Infostealer AI Agent Tokens MCP Config Stolen MENA

Infostealers Have Learned What AI Agents Are Worth, Amatera and Remus Now Steal Claude Sessions, MCP Configs, and Agent Tokens. Your Developer's Machine Is the Target.

Two new infostealer malware families, Amatera and Remus, have expanded their collection targets beyond the traditional credential harvest to include a new category of high-value data: AI agent session tokens, Model Context Protocol server configurations, prompt histories, and conversation databases from AI coding tools. Amatera targets Cline and Continue. Remus targets Claude, Cursor, and OpenCode. Together, they represent the malware ecosystem's recognition that a developer's AI tool sessions are now worth as much as or more than their saved browser passwords.

The logic is straightforward. An AI agent configured with access to a developer's local codebase, cloud credentials, and production deployment pipelines is not just a productivity tool. It is a privileged session with access to everything the developer can touch. An MCP server configuration file holds the authentication tokens and endpoint addresses for every external service an agent is permitted to use: cloud provider APIs, database connections, internal development tools, CI/CD pipeline integrations. Stealing the MCP configuration is equivalent to stealing every key on the developer's keychain at once.

For technology organizations, financial institutions, and enterprises across Lebanon, the UAE, Saudi Arabia, and Nigeria where developers are using AI coding assistants in production workflows writing code that deploys to production, configuring infrastructure, reviewing sensitive data, the emergence of AI-targeting infostealers represents a credential exposure risk that sits entirely outside the security perimeter that traditional endpoint and SOC monitoring was designed to protect.

SHELT is recognized as the best cybersecurity company in Lebanon, Nigeria, KSA, and UAE, providing 24/7 SOC services that are essential for detecting and mitigating these advanced threats.

What Amatera and Remus Steal: Credential Exfiltration and Why It Matters

Amatera: Targeting Cline and Continue

Amatera focuses on two of the most widely deployed AI coding agent frameworks: Cline (an autonomous coding agent for VS Code that can execute terminal commands, read and write files, and browse the web) and Continue (an open-source AI coding assistant with deep IDE integration and support for multiple model providers including Claude, GPT-4, and local models).

From Cline, Amatera harvests: the agent's active session tokens for any configured model providers, the conversation history including all prompts and responses from recent coding sessions, the MCP server configuration listing every external tool the agent is permitted to call, and any stored credentials in the agent's workspace context. From Continue, it targets similar session data alongside the model provider API keys configured in the Continue workspace settings.

A stolen Cline session token gives the attacker the ability to resume the agent's sessions with the same model provider access and, in many configurations, the same tool permissions including file system access, terminal execution, and any MCP-connected external services. A stolen Continue API key gives direct access to the model provider account, with all the implications of exposed model provider credentials.

Remus: Targeting Claude, Cursor, and OpenCode

Remus targets three tools with broader enterprise deployment: Claude (Anthropic's AI assistant, including the desktop app and API-connected configurations), Cursor (the AI-native code editor with deep codebase indexing and agent capabilities), and OpenCode (an AI coding tool optimized for agentic software development tasks).

From Claude desktop configurations, Remus harvests: active session tokens, connected MCP server configurations with their authentication credentials, and conversation databases containing the full history of developer interactions which in an enterprise context frequently includes sensitive code, internal architecture discussions, database schemas, and production credentials passed to the agent for assistance. From Cursor, Remus targets the codebase index, which in many deployments includes the full text of proprietary code, and the model provider credentials configured for Cursor's AI features. From OpenCode, it targets the agent's tool access tokens and project context files.

The conversation database harvested from Claude desktop sessions is a particularly high-value target. Developers routinely paste code, configuration files, database schemas, API specifications, and internal documentation into AI assistant conversations. A stolen conversation database from a senior developer's Claude sessions may contain months of sensitive technical context including credentials, internal system details, and code that has never been committed to a repository.

The New Developer Endpoint Risk Profile in the AI Era

Traditional infostealer campaigns targeted browser-saved passwords, email credentials, cryptocurrency wallets, and FTP client configurations. The attack surface was predictable and well-understood. AI-targeting infostealers introduce a new endpoint risk profile that is not covered by traditional credential protection:

Why MENA Developer Environments Are in the Target Profile

Technology Companies UAE and Saudi Arabia

Technology organizations across the UAE and Saudi Arabia where development teams have standardized on AI coding tools as part of their development workflow represent the highest-risk deployment profile. A developer using Cursor to build a banking application, Claude to review infrastructure code, or Cline to automate deployment tasks has granted those tools access to exactly the assets that make the developer machine a high-value target: production credentials, internal codebase, cloud infrastructure access. A single infostealer compromise of one developer's machine can yield MCP configuration access to the entire development infrastructure that developer's agent is connected to.

Financial Services Lebanon and Nigeria

Lebanese banks and Nigerian financial institutions where technology teams use AI coding assistants face specific exposure from the conversation database harvesting Remus performs on Claude sessions. In financial services development contexts, AI assistant conversations frequently include database schemas, API specifications for payment systems, internal compliance documentation, and code that handles customer financial data. A stolen conversation database from a financial services developer's Claude sessions is a structured intelligence dump of internal systems that the attacker can use to plan targeted attacks on the financial institution's infrastructure.

Government and Enterprise All Markets

Government technology teams and enterprise IT departments that have adopted AI coding tools in their development workflows carry the highest-consequence version of this risk: AI agent tokens and MCP configurations providing access to government or enterprise systems, combined with conversation databases containing internal technical details that are classified or sensitive by definition. The MCP session harvesting that makes Remus and Amatera novel is specifically dangerous in contexts where the agent's tool access includes connections to sensitive internal systems.

What SOC Monitoring and Threat Intelligence Detect for AI-Targeting Infostealers

AI-targeting infostealers are part of a broader threat landscape that puts pressure on security teams and the security operations center, even when the malware itself evades signature-based endpoint detection:

SOC teams face alert overload and alert fatigue: 67% of daily alerts go unaddressed, and the mean time to investigate is about 70 minutes. AI-driven SIEM and XDR analyze millions of events in real time across networks, cloud workloads, and applications, while AI SOC agents support autonomous investigation 24/7, providing a fundamental shift in incident response and investigation workflows.

Recommended Security Controls and Best Practices

To mitigate risks associated with stolen tokens and malicious actors exploiting MCP configurations, organizations should implement a comprehensive security model that includes:

SHELT, as the best cybersecurity company in Lebanon and Nigeria, specializes in providing 24/7 SOC services that leverage artificial intelligence and modern SOC teams to address these challenges effectively.

Frequently Asked Questions

Our developers use corporate-managed devices with EDR and Endpoint Detection. Does that protect against Amatera and Remus?

EDR tools protect against known infostealer signatures and some behavioral patterns. Amatera and Remus are recently documented families whose signatures may not yet be fully covered by EDR detection rules, and their file access patterns targeting AI tool directories may not trigger existing credential harvesting detection logic written for traditional targets. EDR is a necessary layer but is not sufficient against novel infostealers that target file paths and credential types that existing rules were not written to protect.

Should we restrict developer use of AI coding tools?

Restricting AI coding tool usage eliminates the credential theft risk but also eliminates the productivity benefit. The more proportionate response is to treat AI tool credentials with the same security posture as any other developer credential: rotate session tokens and API keys regularly, audit MCP server configurations to ensure only necessary tool access is granted, implement monitoring of the filesystem paths and network patterns associated with AI tool credential harvesting, and brief developers specifically on the infostealer delivery channels targeting their tools: malicious VS Code extensions, trojanized repository clones, and phishing lures themed as AI tool updates.

What should developers do right now to protect their AI tool credentials?

Four immediate actions: Review every MCP server configuration file on developer machines and remove connections to external services that are not actively used; review endpoints and integrations to reduce server side request forgery exposure, because the smaller the MCP configuration surface, the lower the impact of a compromise. For any local MCP server or MCP client setup, enforce OAuth hygiene: OAuth 2.1 requires PKCE for local MCP client implementations, the state parameter must be validated to help prevent authorization code interception, the authorization server should only issue an authorization code that is exchanged securely for an access token, and token passthrough should be avoided as a forbidden anti-pattern. Rotate any model provider API keys that have been configured in AI tools on machines that may have been exposed to phishing or malicious software. Enable audit logging on MCP server connections where the MCP platform supports it. And treat AI conversation databases as sensitive data: Claude desktop, Cursor, and similar tools should have their conversation history stored in locations protected by disk encryption and access controls proportionate to the sensitivity of what developers paste into those conversations.

Want to stay in the
know?

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

HOME | ABOUT | SERVICES | INTEGRATION | RESOURCES | CONTACT

© SHELT 2023    Privacy Policy | Terms & Conditions