A new analysis of infostealer malware logs has exposed something that should be on every CISO's radar in 2026: AI account credentials and active sessions tied to more than 80,000 corporate domains are sitting in stealer log marketplaces right now. This isn't a theoretical supply chain risk — it's harvested, indexed, and for sale.
The exposure cuts two ways. First, stolen AI platform logins (ChatGPT, Claude, Gemini, Copilot, and dozens of smaller SaaS AI tools) hand attackers everything your employees ever typed into those platforms: source code, customer data, contracts, credentials pasted into prompts, and internal strategy. Second, stolen API keys and session tokens enable LLMjacking — where threat actors hijack your paid LLM access and burn your cloud budget running their own workloads, or worse, resell access to your models as a proxied service.
The root cause is depressingly familiar: Shadow AI. Employees sign up for AI tools with corporate email, authenticate from infostealer-infected endpoints (often personal or unmanaged devices), and those credentials land in stealer logs alongside everything else. Your IdP never saw the login because the account was never federated. Your DLP never saw the prompt because the tool was never sanctioned.
This post breaks down the attack chain, gives you production-ready detections for infostealer credential theft and AI service abuse, and lays out a remediation plan for finding your organization's exposure before someone monetizes it.
Technical Analysis
What Was Found
SOCRadar's research into infostealer log marketplaces identified AI-related credentials and sessions tied to over 80,000 corporate domains. The logs — the standard output of commodity infostealers like RedLine, Raccoon, Vidar, Lumma, and StealC — contain:
- Saved browser credentials for AI platforms (URLs matching
chat.openai.com,chatgpt.com,claude.ai,gemini.google.com,copilot.microsoft.com, plus hundreds of smaller AI SaaS domains) - Session cookies and tokens, which bypass MFA entirely when replayed before expiry
- API keys stored in plaintext files —
.envfiles, shell profiles,config.json, IDE settings, and~/.configdirectories that infostealers specifically enumerate and exfiltrate - Autofill data and clipboard contents, which frequently include prompts containing sensitive internal data
The Attack Chain
From a defender's perspective, the kill chain looks like this:
- Infection: User executes an infostealer payload — typically via malvertising, cracked software, fake AI tools (ironically, fake "ChatGPT desktop clients" remain a top lure), or phishing. Lumma and StealC dominate current distribution.
- Harvest: The stealer reads browser credential stores (Chrome
Login Data+Local Statefor the DPAPI-encrypted key, Firefoxlogins.json+key4.db), enumerates files matching keyword lists (*.env,*api*key*,*token*,credentials*), and grabs cookies, autofill, and clipboard. - Exfiltration: Logs are zipped and sent to attacker C2, then bundled and sold or traded on Telegram channels and dark web markets — increasingly with dedicated "AI account" filters and pricing tiers.
- Monetization: Buyers either (a) browse stolen conversation history for intelligence and extortion material, (b) replay session cookies to maintain access, or (c) LLMjack extracted API keys — validating them against the provider's API, then using the victim's quota for their own inference workloads, spam generation, or resale as discounted proxied access.
Why LLMjacking Hurts Beyond the Bill
The obvious cost is financial — a hijacked key against a frontier model can rack up thousands of dollars in hours. But the quieter risks matter more:
- Abuse attribution: Attacker-generated content (phishing at scale, CSAM-adjacent content, disinformation) is generated under your account, triggering provider suspensions and potential legal exposure.
- Model and data access: Keys scoped to fine-tuned models or connected data sources (Azure OpenAI deployments, AWS Bedrock agents with knowledge bases, GCP Vertex AI with grounded search) can expose proprietary fine-tunes and internal documents.
- Session replay: Stolen consumer-platform sessions (chat.openai.com, claude.ai) expose full conversation history — which, in a Shadow AI scenario, is effectively an unlogged exfiltration channel of whatever employees pasted in.
Exploitation Status
This is confirmed, active, at-scale criminal activity — not theoretical. Infostealer-as-a-service is a mature economy, AI credential categories are now a standard marketplace filter, and LLMjacking of cloud-hosted LLM endpoints has been observed in the wild since 2024 and continues to accelerate. No CVE applies here; this is credential theft and abuse of valid accounts (MITRE ATT&CK T1552, T1555, T1539, T1078), which makes detection — not patching — the primary control.
Detection & Response
SIGMA Rules
The highest-fidelity signal in this chain is the infostealer harvest itself: a non-browser process reading browser credential stores, or processes scraping files that match AI API key patterns. Both are low-noise in most environments.
---
title: Infostealer-Style Access to Browser Credential Stores
id: 9c2b7f41-3e8a-4d15-b6c9-7a1e2f8d3b44
status: experimental
description: Detects non-browser processes accessing Chrome/Edge/Firefox credential stores, a hallmark of infostealer harvest behavior (RedLine, Lumma, Vidar, StealC) that captures AI platform logins and session cookies.
references:
- https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
- https://attack.mitre.org/techniques/T1555/003/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1555.003
- attack.t1539
logsource:
category: file_event
product: windows
detection:
selection_paths:
TargetFilename|contains:
- '\AppData\Local\Google\Chrome\User Data\'
- '\AppData\Local\Microsoft\Edge\User Data\'
- '\AppData\Roaming\Mozilla\Firefox\Profiles\'
- '\AppData\Local\BraveSoftware\Brave-Browser\User Data\'
selection_files:
TargetFilename|endswith:
- '\Login Data'
- '\Local State'
- '\Cookies'
- '\logins.json'
- '\key4.db'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\brave.exe'
condition: selection_paths and selection_files and not filter_browsers
falsepositives:
- Enterprise password managers and browser backup utilities (verify Image and signer)
- EDR/forensic tooling performing credential audits
level: high
---
title: Suspicious Process Reading AI API Key or Environment Files
id: 2f8d4a67-1b3c-4e59-a2d8-6c9f0e7b5a13
status: experimental
description: Detects non-development processes accessing .env files, shell profiles, or AI provider config files commonly harvested by infostealers for OpenAI/Anthropic/Google API keys.
references:
- https://www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
- https://attack.mitre.org/techniques/T1552/001/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1552.001
- attack.t1552.004
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|contains:
- '\.env'
- '\.openai'
- '\.anthropic'
- '\openai_api_key'
- '\credentials.json'
filter_dev_tools:
Image|endswith:
- '\code.exe'
- '\devenv.exe'
- '\git.exe'
- '\node.exe'
- '\python.exe'
- '\idea64.exe'
condition: selection and not filter_dev_tools
falsepositives:
- CI/CD build agents reading environment files
- Backup and sync agents (OneDrive, Dropbox) — tune by signer
level: high
---
title: Windows Process Enumerating Files by Credential Keywords
id: 6b1e9c05-8d47-4f2a-b3e6-0d5a9c2f8e71
status: experimental
description: Detects command-line file searches for credential/secret keywords, consistent with infostealer and hands-on-keyboard secret harvesting targeting AI API keys stored in plaintext files.
references:
- https://attack.mitre.org/techniques/T1552/
- https://attack.mitre.org/techniques/T1083/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.credential_access
- attack.t1552
- attack.discovery
- attack.t1083
logsource:
category: process_creation
product: windows
detection:
selection_tools:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\findstr.exe'
- '\where.exe'
selection_keywords:
CommandLine|contains:
- 'sk-ant-'
- 'OPENAI_API_KEY'
- 'ANTHROPIC_API_KEY'
- 'api_key'
- '.env'
condition: all of selection_*
falsepositives:
- Developers searching their own projects — correlate with parent process and user context; treat as medium in dev-heavy environments
level: medium
KQL — Hunting in Microsoft Sentinel / Defender
Two angles matter: endpoint harvest behavior, and abuse of the stolen credentials at the network layer. The second query hunts for non-browser processes talking to AI provider API endpoints — a strong signal of LLMjacking or unsanctioned automation in environments where API usage is supposed to originate from known app servers.
// Hunt 1: Non-browser processes touching browser credential stores (infostealer harvest)
let BrowserPaths = dynamic(["chrome.exe", "msedge.exe", "firefox.exe", "brave.exe", "msedgewebview2.exe"]);
DeviceFileEvents
| where TimeGenerated > ago(7d)
| where FolderPath has_any ("\\User Data\\", "\\Firefox\\Profiles\\")
| where FileName in~ ("Login Data", "Local State", "Cookies", "logins.json", "key4.db")
| where not(InitiatingProcessFileName in~ (BrowserPaths))
| where not(InitiatingProcessFolderPath has_any ("\\Windows\\System32\\", "C:\\ProgramData\\Microsoft\\Windows Defender\\"))
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), FilesAccessed = make_set(FolderPath, 10)
by DeviceName, InitiatingProcessFileName, InitiatingProcessFolderPath, InitiatingProcessCommandLine, AccountName
| order by FirstSeen asc;
// Hunt 2: Unexpected processes connecting to AI provider API endpoints (LLMjacking / shadow AI tooling)
let AIEndpoints = dynamic(["api.openai.com", "api.anthropic.com", "generativelanguage.googleapis.com",
"openai.azure.com", "bedrock-runtime", "aiplatform.googleapis.com", "api.cohere.ai", "api.mistral.ai"]);
let KnownGoodProcs = dynamic(["python.exe", "node.exe", "pwsh.exe", "curl.exe"]); // tune to your approved AI tooling
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any (AIEndpoints)
| where not(InitiatingProcessFileName in~ (KnownGoodProcs))
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
URLs = make_set(RemoteUrl, 10)
by DeviceName, InitiatingProcessFileName, InitiatingProcessFolderPath, InitiatingProcessCommandLine, AccountName
| order by Connections desc;
// Hunt 3: Outbound AI API traffic from server/workstation segments with no sanctioned AI workload
// (Requires CommonSecurityLog via firewall/proxy CEF ingestion)
CommonSecurityLog
| where TimeGenerated > ago(24h)
| where DestinationHostName has_any ("api.openai.com", "api.anthropic.com", "generativelanguage.googleapis.com", "api.cohere.ai", "api.mistral.ai")
| summarize Requests = count(), BytesOut = sum(tolong(SentBytes)) by SourceIP, DestinationHostName, DeviceAction
| order by BytesOut desc;
Tune Hunt 2 aggressively before deployment — build your KnownGoodProcs list from the actual executables used by sanctioned AI integrations, or scope the query to server VLANs where no endpoint AI traffic is expected.
Velociraptor VQL — Endpoint Sweep for Exposed AI Keys
Use this to sweep endpoints for plaintext AI API keys sitting in the exact locations infostealers harvest — your exposure is what's on disk today waiting for the next infection.
-- Hunt for plaintext AI provider API keys in files commonly harvested by infostealers
LET key_files = SELECT FullPath, Size, Mtime
FROM glob(globs=[
'C:/Users/*/.env',
'C:/Users/*/**/.env',
'C:/Users/*/.openai/**',
'C:/Users/*/.config/**/config.json',
'C:/Users/*/AppData/Roaming/*AI*/**/*.json'
], accessor='ntfs')
WHERE Size < 1048576
SELECT FullPath, Mtime,
read_file(filename=FullPath, length=512) AS Preview,
regex_replace(source=FullPath, re='C:/Users/([^/]+)/.*', replace='$1') AS User
FROM key_files
WHERE Preview =~ '(?i)(sk-[a-z0-9]|sk-ant-|OPENAI_API_KEY|ANTHROPIC_API_KEY|AZURE_OPENAI|api[_-]?key)'
Run this scoped to high-risk populations first (developers, executives, finance) — full-fleet globs over ** are expensive on large estates.
Remediation Script — Find and Flag Exposed AI Keys
This PowerShell audits local user profiles for plaintext AI keys and verifies whether Chrome credential stores are accessible, giving you a concrete exposure report per endpoint.
# AI Credential Exposure Audit - run elevated via your RMM/Intune
# Flags plaintext AI API keys and confirms browser credential store presence
$KeyPatterns = @('sk-ant-[a-zA-Z0-9-]{20,}', 'sk-[a-zA-Z0-9]{20,}', 'OPENAI_API_KEY\s*=\s*["'']?\S+', 'ANTHROPIC_API_KEY\s*=\s*["'']?\S+', 'AZURE_OPENAI_API_KEY\s*=\s*["'']?\S+', 'AIza[0-9A-Za-z_-]{35}')
$SearchPaths = @("$env:USERPROFILE\.env", "$env:USERPROFILE\.openai", "$env:USERPROFILE\.config", "$env:APPDATA")
$Report = @()
foreach ($Path in $SearchPaths) {
if (Test-Path $Path) {
Get-ChildItem -Path $Path -Recurse -File -Include *.env,*.json,*.txt,*.cfg,*.ini,config -ErrorAction SilentlyContinue |
Where-Object { $_.Length -lt 1MB } | ForEach-Object {
$content = Get-Content $_.FullName -Raw -ErrorAction SilentlyContinue
foreach ($p in $KeyPatterns) {
if ($content -match $p) {
$Report += [PSCustomObject]@{ File = $_.FullName; Pattern = $p; Severity = 'HIGH - Rotate this key immediately' }
}
}
}
}
}
# Check for browser credential stores present on this endpoint (infostealer targets)
$CredStores = @(
"$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Login Data",
"$env:LOCALAPPDATA\Microsoft\Edge\User Data\Default\Login Data",
"$env:APPDATA\Mozilla\Firefox\Profiles"
)
foreach ($store in $CredStores) {
if (Test-Path $store) {
$Report += [PSCustomObject]@{ File = $store; Pattern = 'Browser credential store present'; Severity = 'INFO - Verify saved AI logins and clear stale sessions' }
}
}
$Report | Format-Table -AutoSize
$Report | Export-Csv -Path "$env:TEMP\AI_Credential_Audit_$(hostname).csv" -NoTypeInformation
Write-Output "Audit complete. $($Report.Count) findings exported to $env:TEMP\AI_Credential_Audit_$(hostname).csv"
Remediation
There is no patch for credential theft — remediation here is a combination of exposure discovery, credential invalidation, and hardening. Execute in this order:
1. Assume exposure and rotate (days 1–3)
- Inventory every AI API key your organization has issued — check cloud consoles (Azure OpenAI, AWS Bedrock, GCP Vertex AI), provider dashboards (OpenAI, Anthropic), and SaaS AI admin panels. Any key that has ever lived on an endpoint in plaintext should be treated as compromised.
- Rotate keys, and enforce scoped, rate-limited, budget-capped keys going forward. A key with a $500/month cap and IP allowlisting is a fundamentally different risk than an unscoped org key.
- Force session invalidation on AI platforms where supported (sign out all sessions), and require re-authentication with MFA — note that stolen cookies bypass MFA until expiry, so session revocation matters more than the MFA toggle itself.
2. Buy visibility into stealer log markets (immediate, ongoing)
- Engage a dark web / stealer log monitoring capability (as SOCRadar did here) and subscribe your corporate domains. You cannot takedown your way out of this — but you can get a hit list of which users, devices, and AI accounts appear in logs, and force targeted resets within hours instead of months.
- When a domain match appears, treat it as an incident: the endpoint that produced the log is (or was) infected. Isolate, reimage, and reset all credentials the user touched — not just the AI one.
3. Kill the Shadow AI gap (weeks 1–4)
- Stand up sanctioned, federated AI access (enterprise ChatGPT/Claude/Copilot tenants with SSO) so employees have an approved path — blocking without an alternative just pushes usage further into shadow.
- Use your CASB, SWG, or DNS layer to inventory AI SaaS usage by destination domain. The list will surprise you; the 80,000-domain figure in this report is what Shadow AI looks like at population scale.
- Enforce Conditional Access / device compliance policies so AI platform sessions from unmanaged devices are blocked or read-only.
4. Endpoint hardening (weeks 2–6)
- Enable App-Bound Encryption enforcement on Chrome (rolled out by Google specifically to break infostealer cookie theft) and keep browsers current.
- Deploy the Sigma rules above; the browser-credential-store access rule is among the highest-fidelity infostealer tripwires available.
- Prohibit plaintext API keys on endpoints: move developers to secret managers (Azure Key Vault, AWS Secrets Manager, HashiCorp Vault) with short-lived tokens, and add the VQL sweep above to your scheduled hunt cadence.
5. Cloud-side LLMjacking controls
- Set hard budget alerts and anomaly detection on Azure OpenAI, Bedrock, and Vertex AI spend. A hijacked key shows up as a usage spike before anything else — a billing alert is often your first SIEM alert.
- Restrict model endpoint network access via private endpoints / VPC controls so a stolen key is useless outside your network.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.