Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Lumma, RedLine, and Vidar steal cloud and developer credentials, enabling session hijacking that bypasses MFA.
NordStellar telemetry across more than 55 infostealer families found LummaC2, RedLine, and Vidar responsible for 85.7% of detected incidents that expose cloud and developer secrets. The stealers, spread via phishing, malvertising, ClickFix, and trojanized software, harvest browser passwords, session cookies, SSH keys, and cloud CLI tokens that can bypass MFA. Wiz documented JINX-0164 using compromised developer endpoints to steal AWS, Azure, GCP, Cloudflare, and GitHub credentials, and in June found the Miasma payload in at least 32 npm releases under @redhat-cloud-services. Stolen secrets also include OpenAI, Anthropic, Hugging Face, and other AI platform keys.
- Lumma, RedLine, and Vidar made up 85.7% of analyzed infostealer incidents.
- Stolen browser session cookies can hijack authenticated sessions and bypass MFA.
- Targets include AWS, Azure, GCP, GitHub, GitLab, and AI API keys.
- Wiz found malicious code in at least 32 @redhat-cloud-services npm releases carrying Miasma.
- Defenders should revoke sessions, rotate cloud and CI/CD secrets, and hunt unusual token use.
Full article704 words · extracted from gbhackers.com · click to collapse
Infostealer malware is increasingly becoming the bridge between a compromised developer workstation and an enterprise cloud environment, with Lumma, RedLine, and Vidar emerging as major threats to credentials, API keys, and active browser sessions.
Identity, rather than exposed infrastructure, remains the most valuable cloud attack surface.
Attackers no longer need to exploit a public-facing server or defeat multifactor authentication directly when a developer’s endpoint contains reusable cloud credentials, privileged session cookies, source-control tokens, and AI platform keys.
A recent analysis of secrets recovered from infostealer-infected devices found that LummaC2, RedLine, and Vidar accounted for 85.7% of detected incidents.
NordStellar’s telemetry tracks data from more than 55 infostealer families and shows that malware logs can expose credentials, cookies, cloud tokens, private keys, source code, and secrets embedded in local files or environment variables.
The business model is efficient: attackers distribute a stealer through phishing, malicious ads, ClickFix lures, pirated applications, gaming cheats, or trojanized software dependencies.
Once executed, the malware rapidly collects browser passwords, cookies, cryptowallet data, SSH keys, cloud CLI files, and developer configuration artifacts before sending them to command-and-control infrastructure.
The logs are then validated and resold, sometimes within hours, to actors seeking verified enterprise access.
Microsoft warned that an infection on an unmanaged personal device can expose VPN credentials, SSO tokens, and browser cookies tied to corporate services.
Session cookies are particularly dangerous because they can allow attackers to assume an authenticated user session and bypass MFA protections without knowing the underlying password.
Microsoft also notes that infostealer operators commonly monetize stolen data through access brokers, ransomware operators, and other downstream criminal groups.
Infostealer malware
Wiz said in a report shared with GBhackers, these malware families operate within a mature malware-as-a-service ecosystem, enabling low-skilled affiliates to harvest and sell access that can later be used by ransomware groups.

The impact extends across AWS, Azure, Google Cloud, GitHub, GitLab, and AI development environments. AWS access keys stored in ~/.aws/credentials, CLI caches, and IAM Identity Center token caches can provide programmatic or console access.
Azure-focused stealers target local Azure CLI token stores and Entra ID artifacts, while GCP attacks concentrate on gcloud credential databases, application default credentials, and service-account JSON files.
NordStellar’s secret-detection taxonomy specifically includes AWS access keys, Azure client secrets, GCP service-account JSON files, GitHub PATs, GitLab runner tokens, Kubernetes secrets, and CI/CD credentials.
Source-control platforms are a high-value target because a compromised GitHub or GitLab token can expose private repositories, Actions or pipeline secrets, package registries, and deployment workflows.
A stolen developer identity can also enable attackers to inject malicious code into trusted repositories.
Wiz recently documented JINX-0164 campaigns in which compromised developer endpoints yielded AWS, Azure, GCP, Cloudflare, GitHub, and package-management credentials; the actors then used GitHub access to exfiltrate CI/CD secrets and modify internal repositories.
AI credentials have also entered the infostealer target set. API keys for OpenAI, Anthropic, and other AI services can be abused for fraudulent compute consumption, resale, or access to connected development workflows.
NordStellar lists numerous AI-related secret types, including OpenAI, Anthropic, Hugging Face, Gemini, Bedrock, and coding-assistant keys, underscoring how quickly AI infrastructure has become part of the enterprise identity perimeter.
Supply-chain compromise compounds the risk. In June, Wiz identified malicious code in at least 32 releases under the @redhat-cloud-services npm namespace.
The Miasma payload included collectors for GCP and Azure identities, showing attackers are increasingly targeting cloud access directly through compromised dependencies rather than relying solely on phishing.
Organizations should treat infostealer exposure as an identity incident, not a routine password-reset event.
Response teams should immediately revoke active sessions, rotate cloud and CI/CD credentials, invalidate API keys, investigate developer endpoints, review cloud audit logs, and hunt for anomalous use of tokens from unfamiliar IP addresses.
Verizon’s 2025 DBIR found credential abuse was involved in 22% of breaches, reinforcing that identity hardening and rapid token revocation are now core cloud-defense requirements.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.