Threat reportMalwareTL-2026-3113
Warden Stealer (CallbackBeaver) Rust Infostealer Targets Claude, Codex, Grok and Cursor AI Agent Data
Warden Stealer (CallbackBeaver) Rust Infostealer Targets (TL-2026-3113), also tracked as CallbackBeaver, is a high-severity malware campaign, first published 2026-10-09. It is attributed to Warden with medium confidence, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1005, T1008, T1012), and is covered by 9 detection rules and 40 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1Warden
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-3113
- Threat ID
- TL-2026-3113
- Also known as
- CallbackBeaver, Warden Loader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Warden
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, consumer, gaming
- Target regions
- Global (excluding CIS and Baltic countries)
- Detection rules
- 9
- Indicators of compromise
- 40
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in Warden Stealer (CallbackBeaver) Rust Infostealer Targets
Malware and tooling: CallbackBeaver, GROK, Warden Stealer
How Warden Stealer (CallbackBeaver) Rust Infostealer Targets works
Warden Stealer (previously tracked by Gen as CallbackBeaver) is a Rust-based malware-as-a-service infostealer with a dedicated loader and crypto clipper that harvests AI-agent tokens, API keys, MCP settings, prompt histories and conversation databases alongside browser, wallet, password-manager, messenger, 2FA and VPN data. It is distributed through cracked software, game cheats, malvertising and ClickFix, and version 1.9 (announced 2026-09-29) added officially advertised AI coding agent token theft.
Warden Stealer is a Rust-based infostealer sold as a service (MaaS) on Russian-language underground forums (Exploit.in is named by Hudson Rock). Early builds were observed in May 2026, a public release was announced on 2026-07-21, and advertising intensified from August 2026. Gen Digital initially tracked the family as CallbackBeaver and attributed it to Warden based on Rust development, distinctive code morphing, a dedicated loader and matching cryptocurrency clipper configurations. Gen reported 5,000+ CallbackBeaver samples in a single 30-day period and describes Warden as one of the most prevalent stealers in its user base alongside Vidar, Amatera and Remus. The developer claims roughly 110 active customers, and the operation deliberately avoids CIS and Baltic countries.
The loader supports three execution modes: injection (EXE to DLL injected into a legitimate process), sideload (a DLL placed alongside a legitimately signed EXE) and standalone EXE. The encoded payload sits in the .rdata section using a per-build Base64-like alphabet with custom LZSS-style decompression. The loader reconstructs the stealer in memory, allocates RWX memory with VirtualAllocEx in the process that owns the Shell_TrayWnd window (explorer.exe), manually registers the module in the PEB module lists, and runs a bootstrap stub that invokes TLS callbacks and the PE entry point. Obfuscation includes dynamic LoadLibraryA/GetProcAddress resolution, indirect jumps and calls with runtime-computed addresses, opaque predicates, decoy strings, junk computations, AST/LLVM-IR code morphing and inflated PE overlays to defeat file-size scan limits.
Anti-VM checks use GetSystemFirmwareTable (requiring SMBIOS Type 7 cache records), CPUID leaves 0, 0x40000000 and 0x40000100 against 27 hypervisor vendor signatures, enumeration of the four Uninstall registry hives for VirtIO software, and EnumDisplayDevicesW checks for adapters such as Virtio, Standard VGA and Basic Display. When a VM is detected the sample aborts, showing a Russian-language dialog.
For Chromium Application-Bound Encryption (ABE) the stealer scans browser process memory for the v20 key tag and a 32-byte encrypted KeyRing entry, suspends a browser thread, redirects its instruction pointer to injected shellcode, and has that shellcode call CryptUnprotectMemory (CRYPTPROTECTMEMORY_SAME_PROCESS), then polls the buffer for changed bytes to recover the v20 master key. The same technique class is seen in Vidar and Remus. Gecko browsers, 200+ cryptocurrency wallet extensions (96 networks) and 360+ applications across 13 categories (messengers, password managers, 2FA tools, VPN clients, FTP clients, Discord, Telegram, Steam) are also targeted. For AI tooling, it collects access and refresh tokens, credentials in MCP configurations, prompt histories, conversation databases and project traces for Claude, Codex, Grok and Cursor; Hudson Rock observed collection of Claude Code and Codex CLI directories, GitHub credentials, SSH keys and .claude.json files holding primaryApiKey values and OAuth tokens. Custom file and registry grabbing rules are delivered by the server in a dynamic configuration.
C2 uses HTTPS with a custom binary protocol: a serialized record is XOR-obfuscated with a build-specific byte, prefixed with a frame tag, LZNT1-compressed and given a header with the uncompressed length plus a 16-byte build marker. Domains are stored with one-byte XOR keys, and the client iterates through 1-5 C2 domains on failure. Registration sends a fingerprint (hardware ID, CPU/memory, OS version, display configuration, username, locales, installed software) and receives an XOR-obfuscated dynamic configuration. Secondary payloads are fetched with certutil.exe -urlcache -split -f via the Shell.Application COM object into %TEMP%\[8-hex GetTickCount][position].ext and executed (msiexec /i /qn /norestart for MSI, cmd.exe /c for BAT/CMD, direct execution for EXE). The built-in clipper swaps wallet addresses across BTC, ETH, TRX, XMR, SOL and TON, extended in v1.7 with LTC, XRP, ADA and BCH. Hudson Rock also reports an auto-bruteforce engine for wallets (up to 20 million password candidates, 490+ mutation rules) and a claimed $485,000 theft. Windows 7 support was dropped in v1.9. Pricing was raised in v1.9 (Test $149/3 days, Personal $450/month, Premium $800/month, new Enterprise $1,500/month).
The operator-dependent distribution vectors are cracked software, game cheats, malvertising and ClickFix. Note: the GBHackers article lists 5 loader hashes; Gen's report lists additional loader and payload hashes and 56 C2 domains, and the Gen-linked GitHub IOC repository holds 1,050 sample hashes and 400+ C2 domains. This record includes a representative subset.
MITRE ATT&CK techniques used in TL-2026-3113
Collection
T1005 Data from Local System; T1115 Clipboard Data
Command and Control
T1008 Fallback Channels; T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Discovery
T1012 Query Registry; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1055.003 Process Injection: Thread Execution Hijacking; T1140 Deobfuscate/Decode Files or Information; T1218.007 System Binary Proxy Execution: Msiexec; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File; T1204.004 User Execution: Malicious Copy and Paste
Credential Access
T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.005 Credentials from Password Stores: Password Managers
Impact
T1565.002 Transmitted Data Manipulation
stealth
Resource Development
Affected products and versions in Warden Stealer (CallbackBeaver) Rust Infostealer Targets
- Microsoft — Windows
Vulnerable versions: Windows 8; Windows 10; Windows 11 - Anthropic — Claude / Claude Code (local config and token storage)
Vulnerable versions: Local data targeted by the stealer; not a product vulnerability - OpenAI — Codex CLI (local config and token storage)
Vulnerable versions: Local data targeted by the stealer; not a product vulnerability - xAI — Grok (local data)
Vulnerable versions: Local data targeted by the stealer; not a product vulnerability - Anysphere — Cursor (local config and token storage)
Vulnerable versions: Local data targeted by the stealer; not a product vulnerability
Remediation for Warden Stealer (CallbackBeaver) Rust Infostealer Targets
Immediate actions
- Block the listed Warden C2 domains and hunt for the listed SHA-256 hashes in EDR/DNS/proxy telemetry
- On suspected infection, revoke AI agent sessions, rotate AI/API keys, GitHub tokens and SSH keys, and review account activity
- Alert on certutil.exe -urlcache -split -f launched via Shell.Application and on msiexec /i /qn /norestart from user-writable paths
- Alert on unsigned DLLs loaded or written next to legitimately signed EXEs in user-writable locations (sideload mode)
Workarounds
- Inventory installed AI agents and review where each stores credentials
- Rotate and scope developer credentials stored on endpoints used for browsing untrusted content
Longer-term hardening
- Store AI agent tokens in the OS credential store, keychain or keyring instead of plaintext files such as .claude.json
- Limit MCP integration permissions to the minimum required and avoid pasting secrets into prompts
- Block cracked software, game cheats and ClickFix paste-and-run workflows via application control and user awareness training
- Monitor for suspension and thread-context changes of Chromium processes and CryptUnprotectMemory use by foreign shellcode
Timeline of Warden Stealer (CallbackBeaver) Rust Infostealer Targets
- Earliest tracked Warden/CallbackBeaver builds observed by Gen Digital (month-level date: May 2026); development began in early 2026.
- Warden Stealer public release announced by its developer as a MaaS offering with stealer, clipper and loader.
- KrakenLabs documents the WardenStealer seller advertisement claiming stealer, clipper and loader functionality (seller claims of 330+ applications and 200+ wallet extensions).
- Warden advertised on Russian-language underground forums (month-level date: August 2026); prevalence rises significantly in Gen telemetry.
- Clipper expanded in v1.7 from BTC, ETH, TRX, XMR, SOL, TON to also cover LTC, XRP, ADA and BCH (approximate month; exact date not stated in sources).
- Version 1.9 announced with official AI coding agent token-stealing support, Windows 7 support removed, new $1,500/month Enterprise tier and price increases.
- Hudson Rock (InfoStealers.com) publishes analysis noting Claude Code, Codex CLI and .claude.json targeting, the wallet bruteforce engine and tens of thousands of compromised machines.
- Gen Digital Threat Labs publishes its technical analysis linking Warden Stealer to CallbackBeaver.
- Gen Digital technical analysis attributing CallbackBeaver to Warden is publicly reported by GBHackers and others, listing loader/payload hashes and 56 C2 domains.
Update history for TL-2026-3113
- 2026-10-09 — Warden Stealer: Rust MaaS Infostealer Spread via ClickFix, Malvertising, Cracked Software and Game Cheats: What changed No severity, exploitability, status or attribution change; the existing HIGH / ACTIVE / MEDIUM values are unchanged. This is an additive enrichment. New indicators (13) 3 new SHA-256 hashes (one early May 2026 build, one loader
Sources cited for Warden Stealer (CallbackBeaver) Rust Infostealer Targets
- Warden Stealer Malware Targets Claude, Codex, Grok and Cursor to Steal AI Agent Data
- Gen Digital: Warden Stealer Rust Infostealer Analysis
- Gen Digital: Infostealers and Your AI Agent
- Hudson Rock / InfoStealers: Infostealers Are Actively Hunting AI Agents and Developer Keys - Warden Infostealer
- Cyberpress: Warden Stealer Targets 200+ Crypto Wallet Extensions and 360+ Applications
- Warden Stealer IOC repository (hashes, configuration sample)
- Mallory: Infostealers Target AI Coding Agents for Tokens, Secrets and Prompt Histories
Detection coverage for TL-2026-3113
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3113 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.