VYPR
researchPublished Sep 9, 2026· 1 source

Infostealer Malware Harvests Replayable AI Session Tokens, Bypassing MFA

Information stealer malware is now targeting and harvesting AI user session tokens, enabling attackers to replay them and bypass multi-factor authentication for illicit access.

Cybercriminals are increasingly targeting artificial intelligence (AI) user accounts by harvesting session tokens, which can then be replayed to bypass multi-factor authentication (MFA) and gain unauthorized access to valuable AI tools and services. Malware strains such as Lumma Stealer and Vidar are at the forefront of this evolving threat, actively scanning for and exfiltrating session tokens from compromised systems.

These information stealers are designed to pilfer a wide array of sensitive data, including traditional credentials, API keys, and crucially, active session tokens. When an attacker obtains a valid session token for an AI service, they can effectively impersonate the legitimate user without needing to re-authenticate, even if MFA is enabled on the account. This significantly lowers the barrier to entry for malicious actors seeking to exploit AI platforms.

The implications of such attacks are far-reaching. Threat actors could potentially misuse these compromised AI accounts for a variety of nefarious purposes, including generating malicious content, conducting sophisticated phishing campaigns, spreading disinformation, or even using the AI's computational power for their own illicit activities. Services from major providers like Google and Anthropic are reportedly among the targets, indicating a broad scope of potential impact.

This new attack vector highlights a critical blind spot in current security paradigms. While MFA is a robust defense against credential stuffing and brute-force attacks, it is rendered ineffective if an attacker possesses a valid, active session token. The replayability of these tokens means that once stolen, they can be used repeatedly until the session naturally expires or is manually terminated by the legitimate user or service provider.

Security researchers are urging users of AI platforms to exercise extreme caution. This includes being vigilant about potential phishing attempts that could lead to the installation of information stealers, ensuring that endpoint security solutions are up-to-date, and being aware that even seemingly secure sessions can be compromised if the underlying tokens are exfiltrated.

While specific details on the exact mechanisms of token harvesting and replay are still emerging, the trend underscores the need for AI service providers to implement more robust session management and token validation techniques. This could include shorter session lifetimes, stricter IP address binding for tokens, or additional out-of-band verification steps for high-risk actions performed within an AI session.

The proliferation of information stealer malware capable of targeting these AI-specific tokens represents a significant escalation in cyber threats. As AI tools become more integrated into professional workflows and daily life, securing access to them becomes paramount, necessitating a continuous evolution of defensive strategies to counter these sophisticated new attack vectors.

Synthesized by Vypr AI