$ techbeacon▋
Phishing

Remus Malware Expands to Snatch AI Platform Tokens, Passwords and Crypto Wallets

Remus Malware Expands to Snatch AI Platform Tokens, Passwords and Crypto Wallets

A newly identified Windows‑based infostealer known as Remus has begun exfiltrating authentication tokens used with popular artificial‑intelligence services, alongside traditional credentials such as passwords and cryptocurrency wallet files. Security researchers say the shift marks a notable escalation in the malware's data‑theft capabilities, targeting the emerging market of AI‑powered applications.

Remus has long been catalogued for harvesting login details for email, banking and social‑media accounts. The latest builds, however, are programmed to locate and extract API keys and usage data stored locally for services like OpenAI and Anthropic. Those tokens grant direct access to language‑model endpoints, enabling an attacker to run queries, generate content or consume paid compute resources on behalf of the victim.

The interest in AI API tokens stems from their monetary value and the potential for abuse. Each token typically carries a credit balance or is linked to a billing arrangement, meaning unauthorized use can quickly generate costly charges. Moreover, the tokens can be repurposed to feed large‑scale prompt‑injection attacks or to create counterfeit AI‑generated content that appears to originate from a legitimate account.

Researchers at SpyCloud Labs traced the recent Remus variants to a multi‑stage data‑gathering routine. After establishing persistence on a victim machine, the malware scrapes browser storage, cookie jars and local configuration files to locate authentication material. It then bundles the collected data—including OpenAI and Anthropic keys, saved passwords and encrypted wallet files—and transmits it to command‑and‑control servers for resale on underground markets.

The development reflects a broader trend where cyber‑criminals adapt their toolsets to exploit the rapid adoption of generative‑AI services. As more enterprises integrate AI APIs into internal workflows, the attack surface expands, giving threat actors new avenues for monetization beyond conventional credential theft.

Experts advise users and organizations to treat AI API keys with the same rigor as any privileged credential. This includes storing tokens in secure vaults, rotating them regularly, monitoring usage patterns for anomalies and employing endpoint protection that can detect suspicious file‑access behavior. Limiting the scope of tokens to specific applications can also reduce the impact of a potential breach.

While the full extent of Remus's distribution remains under investigation, analysts expect the malware to evolve further as AI platforms proliferate. Ongoing collaboration between security firms and AI providers will be critical to develop detection signatures and share threat intelligence, helping to curb the misuse of these increasingly valuable digital assets.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related