Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Lumma, RedLine, and Vidar steal cloud and developer credentials, enabling session hijacking that bypasses MFA.
NordStellar telemetry across more than 55 infostealer families found LummaC2, RedLine, and Vidar responsible for 85.7% of detected incidents that expose cloud and developer secrets. The stealers, spread via phishing, malvertising, ClickFix, and trojanized software, harvest browser passwords, session cookies, SSH keys, and cloud CLI tokens that can bypass MFA. Wiz documented JINX-0164 using compromised developer endpoints to steal AWS, Azure, GCP, Cloudflare, and GitHub credentials, and in June found the Miasma payload in at least 32 npm releases under @redhat-cloud-services. Stolen secrets also include OpenAI, Anthropic, Hugging Face, and other AI platform keys.