Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Malware distributed through Malware-as-a-Service platforms has overtaken traditional access techniques as the primary vector for compromising enterprise cloud environments. According to an advisory published by Wiz on September 25, 2026, these tools — rentable for a few hundred dollars a month — steal credentials, API keys, and session tokens from developer endpoints that are often less protected than corporate workstations, bypassing MFA controls entirely. The stakes are no longer about the strength of authentication, but about protecting the device after the user has already passed every check.
- Lumma C2, RedLine, and Vidar account for 85.7% of incidents detected by Wiz via NordStellar integration, with a MaaS ecosystem that drastically lowers the barrier to entry for threat operators.
- Cloud credentials dominate the haul: AWS represents 46% and GCP 13% of compromised secrets, while GitHub — the third target — absorbs roughly 10% with App Tokens, OAuth tokens, and PATs.
- Attackers do not break MFA: they steal post-authentication session tokens, gaining access windows that for AWS SSO OIDC tokens can extend up to 90 days.
- AI platforms enter the crosshairs with 5% of stolen secrets, predominantly OpenAI API keys, extending the attack surface to workloads and development pipelines previously overlooked.
The Mechanism: From Personal Device to Enterprise Cloud
Infection begins on machines that enterprise security teams do not directly control. Wiz documents the use of legitimate Windows binaries such as vbc.exe and trojanized gaming files — Roblox.exe, Valorant SkinChanger.exe — to hook developers on their personal devices. The malware then extracts credentials from password managers, macOS keychains, browsers, and cloud keys for AWS, GCP, Azure, and Cloudflare, as verified in the AUDIOFIX sample associated with actor JINX-0164.
The critical detail is that the theft occurs after authentication. As Wiz reports, attackers "steal post-MFA authentication session tokens rather than attempting to breach MFA itself, bypassing the control entirely." AWS SSO OIDC tokens, stored in ~/.aws/sso/cache/, typically last up to 90 days: the attacker needs neither the password nor the second factor, only a file the user legitimately generated after passing all checks.
Temporary STS tokens in ~/.aws/cli/cache/, with a lifespan of 1-12 hours, prove less attractive to infostealer operators. ~/.aws/config files, while containing no secrets, reveal profiles, roles, and accessible accounts: a reconnaissance map that precedes lateral movement.
"Identity has long been the primary attack surface of the cloud. Infostealer malware, distributed through an industrialized cybercrime economy, is a leading initial access vector for compromising enterprise cloud, code, and AI environments."
The Numbers: Cloud, Code, and AI in the Crosshairs
Wiz's NordStellar integration identified over 400 distinct types of non-credential secrets collected by infostealers, a variety that makes defense by negative listing impractical. Compromise percentages reveal a clear hierarchy: AWS at 46% and GCP at 13% constitute the absolute majority, followed by GitHub at roughly 10% — App Tokens, OAuth tokens, and Personal Access Tokens that open CI/CD pipelines and private repositories.
The positional novelty concerns AI platforms, now at 5% of stolen secrets with OpenAI as the dominant provider in the segment. Wiz does not quantify specific incidents of access to historical chat logs, and the dossier does not document whether such compromise has occurred in publicly reported campaigns. The data remains significant nonetheless: API keys for reasoning and inference services represent a privileged entry point into workloads handling sensitive training data and prompt engineering.
Miasma, described by Wiz as an infostealer-like evolution, extends targeting directly to CI/CD pipelines through software dependency compromise. It is no longer about human endpoints but automated build processes, development servers, and release artifacts: a qualitative leap that erodes the boundary between developer security and infrastructure security.
Industrialization: From MaaS to Ransomware Affiliates
The economic model is what makes the phenomenon scalable beyond all prediction. Lumma, RedLine, and Vidar operate on a monthly rental scheme, democratizing access to technical capabilities that a decade ago required proprietary reverse-engineering skills. The chain completes with Initial Access Brokers who resell validated credentials, and finally with ransomware affiliates who execute the final monetization.
TeamPCP, tracked by Wiz in related analyses, validated stolen credentials with TruffleHog and launched AWS discovery operations within 24 hours of the theft. Defensive response time is measured in hours, not days: the speed of commoditization outpaces many enterprise incident response operations.
Wiz signals that no infrastructure overlaps emerge linking Miasma to TeamPCP at this stage: the possibility of copycats remains open, and the dossier does not resolve this uncertainty. Attribution, here as elsewhere, is a declared limit rather than a forced hypothesis.
"These attacks begin with a simple malware infection on a personal device, and end with attackers gaining privileged access to your AWS, Azure, or GCP estate, and more recently to the code platforms used by your organization, such as GitHub or GitLab."
Why It Matters
The "strong authentication equals security" paradigm shows its limits. MFA remains technically valid: it is not vulnerable in itself, but is systematically bypassed by an attack that shifts the target to the token generated after its passage. Enterprise investment in multi-factor authentication is not wasted, but proves insufficient without parallel protection of the endpoints that generate and store session tokens.
The perimeter has shifted from the data center to the developer's device, often personal, often with looser security policies than the corporate workstation. Wiz does not specify technical remediation measures in its advisory, and the dossier does not document operational recommendations such as key rotation, zero-trust segmentation, or endpoint hardening. The source stops at mapping the phenomenon: the implications for defensive practice remain, for now, a reading exercise for the audience.
The percentage figure for AI platforms — 5% — may appear marginal, but placed in a market of reasoning API keys in exponential expansion, it indicates a rapidly growing attack surface. The brief does not quantify transaction volume in the illegal LLM resale market, nor the exact geographic extent of campaigns.
The clearest lesson is that the enterprise cloud can no longer assume that strong authentication on corporate endpoints constitutes a sufficient perimeter. The tools to bypass it are cheap, distributed, and technically trivial: stealing a cache file beats every complex password policy.
Frequently Asked Questions
Has MFA become useless?
No. MFA is not technically vulnerable: attackers bypass it by stealing tokens generated after its passage, not by attacking the mechanism itself. The control remains valid for direct access, not for already-authenticated sessions.
Why do OIDC SSO tokens last 90 days?
This is the typical duration configured in AWS SSO systems. The user does not manually manage expiration: the token remains valid in the cache file even if the user no longer accesses it, creating an extended vulnerability window that the attacker exploits without needing re-authentication.
Do Wiz data represent global statistics?
The data come from Wiz's proprietary NordStellar integration. The dossier does not clarify whether the dataset is limited to Wiz customers or has broader coverage, and should be read as specific evidence from a tier-1 source rather than as a representative industry statistic.
Information is based on the cited source and current as of the time of publication.
Sources
- https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials
- https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages
- https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild
- https://www.wiz.io/blog/threat-actors-target-crypto-orgs
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.