The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
Wiz finds Lumma, RedLine, and Vidar dominate infostealer theft of AWS, GitHub, and OpenAI credentials from endpoints.
Wiz, using NordStellar telemetry, reports that infostealers remain a leading path into enterprise cloud, source-code, and AI environments. Lumma C2, RedLine, and Vidar account for 85.7% of detected incidents, and NordStellar tracks more than 400 types of non-credential secrets. AWS and GCP represent 46% and 13% of compromised secrets, GitHub tokens about 10%, and AI platform keys about 5%, mostly OpenAI API keys. Attackers also hijack session cookies to bypass MFA and, via malware such as Miasma, poison software dependencies to steal CI/CD and cloud credentials.