Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ViewSonic vCast Vulnerabilities Let Attackers Seize Control
September 28, 2026
Critical Kiteworks Zero-Day Vulnerability Prompts Server Shutdown Warning
September 28, 2026
CISA Warns of Critical Citrix NetScaler RCE 0-Day Vulnerabilities Under Attack
September 28, 2026
Home/Threats/Cloud Credential Theft: Attackers Exploit Stolen Keys for Cloud Access
Threats

Cloud Credential Theft: Attackers Exploit Stolen Keys for Cloud Access

Key Takeaways Infostealer malware is increasingly targeting cloud credentials, API keys, and active sessions from developer and employee devices. Attackers are bypassing traditional cloud perimeter...

Sarah simpson
Sarah simpson
September 28, 2026 5 Min Read
3 0

Key Takeaways

  • Infostealer malware is increasingly targeting cloud credentials, API keys, and active sessions from developer and employee devices.
  • Attackers are bypassing traditional cloud perimeter defenses by compromising endpoints to steal already trusted access tokens.
  • Major cloud providers like AWS and Google Cloud are significantly impacted, with their secrets comprising 46% and 13% of compromised credentials, respectively.
  • The primary infostealers observed are Lumma C2, RedLine, and Vidar, accounting for 85.7% of detected incidents.
  • Organizations must treat infostealer infections as identity incidents, requiring immediate session revocation, credential rotation, and thorough log review.

The Silent Infiltration: How Infostealers Bypass Cloud Security

Cybercriminals are increasingly leveraging infostealer malware to gain surreptitious entry into enterprise cloud environments. Rather than attempting to breach robust cloud perimeters directly, attackers are opting for a more indirect, yet highly effective, strategy: compromising developer or employee workstations to pilfer existing credentials, API keys, and active sessions that are already authorized by the organization.

Table Of Content

  • Key Takeaways
  • The Silent Infiltration: How Infostealers Bypass Cloud Security
  • Attackers Sidestep Cloud Defenses
  • Exploiting Long-Lived and Cached Credentials
  • From Infection to Remediation: A Comprehensive Approach
  • What You Should Do

The initial infection vector typically involves phishing campaigns, deceptive software downloads, or malicious software dependencies. Once executed, the infostealer rapidly collects browser data and sensitive local development secrets. This stolen access is then frequently sold to other criminal entities, enabling subsequent phases of attack.

These sophisticated campaigns pose a significant threat to cloud infrastructure, code repositories, and AI environments. An analysis of compromised systems revealed that Lumma C2, RedLine, and Vidar were responsible for a substantial 85.7% of the detected incidents. Wiz.io said in a report that AWS and Google Cloud secrets constituted a significant portion of the compromised data, accounting for 46% and 13% respectively.

A valid stolen token can grant unauthorized access to cloud consoles, code repositories, build pipelines, and AI services, leading to data exfiltration or inflated operational costs. This pattern mirrors the broader trend of breaches fueled by infostealer logs, where criminals purchase access rather than exploiting technical vulnerabilities.

Attackers Sidestep Cloud Defenses

Attackers frequently bypass multi-factor authentication (MFA) altogether by stealing active browser session tokens. After a legitimate user authenticates, a session token is generated. If malware compromises this token and an attacker loads it into a new browser, the cloud service often perceives the attacker as the legitimate, authenticated user.

Exploiting Long-Lived and Cached Credentials

The persistence of long-lived credentials further exacerbates this risk. AWS access keys, often stored in developer configuration files, can provide direct programmatic access. Similarly, cached AWS SSO tokens can allow an attacker to generate new temporary credentials, extending their window of access.

On Azure platforms, local Command Line Interface (CLI) and identity caches can expose sensitive access or refresh tokens, tenant information, and account details. Google Cloud developer machines are also prime targets, as command-line credentials and service-account key paths can offer sustained access to critical production projects.

Source-control platforms present another critical vulnerability. A stolen repository token, SSH key, or active session can expose proprietary code, CI/CD variables, and crucial deployment settings. Wiz.io’s analysis indicated that GitHub tokens accounted for approximately 10% of stolen secrets, while AI platform secrets comprised 5%.

AI credentials are an increasingly valuable target. Stolen keys can be used to consume services at the victim’s expense, while compromised sessions may expose confidential internal chat histories. This risk parallels recent AI infrastructure attacks where exposed systems provided a pathway to sensitive keys and connected resources. Personal or inadequately managed developer devices often contain privileged business access without the robust corporate security safeguards typically found on production systems.

Attackers have been observed abusing legitimate Windows utilities, such as vbc.exe, and trojanizing gaming-related files like Roblox.exe and SkinChanger.exe. Furthermore, supply-chain stealers are now targeting build servers and CI/CD processes directly, eliminating the need for traditional phishing tactics.

From Infection to Remediation: A Comprehensive Approach

The ecosystem of infostealer operations involves malware-as-a-service providers distributing stealers, followed by initial-access brokers who validate and resell stolen credentials. A single careless download can quickly escalate into a severe cloud incident, as demonstrated by campaigns like MacSync targeting developers.

Organizations must view a confirmed infostealer infection as an identity compromise, not merely a malware cleanup task. The immediate response should include isolating the compromised device, thoroughly investigating all accounts used on it, revoking all active sessions, and rotating passwords, API keys, SSH keys, cloud credentials, and repository tokens from a clean, secure device.

Security teams should meticulously review logs across cloud, identity, source-control, and CI/CD platforms for any suspicious activity, including unfamiliar sessions, newly created access keys, unusual token usage, unauthorized changes to roles, and unexpected repository access.

Rebuilding affected endpoints from trusted, clean sources is paramount, as simply removing malware does not guarantee the eradication of stolen access. Proactive prevention strategies should focus on minimizing the value of sensitive data stored on endpoints. This includes implementing short-lived credentials and workload identity where feasible, safeguarding secrets using operating system keychains or managed vaults, ensuring developer devices are fully managed, and strictly scoping permissions.

Lessons from incidents like the LiteLLM supply-chain exposure underscore the importance of pinning dependencies and scrutinizing build-time behavior. While robust multi-factor authentication remains crucial, it is insufficient if an attacker can replay a valid session. Organizations should enforce device-based access controls for critical services, continuously monitor for exposed credentials, and promptly revoke sessions when risk indicators change. Ultimately, securing cloud environments necessitates comprehensive protection of every endpoint that holds its keys.

What You Should Do

  • Isolate and Investigate: Immediately isolate any device suspected of infostealer infection. Conduct a thorough forensic investigation of all accounts and credentials used on that device.
  • Revoke and Rotate: From a clean device, revoke all active sessions for affected accounts and rotate all passwords, API keys, SSH keys, cloud credentials, and repository tokens.
  • Monitor Logs: Regularly review cloud, identity, source-control, and CI/CD logs for anomalies such as unusual logins, new access keys, unexpected token activity, or unauthorized role changes.
  • Rebuild Endpoints: Rebuild compromised endpoints from trusted sources rather than relying solely on malware removal.
  • Implement Least Privilege and Short-Lived Credentials: Adopt a principle of least privilege for all users and services. Utilize short-lived credentials and workload identity where possible to minimize the impact of a breach.
  • Secure Secrets: Store sensitive secrets in operating system keychains or managed vaults, not in plaintext files.
  • Manage Developer Devices: Ensure all developer devices are fully managed and adhere to corporate security policies.
  • Enhance MFA and Device Controls: Implement strong multi-factor authentication, but also enforce device-based access controls for sensitive services.
  • Continuous Monitoring: Monitor for exposed credentials and implement rapid session revocation mechanisms based on risk signals.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies

Next Post

PHP Patches Critical Credential Exposure Vulnerability

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies
September 28, 2026
Top Adaptive & Risk-Based Authentication Tools for 2026
September 28, 2026
Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us