GitHub, Google Cloud and AWS: Hackers Don’t Need to Break Into the Cloud When They Can Steal the Keys

GitHub, Google Cloud and AWS: Hackers Don’t Need to Break Into the Cloud When They Can Steal the Keys

Infostealer Malware Targets Cloud Credentials, Enabling Silent Corporate Breaches

Cybercriminals are increasingly leveraging infostealer malware to bypass hardened cloud defenses by compromising employee or developer devices and harvesting trusted credentials, API keys, and active sessions. According to a report by Wiz.io shared with Cyber Security News, these attacks exploit phishing, malicious downloads, or poisoned software dependencies to deploy stealers like Lumma C2, RedLine, and Vidar, which accounted for 85.7% of detected incidents.

Once infected, malware rapidly extracts browser data and local secrets, enabling attackers to sell access to other criminals. AWS and Google Cloud credentials were the most frequently compromised, representing 46% and 13% of stolen secrets, respectively. Valid tokens can grant access to cloud consoles, code repositories, CI/CD pipelines, and AI services, leading to data exposure or unauthorized resource consumption.

Attackers often bypass multi-factor authentication (MFA) by stealing browser session tokens created after legitimate logins which can be replayed in another browser to impersonate users. Long-lived credentials, such as AWS access keys stored in developer files or Azure CLI caches, further extend this risk. Google Cloud environments are similarly vulnerable, with command-line credentials and service-account keys providing persistent access.

GitHub tokens (10% of stolen secrets) and AI platform credentials (5%) are also prime targets. Stolen AI keys can drain service quotas at the victim’s expense, while compromised sessions may expose internal chat histories or proprietary models. The attack chain mirrors recent AI infrastructure breaches, where exposed systems serve as gateways to broader cloud resources.

Malware-as-a-service operators distribute stealers, while initial-access brokers validate and resell stolen credentials, turning a single infected device into a full-blown cloud incident. Recent campaigns, such as MacSync, have demonstrated how developer-focused infections can escalate into enterprise breaches.

Organizations are advised to treat infostealer infections as identity incidents, requiring isolation of affected devices, revocation of active sessions, and rotation of credentials from a clean system. Log reviews should focus on unfamiliar sessions, unusual token activity, and unauthorized role changes. Rebuilding endpoints from clean sources is recommended, as malware removal alone may not eliminate stolen access.

The report highlights indicators of compromise (IoCs), including abused Windows tools (vbc.exe), trojanized gaming files (Roblox.exe, SkinChanger.exe), and targeted credential storage locations (e.g., ~/.aws/credentials, %localappdata%.IdentityService\msal.cache). Prevention strategies include short-lived credentials, managed vaults, and device-based access controls to reduce the value of endpoint-stored secrets.

Source: https://cybersecuritynews.com/break-into-the-cloud/

GitHub TPRM report: https://www.rankiteo.com/company/github

Google Cloud TPRM report: https://www.rankiteo.com/company/googlecloudsecurity

AWS TPRM report: https://www.rankiteo.com/company/amazon-web-services

"id": "gitgooama1790591146",
"linkid": "github, googlecloudsecurity, amazon-web-services",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': ['enterprise', 'developer']}],
 'attack_vector': ['phishing',
                   'malicious downloads',
                   'poisoned software dependencies'],
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['cloud credentials',
                                              'API keys',
                                              'browser session tokens',
                                              'AI platform credentials',
                                              'GitHub tokens']},
 'description': 'Cybercriminals are increasingly leveraging infostealer '
                'malware to bypass hardened cloud defenses by compromising '
                'employee or developer devices and harvesting trusted '
                'credentials, API keys, and active sessions. These attacks '
                'exploit phishing, malicious downloads, or poisoned software '
                'dependencies to deploy stealers like Lumma C2, RedLine, and '
                'Vidar, which accounted for 85.7% of detected incidents. Once '
                'infected, malware rapidly extracts browser data and local '
                'secrets, enabling attackers to sell access to other '
                'criminals. Valid tokens can grant access to cloud consoles, '
                'code repositories, CI/CD pipelines, and AI services, leading '
                'to data exposure or unauthorized resource consumption.',
 'impact': {'data_compromised': ['cloud credentials',
                                 'API keys',
                                 'browser session tokens',
                                 'AI platform credentials',
                                 'GitHub tokens'],
            'identity_theft_risk': 'high',
            'operational_impact': 'unauthorized access to cloud resources, '
                                  'data exposure, unauthorized resource '
                                  'consumption',
            'systems_affected': ['cloud consoles',
                                 'code repositories',
                                 'CI/CD pipelines',
                                 'AI services']},
 'initial_access_broker': {'data_sold_on_dark_web': True,
                           'entry_point': ['phishing',
                                           'malicious downloads',
                                           'poisoned software dependencies'],
                           'high_value_targets': ['AWS credentials',
                                                  'Google Cloud credentials',
                                                  'GitHub tokens',
                                                  'AI platform credentials']},
 'lessons_learned': 'Infostealer infections should be treated as identity '
                    'incidents, requiring isolation of affected devices, '
                    'revocation of active sessions, and rotation of '
                    'credentials. Log reviews should focus on unfamiliar '
                    'sessions, unusual token activity, and unauthorized role '
                    'changes. Rebuilding endpoints from clean sources is '
                    'recommended.',
 'motivation': ['financial gain',
                'data exfiltration',
                'unauthorized resource consumption'],
 'post_incident_analysis': {'corrective_actions': ['isolation of affected '
                                                   'devices',
                                                   'revocation of active '
                                                   'sessions',
                                                   'rotation of credentials',
                                                   'rebuilding endpoints from '
                                                   'clean sources',
                                                   'log reviews for unusual '
                                                   'activity'],
                            'root_causes': ['compromised employee/devices',
                                            'harvesting of trusted '
                                            'credentials/API keys/sessions',
                                            'lack of short-lived credentials '
                                            'and device-based access '
                                            'controls']},
 'recommendations': ['use short-lived credentials',
                     'implement managed vaults',
                     'enforce device-based access controls',
                     'monitor for indicators of compromise (IoCs) such as '
                     'abused Windows tools (vbc.exe) and trojanized files '
                     '(Roblox.exe, SkinChanger.exe)'],
 'references': [{'source': 'Wiz.io'}, {'source': 'Cyber Security News'}],
 'response': {'containment_measures': ['isolation of affected devices',
                                       'revocation of active sessions',
                                       'rotation of credentials from a clean '
                                       'system'],
              'recovery_measures': ['rebuilding endpoints from clean sources'],
              'remediation_measures': ['log reviews for unfamiliar sessions',
                                       'unusual token activity monitoring',
                                       'unauthorized role changes detection']},
 'threat_actor': ['initial-access brokers', 'malware-as-a-service operators'],
 'title': 'Infostealer Malware Targets Cloud Credentials, Enabling Silent '
          'Corporate Breaches',
 'type': 'Infostealer Malware',
 'vulnerability_exploited': ['browser session tokens',
                             'long-lived credentials (AWS access keys, Azure '
                             'CLI caches)',
                             'GitHub tokens',
                             'AI platform credentials']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.