostealers are hijacking Claude accounts at users' expense (Malwarebytes)
- Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution (BleepingComputer)
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt (The Hacker News)
- Poison Claude: The Discount That Reads Everything You Type (Adaptive Security)
- Discounted Claude access bought on the gray market may expose every prompt you send (Help Net Security)
More in malware
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
Detection coverage for TL-2026-2752
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2752 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.