Threat reportMalwareTL-2026-3026
Warden Stealer: Rust MaaS Infostealer, Clipper and Loader Targeting AI Agents (Claude Code, Codex CLI) and Developer Keys
Warden Stealer (TL-2026-3026), also tracked as WARDEN Stealer, is a high-severity malware campaign, first published 2026-10-07. It is attributed to WardenStealer with low confidence, affects Microsoft Windows (x64), maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1030), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 1WardenStealer
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-3026
- Threat ID
- TL-2026-3026
- Also known as
- WARDEN Stealer, Warden Infostealer
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- WardenStealer
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, finance, cryptocurrency, general-consumer
- Target regions
- Global (CIS and Baltic countries excluded by geofencing)
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Warden Stealer
Malware and tooling: Clipper, Warden Stealer, Claude Code, Codex CLI
How Warden Stealer works
Warden Stealer is a Rust-based malware-as-a-service stealer, clipper and loader released publicly on 2026-07-21 that targets 360+ applications across 13 categories, including AI/developer tooling (Claude Code, Codex CLI, GitHub, SSH keys), Chromium/Gecko browser data and 200+ crypto wallet extensions. Hudson Rock's Cavalier platform reports tens of thousands of compromised machines; most capability, revenue and success-rate figures are developer claims, and no samples or IOCs have been published.
Warden Stealer is a Windows x64 information stealer, cryptocurrency-address clipper and loader sold as a malware-as-a-service (MaaS) subscription on underground forums. Hudson Rock (InfoStealers) reports development began in early 2026 and the product was publicly released on 2026-07-21; the operator handle is "WardenStealer" and the product is advertised on the Exploit.in forum. KrakenLabs (Outpost24) documented the advertisement on 2026-07-24, and secondary coverage (GridinSoft, Cyberpress, BornCity, PCrisk) repeats those claims. Hudson Rock's Cavalier platform has detected tens of thousands of machines compromised by the family, and an anonymous developer interview (published by g0njxa) states roughly 110 customers actively use it.
Capabilities. Chromium and Gecko browser profiles (passwords, history, autofill, cookies, payment cards) plus messengers, gaming clients, password managers, VPNs and FTP clients; counts vary by source (330+ applications per KrakenLabs-derived coverage, 360+ across 13 categories per Hudson Rock). From version 1.9 the stealer adds AI and developer-tool targets: Claude Code, Codex CLI, Discord, GitHub and SSH keys. Per Hudson Rock it exfiltrates the .claude.json file containing the primaryApiKey value and steals OAuth account data tied to Anthropic/Claude accounts. The crypto module targets 200+ wallet extensions and desktop apps across 96 networks and includes a bruteforce engine that builds custom dictionaries from victim data (490+ mutation rules, up to 20M candidates per wallet). The developer claims a 66% crack rate on wallets with balances and $485,000 stolen in a recent run; these figures are unverified. A clipper (v2 in development) swaps copied wallet addresses for attacker-controlled ones, and the loader fetches and executes secondary payloads from operator-supplied URLs.
Evasion and operations (all vendor/developer claims, no sample verification). A "proprietary binary transfer protocol" with custom per-build encryption and chunked log uploads, server-side decryption so the client stays small (~350 KB per Hudson Rock; 500-600 KB per KrakenLabs-derived coverage), hardware-ID tying for zero duplicate logs, "AST/LLVM morphing" at PE-layout, AST, IR and ASM levels, anti-VM/sandbox checks, process injection, a claimed browser App-Bound Encryption bypass, geofencing that excludes CIS and Baltic countries, Cloudflare-backed gates with automatic failover, and a web panel with real-time dashboards and Telegram notifications. Pricing is reported as a $349/month personal tier up to $1,500/month for Enterprise, with a free 3-day trial.
Intelligence limits. No hashes, domains, IPs, delivery chain or confirmed victim campaign have been published; GridinSoft explicitly notes the capabilities are seller claims and the name alone does not prove execution or theft. Defenders should treat AI-agent credential files and developer keys on Windows endpoints as stealer targets and focus on behavioral detection and credential hygiene.
MITRE ATT&CK techniques used in TL-2026-3026
Collection
Stealth
T1027 Obfuscated Files or Information; T1055 Process Injection; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1030 Data Transfer Size Limits
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files; T1552.004 Private Keys; T1555.003 Credentials from Web Browsers; T1555.005 Password Managers
Command and Control
Discovery
T1614 System Location Discovery
Impact
Affected products and versions in Warden Stealer
- Microsoft — Windows (x64)
Vulnerable versions: Windows 7 through Windows 11 (as advertised) - Anthropic — Claude Code (.claude.json primaryApiKey and OAuth account data)
Vulnerable versions: Credential files on any infected host - OpenAI — Codex CLI (local credentials/config)
Vulnerable versions: Credential files on any infected host - GitHub — GitHub credentials and SSH keys on developer hosts
Vulnerable versions: Any
Remediation for Warden Stealer
Immediate actions
- Treat any endpoint with suspected Warden activity as compromised: rotate Anthropic/Claude API keys and OAuth sessions, OpenAI/Codex credentials, GitHub tokens and SSH keys that were present on it
- Revoke and re-issue browser-stored credentials and invalidate active session cookies for SaaS, cloud and developer accounts
- Move crypto assets from wallets/extensions on affected hosts to newly generated wallets and re-verify destination addresses before any transfer
Workarounds
- Restrict execution of unsigned binaries from user-writable paths via application control (WDAC/AppLocker)
- Block unsanctioned software downloads and enforce phishing-resistant MFA so stolen passwords/cookies alone do not grant access
Longer-term hardening
- Keep AI-agent credentials out of plaintext config files (use OS keychain or short-lived scoped tokens) and avoid long-lived primary API keys on developer workstations
- Use hardware-backed SSH keys and passphrase-protected keys; enforce short-lived GitHub tokens with scoped permissions
- Deploy EDR with behavioral detection for non-browser processes reading browser profile stores, wallet extension data, .claude.json and ~/.ssh, and for clipboard hijacking
- Monitor infostealer-exposure feeds (e.g. Hudson Rock Cavalier) for employee and developer credential leakage
Timeline of Warden Stealer
- Per Hudson Rock, Warden Stealer development began in early 2026 (exact month not given; date is a placeholder for 'early 2026')
- Warden Stealer publicly released as a Rust-based MaaS stealer, clipper and loader (Hudson Rock)
- Cyberpress, BornCity and GridinSoft publish coverage of the offering, noting $349/month personal pricing, CIS/Baltic geofencing and that no samples or IOCs are public
- KrakenLabs documents the 'WardenStealer' advertisement: Windows x64 stealer/clipper/loader with 330+ app targets, 200+ wallet extensions, custom encrypted protocol and ABE bypass claims
- PCrisk publishes a WARDEN Stealer removal guide listing generic 'WARDEN data stealer' detection names
- Hudson Rock reports v1.9 targeting of Claude Code (.claude.json primaryApiKey, OAuth data), Codex CLI, GitHub and SSH keys, and tens of thousands of infected machines in Cavalier data; developer interview claims ~110 active users
Sources cited for Warden Stealer
- Infostealers Are Actively Hunting AI Agents and Developer Keys - Warden Infostealer (Hudson Rock)
- Approaching Stealer Devs: A Brief Interview with Warden (g0njxa) - cited by Hudson Rock, not retrievable
- WARDEN Stealer: Claims, Cookie Theft Risk, and Removal (GridinSoft)
- New WARDEN Stealer Targets 330+ Apps and 200 Crypto Extensions on Windows (Cyberpress)
- WARDEN Stealer: Neue MaaS-Plattform stiehlt Passwoerter und Krypto (BornCity)
- How to get rid of WARDEN Stealer (PCrisk)
Detection coverage for TL-2026-3026
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3026 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.