Infostealers Lead Theft of Cloud, Code, and AI Keys
Wiz and NordStellar say Lumma, RedLine, and Vidar drive 85.7% of infostealer cases stealing cloud, code, and AI secrets.
Wiz, using NordStellar telemetry, says infostealers remain a leading path into enterprise cloud, source-code, and AI environments. Lumma—called Lumma C2 in the Wiz write-up and LummaC2 in a later recap—plus RedLine and Vidar account for 85.7% of detected incidents; sources disagree slightly on scope, with Wiz and Cyber Security News describing infostealer incidents generally and GBHackers describing incidents that expose cloud and developer secrets across more than 55 families. Of compromised secrets, AWS is 46% and Google Cloud 13%, GitHub tokens about 10%, and AI platform keys about 5%, mostly OpenAI; later reporting also names Azure, Cloudflare, GitLab, Anthropic, and Hugging Face without repeating those shares. The stealers, spread via phishing, malvertising, ClickFix, and trojanized software, harvest browser passwords, session cookies, SSH keys, and cloud CLI tokens, and stolen cookies can bypass MFA. Wiz linked cluster JINX-0164 to credential theft from developer machines and, in June, found Miasma in at least 32 @redhat-cloud-services npm releases, while the earlier post described Miasma-style dependency poisoning more generally. NordStellar also tracks more than 400 types of non-credential secrets, and defenders are advised to revoke sessions, rotate cloud and CI/CD secrets from a clean device, and hunt unusual token use.
- Lumma (called Lumma C2 by Wiz and LummaC2 in a later recap), RedLine, and Vidar account for 85.7% of detected incidents; sources differ on whether that share covers infostealer incidents generally or cloud and developer secret exposures…
- Of compromised secrets, AWS is 46% and Google Cloud 13%; GitHub tokens are about 10%, and AI platform keys about 5%, mostly OpenAI.
- Later reporting also names Azure, Cloudflare, GitLab, Anthropic, and Hugging Face among stolen secrets without giving those shares.
- NordStellar tracks more than 400 types of non-credential secrets.
- Stolen browser session cookies, passwords, SSH keys, and cloud CLI tokens can hijack authenticated sessions and bypass MFA.
- Wiz tied cluster JINX-0164 to theft from developer endpoints and, in June, found the Miasma payload in at least 32 @redhat-cloud-services npm releases.
- Named spread methods are phishing, malvertising, ClickFix, and trojanized software.
- Advised response is to revoke sessions, rotate cloud and CI/CD secrets from a clean device, and hunt unusual token use.
Coverage timelineoldest first · each row is one article
- · 4d agoThe Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
Wiz Blog· 64
Wiz finds Lumma, RedLine, and Vidar dominate infostealer theft of AWS, GitHub, and OpenAI credentials from endpoints.
- · 1d agoLumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
GBHackers· 62
Lumma, RedLine, and Vidar steal cloud and developer credentials, enabling session hijacking that bypasses MFA.
- · 1d agoHackers Don’t Need to Break Into the Cloud When They Can Steal the Keys
Cyber Security News· 73