In short: On October 1, 2026, Russian infosec outlets reported a finding from BI.ZONE Threat Intelligence: a new generation of infostealers — Bee Stealer (sold on darknet forums for about $300) and AVENGER for macOS — now steals not just passwords and cookies, but the entire local chat history with AI assistants on an infected device. A language model built into the stealer itself then sorts the haul into categories and assembles a readable victim profile — occupation, interests, work projects, even travel plans — instead of just dumping raw data to the operator. Two such samples were documented in September 2026.
What stealers actually take from AI chats
In conversations with an AI assistant, people leave things that typically don't exist anywhere else: contract drafts, code snippets, service access tokens, medical questions, financial plans. For a stealer, that's a single point where the most sensitive material is already gathered — no need to separately hunt for browser passwords and messenger chats. BI.ZONE documented theft of chat request/response history, session authentication data, code fragments and internal documents, and configuration files with access tokens.
Why scammers want a finished dossier, not raw data
Previously, a stealer operator received a raw log archive and had to manually sift through it. Now the malware's own built-in AI model analyzes the stolen data right at the exfiltration stage and produces a short victim profile: occupation, interests, which services and domains relate to their professional work. In one documented case, the model correctly identified the infected device's owner as an IT specialist and web developer and singled out domains tied specifically to their work projects. A conversation where the other side already knows your context and life details clears a trust check far more easily than a generic phishing email — sharply boosting the conversion rate of follow-on social-engineering attacks.
What this means for ordinary users and their data
If you've ever pasted a work document, code fragment, or access key into a chatbot, a stealer compromising your device hits far wider than a single compromised account. We covered an adjacent risk separately — what data a phone's built-in system AI assistant actually collects and how to limit its access: AI assistant privacy on your phone. This is a different vector: not a vendor's legal data collection, but malware stealing local chat history, typically delivered via phishing or fake installer sites.
How to protect yourself now
- Don't paste into an AI chat anything you're not prepared to see in someone else's hands. Keep passwords, access tokens, document scans, and financial details out of the conversation with your assistant.
- Use two-factor authentication and a password manager — if a stealer does land on your device, this limits the damage from stolen credentials.
- Periodically end active sessions and revoke unused tokens for services and AI assistants you no longer use.
- Verify the source of files and links before installing anything — most such stealers spread through fake websites and phishing emails rather than official app stores; see a similar scheme in our piece on the fake ClickFix CAPTCHA.
- Encrypt your network traffic. LiMP VPN won't remove a stealer from an infected device, but it hides your real IP address and encrypts your connection at the network level, reducing what an attacker can learn about you during reconnaissance before an attack.
Plans with a verified no-logs policy: LiMP VPN pricing. More AI and cybersecurity coverage on the LiMP VPN blog.
