ZeroHour
Story · 3 sources · 4 articlesfirst updated ()

Commodity Infostealers Harvest AI Agent Credentials at Scale: Gen Digital Maps the Families, Okta Counts Replayable Tokens Fueling LLMjacking, and OpenAI Unveils an Agent 'Defense…

mediumMalwareexploited in the wildimportance 62
What's new: The previous story summary covered only the Gen Digital infostealer findings and OpenAI's Defense Factory. This merge adds The Hacker News' report on Okta's analysis of a 7 GB infostealer dump, supplying quantified evidence that stolen AI credentials are already circulating and replayable at scale — 555 of 44,791 JWTs tied to AI services, 1,843 unexpired tokens and 24 live API keys — along with…
Merged summary · glm-5.3 · rewritten as coverage arrives

Three strands reported September 9-10, 2026: Gen Digital documents commodity infostealers (Amatera, Remus, CallbackBeaver, Djinn Stealer) stealing Claude, Cursor and Codex agent tokens, prompt histories and MCP configs via remotely managed collection rules;…

The story spans the full arc of AI-agent credential abuse — theft, monetization, and defense. On the theft side, Gen Digital researchers found commodity infostealers extending their collection rules to local AI coding agent data from Claude, Cursor, Codex, Cline, Continue and OpenCode on Windows and macOS. Targeting breaks down as: Amatera against Cline and Continue; Remus against Claude, Cursor and OpenCode (assessed as a Lumma Stealer variant using EtherHiding C2 resolution via Ethereum smart contracts); CallbackBeaver, which added Claude and Cursor to its scope with more than 5,000 samples observed in 30 days; and macOS-focused Djinn Stealer against Claude, Codex, Gemini, Cline, OpenCode and Kilo. Stolen data includes access and refresh tokens, prompt histories, conversation databases and MCP configuration files holding API keys, potentially exposing connected source-control, cloud, database and ticketing systems. Amatera and Remus detections were recorded among tens of thousands of protected users — Cyber Security News specifies protected Windows users over a three-month window — and both reports stress these are detections, not confirmed infections, and that remotely managed collection rules mean an adaptation of existing infostealers via config updates rather than a new vulnerability in the AI tools themselves. On the monetization side, Okta analyzed a 7 GB infostealer dump dated August 2, 2026 covering 5,871 infected machines in 162 countries: 555 of 44,791 JWTs related to AI services, 1,843 unexpired JWTs and JWEs (largely set by OpenAI via NextAuth.js), 24 still-valid API keys for Google Gemini, OpenAI, Groq and OpenRouter, and 17.7% of JWTs containing plaintext PII usable for social engineering. Valid sessions and keys can be replayed with anti-detect browsers like Camoufox to bypass credential, MFA and impossible-travel checks, feeding an underground market for AI account access known as LLMjacking, where attackers run up victims' AI compute bills for espionage, extortion or resource theft. Google's GTIG reported growing buyer demand for Claude, Gemini, Cursor and Devin credentials, and Mandiant handled an incident where an actor used an exposed GitHub PAT to deploy unauthorized AI infrastructure and scale high-performance compute. On the defense side, OpenAI introduced a Defense Factory, an agent-first cybersecurity operation connecting AI agents to GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear and ServiceNow via APIs, CLIs and Model…

  • Gen Digital: infostealer targeting by family — Amatera hits Cline and Continue; Remus hits Claude, Cursor and OpenCode; CallbackBeaver added Claude and Cursor with more than 5,000 samples observed in 30 days; macOS-focused Djinn Stealer…
  • Remus is assessed as a Lumma Stealer variant using EtherHiding C2 resolution via Ethereum smart contracts.
  • Amatera and Remus detections were recorded among tens of thousands of protected users; Cyber Security News specifies protected Windows users over a three-month window; the reports stress detections, not confirmed infections.
  • Collection rules are remotely managed, letting criminals add new agent targets via config updates — an adaptation of existing infostealers, not a new vulnerability in the AI tools.
  • Okta analyzed a 7 GB infostealer dump dated August 2, 2026 covering 5,871 infected machines in 162 countries.
  • Of 44,791 JWTs in the dump, 555 related to AI services; 1,843 JWTs/JWEs were unexpired (largely set by OpenAI via NextAuth.js); 24 API keys for Google Gemini, OpenAI, Groq and OpenRouter were still valid; 17.7% of JWTs contained plaintext…
  • Stolen session tokens and API keys can be replayed with anti-detect browsers such as Camoufox to bypass credential, MFA and impossible-travel checks, fueling the LLMjacking underground market for AI account access.
  • Google's GTIG reported growing buyer demand for Claude, Gemini, Cursor and Devin credentials; Mandiant handled an incident where an exposed GitHub PAT was used to deploy unauthorized AI infrastructure and scale high-performance compute.

Coverage timeline

  1. · 6d ago
    GBHackers· 62
    Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data

    Gen Digital researchers report infostealer families Amatera, Remus and CallbackBeaver now harvest Claude, Cursor and Codex agent data, including tokens and MCP configs.

  2. · 6d ago
    Cyber Security News· 58
    Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

    Gen Digital found infostealers like Amatera and Remus stealing AI coding agent tokens, prompt histories, and MCP configs from infected Windows and macOS machines.

  3. · 6d ago
    The Hacker News· 60
    Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

    Okta finds infostealer logs contain thousands of replayable AI session tokens and API keys, letting criminals bypass MFA and access services from Google, Anthropic and OpenAI.

  4. · 5d ago
    Cyber Security News· 55
    OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities

    OpenAI unveils a Defense Factory where AI agents continuously discover, validate, and fix vulnerabilities, integrating GitHub, Snyk, Semgrep, Tenable, and ServiceNow.