# Warden Stealer: Rust MaaS Infostealer, Clipper and Loader Targeting AI Agents (Claude Code, Codex CLI) and Developer Keys

> Warden Stealer is a Rust-based malware-as-a-service stealer, clipper and loader released publicly on 2026-07-21 that targets 360+ applications across 13 categories, including AI/developer tooling (Claude Code, Codex CLI, GitHub, SSH keys), Chromium/Gecko browser data and 200+ crypto wallet extensions. Hudson Rock's Cavalier platform reports tens of thousands of compromised machines; most capability, revenue and success-rate figures are developer claims, and no samples or IOCs have been published.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3026
- **ID:** TL-2026-3026
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** WardenStealer
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Warden Stealer is a Windows x64 information stealer, cryptocurrency-address clipper and loader sold as a malware-as-a-service (MaaS) subscription on underground forums. Hudson Rock (InfoStealers) reports development began in early 2026 and the product was publicly released on 2026-07-21; the operator handle is "WardenStealer" and the product is advertised on the Exploit.in forum. KrakenLabs (Outpost24) documented the advertisement on 2026-07-24, and secondary coverage (GridinSoft, Cyberpress, BornCity, PCrisk) repeats those claims. Hudson Rock's Cavalier platform has detected tens of thousands of machines compromised by the family, and an anonymous developer interview (published by g0njxa) states roughly 110 customers actively use it.

Capabilities. Chromium and Gecko browser profiles (passwords, history, autofill, cookies, payment cards) plus messengers, gaming clients, password managers, VPNs and FTP clients; counts vary by source (330+ applications per KrakenLabs-derived coverage, 360+ across 13 categories per Hudson Rock). From version 1.9 the stealer adds AI and developer-tool targets: Claude Code, Codex CLI, Discord, GitHub and SSH keys. Per Hudson Rock it exfiltrates the .claude.json file containing the primaryApiKey value and steals OAuth account data tied to Anthropic/Claude accounts. The crypto module targets 200+ wallet extensions and desktop apps across 96 networks and includes a bruteforce engine that builds custom dictionaries from victim data (490+ mutation rules, up to 20M candidates per wallet). The developer claims a 66% crack rate on wallets with balances and $485,000 stolen in a recent run; these figures are unverified. A clipper (v2 in development) swaps copied wallet addresses for attacker-controlled ones, and the loader fetches and executes secondary payloads from operator-supplied URLs.

Evasion and operations (all vendor/developer claims, no sample verification). A "proprietary binary transfer protocol" with custom per-build encryption and chunked log uploads, server-side decryption so the client stays small (~350 KB per Hudson Rock; 500-600 KB per KrakenLabs-derived coverage), hardware-ID tying for zero duplicate logs, "AST/LLVM morphing" at PE-layout, AST, IR and ASM levels, anti-VM/sandbox checks, process injection, a claimed browser App-Bound Encryption bypass, geofencing that excludes CIS and Baltic countries, Cloudflare-backed gates with automatic failover, and a web panel with real-time dashboards and Telegram notifications. Pricing is reported as a $349/month personal tier up to $1,500/month for Enterprise, with a free 3-day trial.

Intelligence limits. No hashes, domains, IPs, delivery chain or confirmed victim campaign have been published; GridinSoft explicitly notes the capabilities are seller claims and the name alone does not prove execution or theft. Defenders should treat AI-agent credential files and developer keys on Windows endpoints as stealer targets and focus on behavioral detection and credential hygiene.

## MITRE ATT&CK

- T1555.003 Credentials from Web Browsers
- T1555.005 Password Managers
- T1539 Steal Web Session Cookie
- T1552.001 Credentials In Files
- T1552.004 Private Keys
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1497 Virtualization/Sandbox Evasion
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1614 System Location Discovery
- T1573 Encrypted Channel
- T1030 Data Transfer Size Limits
- T1657 Financial Theft

## Sources

- [Infostealers Are Actively Hunting AI Agents and Developer Keys - Warden Infostealer (Hudson Rock)](https://www.infostealers.com/article/infostealers-are-actively-hunting-ai-agents-and-developer-keys-warden-infostealer/)
- [Approaching Stealer Devs: A Brief Interview with Warden (g0njxa) - cited by Hudson Rock, not retrievable](https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-warden-a978d5ae1147)
- [WARDEN Stealer: Claims, Cookie Theft Risk, and Removal (GridinSoft)](https://blog.gridinsoft.com/warden-stealer-malware/)
- [New WARDEN Stealer Targets 330+ Apps and 200 Crypto Extensions on Windows (Cyberpress)](https://cyberpress.org/new-warden-stealer-targets-330-apps/)
- [WARDEN Stealer: Neue MaaS-Plattform stiehlt Passwoerter und Krypto (BornCity)](https://borncity.com/news/warden-stealer-neue-maas-plattform-stiehlt-passwoerter-und-krypto/)
- [How to get rid of WARDEN Stealer (PCrisk)](https://www.pcrisk.com/removal-guides/35689-warden-stealer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3026
