Stolen Credentials: How Infostealer Malware Opens the Door to Your Cloud and Code Systems
Research from Wiz highlights how infostealer malware has become one of the most common ways attackers gain initial access to business cloud environments, code repositories, and AI systems. Rather than attacking hardened cloud defences directly, criminals target unsecured personal or developer devices through phishing and social engineering, stealing passwords, API keys, and active session tokens in the process.
These attacks are powered by an organised criminal supply chain. Malware-as-a-Service platforms rent out tools like Lumma and RedLine for a few hundred dollars a month, allowing even low-skilled attackers to harvest credentials in seconds, often evading up-to-date antivirus software. The stolen data is then sold through underground marketplaces, where Initial Access Brokers verify and package valuable credentials for sale to more advanced attackers, including ransomware groups. This process can take anywhere from a few hours to several months from the moment an employee clicks a malicious link.
Critically, infostealers don't just take passwords. They also capture API keys stored in developer configuration files and active session cookies or tokens, which can allow attackers to bypass multi-factor authentication entirely by hijacking an already logged-in session. This makes infostealer infections a serious risk even for organisations that have strong password policies and MFA in place.