Skip to content
Infostealer Malware Targets AI Accounts with Session Cookie Theft

Infostealer Malware Targets AI Accounts with Session Cookie Theft

First seen 20 Sep 2026, 21:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 21:58 UTC
  • Infostealer malware now targets generative AI accounts, stealing session cookies.
  • Over 49,700 stolen session cookies from AI platforms are circulating on the dark web.
  • Attackers can access AI accounts without passwords, compromising both personal and corporate data.

Infostealer malware has evolved to target generative AI accounts, stealing session cookies to bypass traditional authentication methods like passwords and two-factor verification. A report by KELA revealed that over 49,700 session cookies from AI platforms were sold on the dark web from January to July 2026, many of which remain valid for logins. This malware not only compromises personal data but also corporate resources, as employees use AI for sensitive tasks. Microsoft previously identified 900,000 installations of malicious browser extensions that collected sensitive AI conversation data. A recent analysis by Octa found 555 authentication tokens linked to AI services among 44,791 tokens extracted from infected PCs. The theft of API keys for platforms like Google Gemini and OpenAI has also been confirmed, allowing attackers to exploit AI services at the victims' expense. The situation highlights the emerging criminal ecosystem around stolen AI credentials.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-01
Session cookies stolen
Over 49,700 session cookies from AI platforms were confirmed stolen and circulated on the dark web.
Chosun
2026-03-01
Malicious extensions identified
Microsoft reported approximately 900,000 installations of malicious browser extensions collecting AI conversation data.
Chosun
2026-09-18
KELA report published
KELA confirmed the theft of session cookies and their circulation on the dark web, emphasizing the threat to AI accounts.
Chosun
2026-09-20
Infostealer malware news published
Chosun published articles detailing the evolving threat of Infostealer malware targeting AI accounts.
Chosun

More articles in this cluster (2)

Following this threat?

Track OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed