Chosun Infostealer Malware Targets AI Accounts with Session Cookie Theft
Article Content
- •Infostealer malware now targets generative AI accounts, stealing session cookies.
- •Over 49,700 stolen session cookies from AI platforms are circulating on the dark web.
- •Attackers can access AI accounts without passwords, compromising both personal and corporate data.
Infostealer malware has evolved to target generative AI accounts, stealing session cookies to bypass traditional authentication methods like passwords and two-factor verification. A report by KELA revealed that over 49,700 session cookies from AI platforms were sold on the dark web from January to July 2026, many of which remain valid for logins. This malware not only compromises personal data but also corporate resources, as employees use AI for sensitive tasks. Microsoft previously identified 900,000 installations of malicious browser extensions that collected sensitive AI conversation data. A recent analysis by Octa found 555 authentication tokens linked to AI services among 44,791 tokens extracted from infected PCs. The theft of API keys for platforms like Google Gemini and OpenAI has also been confirmed, allowing attackers to exploit AI services at the victims' expense. The situation highlights the emerging criminal ecosystem around stolen AI credentials.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…