Stolen AI Session Tokens Enable MFA Bypass via Infostealer Malware
Infostealer malware such as Lumma Stealer and Vidar is harvesting session tokens and API keys from compromised endpoints, allowing attackers to replay these credentials and bypass multi-factor authentication entirely. This highlights a critical flaw in relying solely on MFA: once a valid session token is stolen, the authentication challenge is already solved from the attacker's perspective. AI service providers and enterprise users are particularly at risk because long-lived tokens and API keys are often stored insecurely on disk or in browser profiles. The additional exposure of PII in these logs further amplifies the risk by enabling targeted social engineering attacks against users and organizations.
Tactical Insight
Immediate actions
- Rotate all AI platform API keys and session tokens immediately if endpoint compromise is suspected.
- Deploy endpoint detection and response (EDR) tooling capable of detecting infostealer malware behavior such as credential file access and browser data exfiltration.
- Audit and revoke any long-lived API keys or tokens that do not have defined expiration windows.
Long-term improvements
- Enforce short-lived, scoped API tokens with automatic expiration for all AI service integrations.
- Store API keys and secrets exclusively in dedicated secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) rather than in plaintext files or environment variables.
- Implement device trust and context-aware access policies so that session tokens are bound to verified device posture and cannot be replayed from unknown hosts.
Detection measures
- Monitor AI platform access logs for anomalous geolocation, IP address, or user-agent changes mid-session that may indicate token replay attacks.
- Configure alerts for bulk API key usage or off-hours access patterns that deviate from established baselines.
- Integrate threat intelligence feeds for known infostealer command-and-control infrastructure to detect exfiltration attempts at the network boundary.