# Warden Stealer (CallbackBeaver) Rust Infostealer Targets Claude, Codex, Grok and Cursor AI Agent Data

> Warden Stealer (previously tracked by Gen as CallbackBeaver) is a Rust-based malware-as-a-service infostealer with a dedicated loader and crypto clipper that harvests AI-agent tokens, API keys, MCP settings, prompt histories and conversation databases alongside browser, wallet, password-manager, messenger, 2FA and VPN data. It is distributed through cracked software, game cheats, malvertising and ClickFix, and version 1.9 (announced 2026-09-29) added officially advertised AI coding agent token theft.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T13:10:53.195Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3113
- **ID:** TL-2026-3113
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Warden
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Warden Stealer is a Rust-based infostealer sold as a service (MaaS) on Russian-language underground forums (Exploit.in is named by Hudson Rock). Early builds were observed in May 2026, a public release was announced on 2026-07-21, and advertising intensified from August 2026. Gen Digital initially tracked the family as CallbackBeaver and attributed it to Warden based on Rust development, distinctive code morphing, a dedicated loader and matching cryptocurrency clipper configurations. Gen reported 5,000+ CallbackBeaver samples in a single 30-day period and describes Warden as one of the most prevalent stealers in its user base alongside Vidar, Amatera and Remus. The developer claims roughly 110 active customers, and the operation deliberately avoids CIS and Baltic countries.

The loader supports three execution modes: injection (EXE to DLL injected into a legitimate process), sideload (a DLL placed alongside a legitimately signed EXE) and standalone EXE. The encoded payload sits in the .rdata section using a per-build Base64-like alphabet with custom LZSS-style decompression. The loader reconstructs the stealer in memory, allocates RWX memory with VirtualAllocEx in the process that owns the Shell_TrayWnd window (explorer.exe), manually registers the module in the PEB module lists, and runs a bootstrap stub that invokes TLS callbacks and the PE entry point. Obfuscation includes dynamic LoadLibraryA/GetProcAddress resolution, indirect jumps and calls with runtime-computed addresses, opaque predicates, decoy strings, junk computations, AST/LLVM-IR code morphing and inflated PE overlays to defeat file-size scan limits.

Anti-VM checks use GetSystemFirmwareTable (requiring SMBIOS Type 7 cache records), CPUID leaves 0, 0x40000000 and 0x40000100 against 27 hypervisor vendor signatures, enumeration of the four Uninstall registry hives for VirtIO software, and EnumDisplayDevicesW checks for adapters such as Virtio, Standard VGA and Basic Display. When a VM is detected the sample aborts, showing a Russian-language dialog.

For Chromium Application-Bound Encryption (ABE) the stealer scans browser process memory for the v20 key tag and a 32-byte encrypted KeyRing entry, suspends a browser thread, redirects its instruction pointer to injected shellcode, and has that shellcode call CryptUnprotectMemory (CRYPTPROTECTMEMORY_SAME_PROCESS), then polls the buffer for changed bytes to recover the v20 master key. The same technique class is seen in Vidar and Remus. Gecko browsers, 200+ cryptocurrency wallet extensions (96 networks) and 360+ applications across 13 categories (messengers, password managers, 2FA tools, VPN clients, FTP clients, Discord, Telegram, Steam) are also targeted. For AI tooling, it collects access and refresh tokens, credentials in MCP configurations, prompt histories, conversation databases and project traces for Claude, Codex, Grok and Cursor; Hudson Rock observed collection of Claude Code and Codex CLI directories, GitHub credentials, SSH keys and .claude.json files holding primaryApiKey values and OAuth tokens. Custom file and registry grabbing rules are delivered by the server in a dynamic configuration.

C2 uses HTTPS with a custom binary protocol: a serialized record is XOR-obfuscated with a build-specific byte, prefixed with a frame tag, LZNT1-compressed and given a header with the uncompressed length plus a 16-byte build marker. Domains are stored with one-byte XOR keys, and the client iterates through 1-5 C2 domains on failure. Registration sends a fingerprint (hardware ID, CPU/memory, OS version, display configuration, username, locales, installed software) and receives an XOR-obfuscated dynamic configuration. Secondary payloads are fetched with certutil.exe -urlcache -split -f via the Shell.Application COM object into %TEMP%\[8-hex GetTickCount][position].ext and executed (msiexec /i /qn /norestart for MSI, cmd.exe /c for BAT/CMD, direct execution for EXE). The built-in clipper swaps wallet addresses across BTC, ETH, TRX, XMR, SOL and TON, extended in v1.7 with LTC, XRP, ADA and BCH. Hudson Rock also reports an auto-bruteforce engine for wallets (up to 20 million password candidates, 490+ mutation rules) and a claimed $485,000 theft. Windows 7 support was dropped in v1.9. Pricing was raised in v1.9 (Test $149/3 days, Personal $450/month, Premium $800/month, new Enterprise $1,500/month).

The operator-dependent distribution vectors are cracked software, game cheats, malvertising and ClickFix. Note: the GBHackers article lists 5 loader hashes; Gen's report lists additional loader and payload hashes and 56 C2 domains, and the Gen-linked GitHub IOC repository holds 1,050 sample hashes and 400+ C2 domains. This record includes a representative subset.

## MITRE ATT&CK

- T1204.002 User Execution: Malicious File
- T1204.004 User Execution: Malicious Copy and Paste
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1574.001 DLL
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1218.007 System Binary Proxy Execution: Msiexec
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1555.005 Credentials from Password Stores: Password Managers
- T1539 Steal Web Session Cookie
- T1552.001 Unsecured Credentials: Credentials In Files
- T1082 System Information Discovery
- T1012 Query Registry
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1008 Fallback Channels
- T1565.002 Transmitted Data Manipulation
- T1583.008 Acquire Infrastructure: Malvertising
- T1055.003 Process Injection: Thread Execution Hijacking
- T1115 Clipboard Data
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Warden Stealer Malware Targets Claude, Codex, Grok and Cursor to Steal AI Agent Data](https://gbhackers.com/warden-stealer-malware/)
- [Gen Digital: Warden Stealer Rust Infostealer Analysis](https://www.gendigital.com/blog/insights/research/warden-stealer-rust-infostealer-analysis)
- [Gen Digital: Infostealers and Your AI Agent](https://www.gendigital.com/blog/insights/research/infostealers-your-ai-agent)
- [Hudson Rock / InfoStealers: Infostealers Are Actively Hunting AI Agents and Developer Keys - Warden Infostealer](https://www.infostealers.com/article/infostealers-are-actively-hunting-ai-agents-and-developer-keys-warden-infostealer/)
- [Cyberpress: Warden Stealer Targets 200+ Crypto Wallet Extensions and 360+ Applications](https://cyberpress.org/warden-targets-crypto-wallets/)
- [Warden Stealer IOC repository (hashes, configuration sample)](https://github.com/vojtechkrejsa/ioc/tree/master/WardenStealer)
- [Mallory: Infostealers Target AI Coding Agents for Tokens, Secrets and Prompt Histories](https://mallory.ai/stories/01a08202-df0d-7aad-a286-2b1b5028d06c)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3113
