VYPR
researchPublished Sep 28, 2026· 1 source

Infostealer Malware Offers Stealthy Access to Cloud Environments by Stealing Credentials

Infostealer malware is increasingly targeting developer devices to steal cloud credentials, API keys, and active sessions, providing attackers with a quiet route into sensitive corporate environments.

Infostealer malware is providing cybercriminals with a more discreet pathway into corporate cloud environments. Rather than attempting to breach hardened cloud perimeters, attackers focus on infecting developer or employee devices to pilfer existing credentials, API keys, and active sessions that are already trusted by the organization. The initial compromise can occur through various vectors, including phishing campaigns, deceptive software downloads, or the exploitation of poisoned software dependencies.

Once the infostealer is active on a system, it rapidly collects browser data and local developer secrets. This stolen information is then often sold to other malicious actors, granting them access to sensitive cloud, code, and AI environments. Analysis of compromised systems indicates that Lumma C2, RedLine, and Vidar are the most prevalent stealers, accounting for a significant majority of detected incidents. Specifically, stolen secrets related to AWS and Google Cloud represent a substantial portion of these compromises, with valid tokens providing access to cloud consoles, code repositories, build pipelines, and AI services, potentially leading to data exfiltration or unauthorized resource consumption.

The attack methodology often bypasses traditional security measures like multi-factor authentication. A legitimate user's active browser session token, once stolen by malware, can be replayed by an attacker to impersonate the user. Similarly, long-lived credentials, such as AWS access keys stored in configuration files or cached AWS SSO tokens, can grant direct programmatic access or enable the acquisition of fresh temporary credentials. In Azure environments, local CLI and identity caches can expose access or refresh tokens, tenant information, and user accounts. Google Cloud developer machines are also prime targets, as command-line credentials and service-account key paths can offer persistent access to valuable production projects.

Beyond cloud platforms, source-control systems present another critical attack vector. Stolen repository tokens, SSH keys, or session cookies can expose private code, CI/CD pipeline variables, and sensitive deployment configurations. GitHub tokens alone constitute a significant percentage of stolen secrets, while secrets for AI platforms are also increasingly targeted. These compromised AI credentials can lead to the unauthorized consumption of cloud services at the victim's expense or expose internal communication logs.

The risk is amplified by the fact that personal or lightly managed developer devices often contain privileged business access without the robust protections found on corporate-managed systems. Attackers are employing sophisticated techniques, including abusing legitimate Windows tools and distributing trojanized gaming-related files. Furthermore, supply-chain attacks now target build servers and CI/CD processes directly, reducing reliance on traditional phishing methods.

Organizations must treat confirmed infostealer infections as serious identity incidents, not merely malware cleanup tasks. Immediate actions should include isolating the affected device, investigating all accounts used on it, revoking active sessions, and rotating all credentials—passwords, API keys, SSH keys, cloud credentials, and repository tokens—from a clean, trusted device. Comprehensive log reviews across cloud, identity, source-control, and CI/CD systems are crucial to detect unfamiliar sessions, new access keys, unusual token activity, or unauthorized changes.

Preventative measures should focus on reducing the value of data accessible from endpoints. This includes implementing short-lived credentials, utilizing workload identities where feasible, protecting secrets with secure key management systems or vaults, maintaining managed developer devices, and enforcing strict permission scoping. While strong multi-factor authentication remains a vital layer, it is insufficient on its own when session tokens can be replayed. Organizations should enforce device-based access controls for sensitive services, actively monitor for exposed credentials, and implement rapid session revocation protocols based on risk signals.

Synthesized by Vypr AI