Description

Infostealer malware is increasingly being used as a bridge between compromised developer workstations and enterprise cloud environments. Lumma, RedLine, and Vidar are among the prominent families harvesting browser credentials, session cookies, API keys, cloud credentials, and developer secrets. Telemetry indicates that these infections can expose reusable identities capable of providing direct access to enterprise services without exploiting public-facing infrastructure. Infostealers are commonly delivered through phishing, malicious advertisements, ClickFix lures, pirated software, gaming cheats, and trojanized dependencies. After execution, they collect browser passwords, authentication cookies, SSH keys, cloud CLI credentials, source-control tokens, cryptocurrency data, and secrets stored in local files or environment variables. Cloud environments including AWS, Azure, and Google Cloud are particularly exposed. Attackers can target AWS credential files and CLI caches, Azure CLI and Entra ID artifacts, and GCP credential databases and service-account files. GitHub and GitLab tokens may provide access to private repositories, CI/CD pipelines, package registries, and deployment workflows. Stolen session cookies are especially significant because they may enable authenticated-session hijacking without requiring the victim's password or directly defeating MFA. The threat also extends to AI development environments, where stolen OpenAI, Anthropic, Gemini, Hugging Face, and other API credentials can enable unauthorized usage or access to connected workflows.