
highPrivacy
Infostealer Logs Enable Replay of AI Session Tokens, Bypassing MFA Protections
Recent reporting indicates that information stealer malware such as Lumma Stealer and Vidar are being used to harvest reusable session tokens and API credentials from compromised endpoints. These tokens, once extracted, can be replayed by attackers to gain illicit access to artificial intelligence platform accounts from Google, Anthropic, and other providers. The technique allows bypass of multi-factor authentication protections by reusing valid session identifiers rather than performing credential-based login. The scope of affected accounts and the precise mechanics of the token replay process remain under investigation.
The Hacker News1 min read