Cloud Credential Theft: Attackers Exploit Stolen Keys for Cloud Access
Key Takeaways Infostealer malware is increasingly targeting cloud credentials, API keys, and active sessions from developer and employee devices. Attackers are bypassing traditional cloud perimeter...
Key Takeaways
- Infostealer malware is increasingly targeting cloud credentials, API keys, and active sessions from developer and employee devices.
- Attackers are bypassing traditional cloud perimeter defenses by compromising endpoints to steal already trusted access tokens.
- Major cloud providers like AWS and Google Cloud are significantly impacted, with their secrets comprising 46% and 13% of compromised credentials, respectively.
- The primary infostealers observed are Lumma C2, RedLine, and Vidar, accounting for 85.7% of detected incidents.
- Organizations must treat infostealer infections as identity incidents, requiring immediate session revocation, credential rotation, and thorough log review.
The Silent Infiltration: How Infostealers Bypass Cloud Security
Cybercriminals are increasingly leveraging infostealer malware to gain surreptitious entry into enterprise cloud environments. Rather than attempting to breach robust cloud perimeters directly, attackers are opting for a more indirect, yet highly effective, strategy: compromising developer or employee workstations to pilfer existing credentials, API keys, and active sessions that are already authorized by the organization.
Table Of Content
The initial infection vector typically involves phishing campaigns, deceptive software downloads, or malicious software dependencies. Once executed, the infostealer rapidly collects browser data and sensitive local development secrets. This stolen access is then frequently sold to other criminal entities, enabling subsequent phases of attack.
These sophisticated campaigns pose a significant threat to cloud infrastructure, code repositories, and AI environments. An analysis of compromised systems revealed that Lumma C2, RedLine, and Vidar were responsible for a substantial 85.7% of the detected incidents. Wiz.io said in a report that AWS and Google Cloud secrets constituted a significant portion of the compromised data, accounting for 46% and 13% respectively.
A valid stolen token can grant unauthorized access to cloud consoles, code repositories, build pipelines, and AI services, leading to data exfiltration or inflated operational costs. This pattern mirrors the broader trend of breaches fueled by infostealer logs, where criminals purchase access rather than exploiting technical vulnerabilities.
Attackers Sidestep Cloud Defenses
Attackers frequently bypass multi-factor authentication (MFA) altogether by stealing active browser session tokens. After a legitimate user authenticates, a session token is generated. If malware compromises this token and an attacker loads it into a new browser, the cloud service often perceives the attacker as the legitimate, authenticated user.
Exploiting Long-Lived and Cached Credentials
The persistence of long-lived credentials further exacerbates this risk. AWS access keys, often stored in developer configuration files, can provide direct programmatic access. Similarly, cached AWS SSO tokens can allow an attacker to generate new temporary credentials, extending their window of access.
On Azure platforms, local Command Line Interface (CLI) and identity caches can expose sensitive access or refresh tokens, tenant information, and account details. Google Cloud developer machines are also prime targets, as command-line credentials and service-account key paths can offer sustained access to critical production projects.
Source-control platforms present another critical vulnerability. A stolen repository token, SSH key, or active session can expose proprietary code, CI/CD variables, and crucial deployment settings. Wiz.io’s analysis indicated that GitHub tokens accounted for approximately 10% of stolen secrets, while AI platform secrets comprised 5%.
AI credentials are an increasingly valuable target. Stolen keys can be used to consume services at the victim’s expense, while compromised sessions may expose confidential internal chat histories. This risk parallels recent AI infrastructure attacks where exposed systems provided a pathway to sensitive keys and connected resources. Personal or inadequately managed developer devices often contain privileged business access without the robust corporate security safeguards typically found on production systems.
Attackers have been observed abusing legitimate Windows utilities, such as vbc.exe, and trojanizing gaming-related files like Roblox.exe and SkinChanger.exe. Furthermore, supply-chain stealers are now targeting build servers and CI/CD processes directly, eliminating the need for traditional phishing tactics.
From Infection to Remediation: A Comprehensive Approach
The ecosystem of infostealer operations involves malware-as-a-service providers distributing stealers, followed by initial-access brokers who validate and resell stolen credentials. A single careless download can quickly escalate into a severe cloud incident, as demonstrated by campaigns like MacSync targeting developers.
Organizations must view a confirmed infostealer infection as an identity compromise, not merely a malware cleanup task. The immediate response should include isolating the compromised device, thoroughly investigating all accounts used on it, revoking all active sessions, and rotating passwords, API keys, SSH keys, cloud credentials, and repository tokens from a clean, secure device.
Security teams should meticulously review logs across cloud, identity, source-control, and CI/CD platforms for any suspicious activity, including unfamiliar sessions, newly created access keys, unusual token usage, unauthorized changes to roles, and unexpected repository access.
Rebuilding affected endpoints from trusted, clean sources is paramount, as simply removing malware does not guarantee the eradication of stolen access. Proactive prevention strategies should focus on minimizing the value of sensitive data stored on endpoints. This includes implementing short-lived credentials and workload identity where feasible, safeguarding secrets using operating system keychains or managed vaults, ensuring developer devices are fully managed, and strictly scoping permissions.
Lessons from incidents like the LiteLLM supply-chain exposure underscore the importance of pinning dependencies and scrutinizing build-time behavior. While robust multi-factor authentication remains crucial, it is insufficient if an attacker can replay a valid session. Organizations should enforce device-based access controls for critical services, continuously monitor for exposed credentials, and promptly revoke sessions when risk indicators change. Ultimately, securing cloud environments necessitates comprehensive protection of every endpoint that holds its keys.
What You Should Do
- Isolate and Investigate: Immediately isolate any device suspected of infostealer infection. Conduct a thorough forensic investigation of all accounts and credentials used on that device.
- Revoke and Rotate: From a clean device, revoke all active sessions for affected accounts and rotate all passwords, API keys, SSH keys, cloud credentials, and repository tokens.
- Monitor Logs: Regularly review cloud, identity, source-control, and CI/CD logs for anomalies such as unusual logins, new access keys, unexpected token activity, or unauthorized role changes.
- Rebuild Endpoints: Rebuild compromised endpoints from trusted sources rather than relying solely on malware removal.
- Implement Least Privilege and Short-Lived Credentials: Adopt a principle of least privilege for all users and services. Utilize short-lived credentials and workload identity where possible to minimize the impact of a breach.
- Secure Secrets: Store sensitive secrets in operating system keychains or managed vaults, not in plaintext files.
- Manage Developer Devices: Ensure all developer devices are fully managed and adhere to corporate security policies.
- Enhance MFA and Device Controls: Implement strong multi-factor authentication, but also enforce device-based access controls for sensitive services.
- Continuous Monitoring: Monitor for exposed credentials and implement rapid session revocation mechanisms based on risk signals.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.