Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)

Infostealers Target Corporate AI Accounts, Sessions and API (TL-2026-2752), also tracked as LLMjacking, is a high-severity malware campaign, first published 2026-09-28. It has no confirmed attribution, affects OpenAI ChatGPT / OpenAI API (sessions, NextAuth.js JWEs, API keys), maps to 13 MITRE ATT&CK techniques (T1005, T1078, T1078.004), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-2752

Threat ID
TL-2026-2752
Also known as
LLMjacking, AI identity exposure
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-28
Last reviewed
2026-09-28
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, internet services, enterprise
Target regions
North America, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Infostealers Target Corporate AI Accounts, Sessions and API

Malware and tooling: Acreed, Atomic Stealer (AMOS), Lumma Stealer - S1213, RedLine, Remus, Stealc, Vidar, telegram, Camoufox, SeleniumBase

SOCRadar's AI Identity Exposure Report found 482 major enterprises with AI-platform credentials or sessions in 5,434 infostealer log records (295 of them in logs from the last 90 days), dominated by ChatGPT/OpenAI. Replayed session cookies and stolen API keys bypass passwords and MFA and enable data access and LLMjacking, where AI compute is consumed at the victim's expense or resold.

How Infostealers Target Corporate AI Accounts, Sessions and API works

SOCRadar's AI Identity Exposure Report 2026 (published 2026-09-28, covered by Security Affairs and BleepingComputer) mapped more than one million infostealer records tied to AI services across 80,000+ corporate domains, then narrowed the analysis to 482 major, established enterprises (about 68% billion-dollar organizations, 36 countries, eight sectors, concentrated in North America). Those 482 companies map to 5,434 stealer-log records and roughly 1,500 distinct corporate email addresses; 295 of the 482 surfaced in logs from the previous 90 days. Technology and internet-services firms are the largest group (144 companies, 40% of records). A captured ChatGPT/OpenAI session appears for 358 of 482 companies (74.3%) and those companies carry roughly 90% of all records. Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs trail far behind, and Claude and Gemini rank low, which SOCRadar reads as a shadow-AI adoption skew (employees signing up with work email on personal devices) rather than a verdict on any vendor's security. The article cited by the hunt also lists Cursor among the exposed services.

The attack chain is commodity: general-purpose infostealer malware, typically delivered through phishing, fake installers, pirated or trojanized software and malicious extensions, harvests the whole browser profile of an infected machine, including saved passwords, live session cookies, JWTs and any API keys pasted into notes apps, configuration files or workspace settings. Session tokens can be replayed to bypass credential-based authentication, so rotating the password alone leaves the intruder signed in ('a stolen cookie is a live session'). Conversation histories are effectively corporate data stores, because employees paste source code, customer data, contracts and unreleased plans into prompts. Agent and automation platforms such as Zapier can additionally hold standing OAuth authorization into CRM, email and file storage. The source describes LLMjacking as attackers stealing keys from notes, configuration files or workspace settings and using them to run AI workloads at the victim's expense, or reselling the access.

Okta Threat Intelligence ('Signing in without actually signing in', 2026-09-09) independently analyzed a 7 GB stealer-log dump posted to a Telegram channel on 2026-08-02: 5,871 folders, one per infected machine, across 162 countries. It contained 44,791 unique JWTs (555 tied to AI services, 17.7% with plaintext PII), 2,937 JWEs (mostly OpenAI NextAuth.js), 1,843 unexpired JWTs/JWEs on the dump date, and thousands of still-valid provider tokens (Google 9,213 unexpired of 9,829; Microsoft 1,763 of 2,491; Anthropic 164 of 561 across 404 machines; Amazon 254 of 349; Gamma 131 of 160; Notion 79 of 90; Character.ai 31 of 38; Cursor 16 of 32; Poe.com 25 of 28; Pika AI 17 of 20). TruffleHog found 24 still-valid API keys for Google Gemini, OpenAI, Groq and OpenRouter. Okta observed replay tooling built around anti-detect browsers (Camoufox) and SeleniumBase that loads sessionStorage/localStorage data from file and configures proxies to defeat impossible-travel detection, and noted it saw no stolen Okta sessions in the dump. The single stealer family Okta names is Remus, seen on one Windows 11 machine in Israel after a trojanized Hearts of Iron IV download.

The risk is already operational. On 2026-08-30 Anthropic emailed affected users that a bad actor was using common infostealer malware to steal Claude login sessions and consume their usage; families named were Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows and Atomic Stealer (AMOS) on a small number of Macs. Anthropic signed users out, removed saved payment methods and refunded unauthorized charges, and stated its platform was not breached and that signing out does not remove the malware. Okta also reported Telegram vendors selling discounted Claude, Cursor, ChatGPT and Gemini access with 24x7 support and money-back guarantees, including a service branded Poison Claude that advertises Opus 4.8/4.7/4.6 and Sonnet 4.6 at 5-15% of official per-token prices. Poison Claude's pricing is attributed to pooled fraudulent cloud accounts with free promotional credits (for example AWS Bedrock new-user credits) rather than to stolen sessions, and because it is a gateway proxy its operator sees every customer prompt; it is documented here as adjacent gray-market context, not as proven consumer of the SOCRadar or Okta datasets.

Limits of the evidence: neither the SOCRadar article nor Okta attributes the logs to a single stealer family or threat actor, no IOCs are published for the dump itself, and SOCRadar's own figures are exposure counts rather than confirmed account takeovers. Lumma and Vidar are named by Anthropic for the Claude campaign and by secondary reporting as capable of this collection; they are not established as the source of the SOCRadar or Okta datasets. The Cloud Security Alliance issued a v1.1 revision of its research note on 2026-09-11 correcting scale-inflation errors in early coverage, so secondary figures should be checked against the primary SOCRadar and Okta numbers used here.

MITRE ATT&CK techniques used in TL-2026-2752

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts; T1078.004 Cloud Accounts

Command and Control

T1090 Proxy

Execution

T1204.002 Malicious File

Impact

T1496.004 Cloud Service Hijacking

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers

lateral-movement

T1550.004 Web Session Cookie

Resource Development

T1650 Acquire Access

Affected products and versions in Infostealers Target Corporate AI Accounts, Sessions and API

  • OpenAI — ChatGPT / OpenAI API (sessions, NextAuth.js JWEs, API keys)
  • Anthropic — Claude (browser sessions)
  • Google — Gemini and Google account tokens (Gemini API keys)
  • Cursor — Cursor (sessions)
  • Hugging Face — Hugging Face accounts
  • Zapier — Zapier automation sessions (OAuth grants into CRM, email, file storage)
  • Notion — Notion workspace sessions
  • Replit — Replit accounts
  • Lovable — Lovable accounts
  • ElevenLabs — ElevenLabs accounts

Remediation for Infostealers Target Corporate AI Accounts, Sessions and API

Immediate actions

  • Treat any corporate AI-account hit in stealer-log intelligence as an endpoint compromise, not a password reset: isolate and reimage or clean the infected device before re-issuing credentials
  • Revoke active sessions and force sign-out on affected AI/SaaS accounts (signing out stops stolen sessions but does not remove the malware); use Universal Logout or equivalent where available
  • Rotate all AI provider API keys found on or reachable from infected endpoints (OpenAI, Anthropic, Google Gemini, Groq, OpenRouter, Hugging Face) and review billing and usage for anomalies
  • Review AI-platform and connected SaaS audit logs for logins or API calls from unfamiliar geographies, device fingerprints or off-hours activity
  • Check Zapier, Notion and other agent/automation platforms for unexpected OAuth grants, scheduled jobs and connected-system access

Workarounds

  • No vendor patch applies (account and session exposure, not a product flaw); remove saved payment methods and disable API keys that cannot be rotated immediately
  • Where a provider cannot bind sessions to devices, shorten session lifetime and require re-authentication for sensitive actions

Longer-term hardening

  • Put AI platforms behind SSO with short-lived sessions and refresh-token rotation (OAuth 2.0/OIDC short-lived access tokens)
  • Adopt Device-Bound Session Credentials where supported and deploy session-token re-use detection (for example Okta Identity Threat Protection session protection)
  • Set usage caps and IP allowlists on API keys, scope keys narrowly, and keep them in a secrets manager rather than plaintext notes, config files or environment variables
  • Inventory shadow AI accounts (work email on personal devices) using stealer-log exposure monitoring before attackers do
  • Move to phishing-resistant authentication such as passkeys and add anomaly and cross-device session-reuse monitoring
  • Harden endpoints against commodity stealers: block unofficial and pirated software, restrict browser extensions, and deploy EDR with infostealer behavioral detection

Timeline of Infostealers Target Corporate AI Accounts, Sessions and API

  • Remus, a 64-bit stealer reported as a Lumma successor that emphasizes cookie and session-token theft, is first commercially promoted on underground forums (month-level precision; the only stealer family Okta names in its later dump analysis)
  • A 7 GB infostealer log dump (5,871 infected machines across 162 countries, containing thousands of unexpired AI and SaaS session tokens) is released on a Telegram channel; Okta later analyzes it
  • Adaptive Security publishes analysis of the Poison Claude gray-market reseller uncovered by Okta researchers, which sells Claude access at 5-15% of official prices via pooled fraudulent cloud accounts and sees every customer prompt
  • Anthropic emails affected users that infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows; AMOS on some Macs) is stealing Claude login sessions to consume their usage; it signs users out, removes saved payment methods and refunds unauthorized charges
  • Help Net Security reports Anthropic's remediation and guidance, including that signing out stops stolen sessions but does not remove the malware and that one victim traced infection to a pirated game
  • Okta Threat Intelligence publishes 'Signing in without actually signing in': 44,791 unique JWTs, 2,937 JWEs, 1,843 unexpired tokens and 24 still-valid AI API keys found in the Telegram dump, plus Camoufox/SeleniumBase replay tooling
  • Cloud Security Alliance research note on AI token replay is revised (v1.1) to correct scale-inflation errors in early coverage
  • SOCRadar publishes its AI Identity Exposure Report 2026 (482 enterprises, 5,434 stealer-log records, 295 active in the last 90 days, ChatGPT/OpenAI exposed at 358 companies); Security Affairs and BleepingComputer cover it

Sources cited for Infostealers Target Corporate AI Accounts, Sessions and API

More in malware

Detection coverage for TL-2026-2752

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2752 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats