Skip to content
Blog Post

Infostealers Are Actively Hunting AI Agents and Developer Keys – Warden Infostealer

InfoStealers
7 min read

Infostealers Are Actively Hunting AI Agents and Developer Keys – Warden Infostealer

Warden Stealer Exploit.in Forum Post
Initial announcement and feature breakdown of Warden Stealer on the Exploit.in dark web forum.

A highly sophisticated piece of malware known as Warden Stealer has been rapidly gaining traction on dark web forums. Billed by its creators as an “all-in-one” stealer, clipper, and loader, Warden is not just another run-of-the-mill infostealer. It represents a terrifying evolution in malware-as-a-service (MaaS), combining devastating crypto-draining features with a highly targeted approach to stealing developer and AI credentials.

What Makes Warden Stealer Different?

The infostealer market is crowded, but Warden distinguishes itself through advanced evasion techniques and a highly resilient infrastructure. Here is what sets it apart from the pack:

  • Proprietary Binary Transfer Protocol: Unlike most stealers that use easily detectable HTTP or JSON requests, Warden uses a custom, heavily encrypted protocol. The traffic is unreadable on the fly by network sensors, allowing it to bypass standard intrusion detection systems.
  • True AST/LLVM Morphing: Warden doesn’t rely on basic obfuscators. It utilizes a custom “morpher” based on AST code parsing and LLVM IR passes. This alters the layout of the binary and injects mathematical garbage instructions, effectively rendering signature-based antivirus tools (like Windows Defender and Avast) useless.
  • Server-Side Decryption: To minimize its footprint on the victim’s machine, the Warden build does zero cryptography or dangerous logic at runtime. All heavy lifting and decryption are handled on the attacker’s servers, making it incredibly lightweight (~350kb) and stealthy.
  • Zero Duplicates & Chunked Delivery: The malware sends data in chunks. If the victim’s connection drops, the partial log is already saved on the attacker’s panel. Furthermore, it ties sessions to hardware IDs, ensuring attackers aren’t bogged down by duplicate logs.

Terrifying Capabilities: Over 360+ Targets

Warden’s grabber is voracious. It targets over 360 applications across 13 categories, including messengers (Discord, Telegram), gaming clients (Steam), password managers, VPNs, and FTP clients. It dynamically collects all Chromium and Gecko browser profiles, grabbing passwords, history, autofill data, and full session cookies – capable of restoring live, authenticated sessions.

Warden Dashboard
The sleek, modern Warden command-and-control (C2) dashboard used by affiliates to manage stolen logs and track hit rates.
Warden Infections in Cavalier
Threat intelligence from Hudson Rock’s Cavalier platform reveals the massive scale of the operation, showing tens of thousands of machines already compromised by Warden.

The AI Developer Threat

Perhaps the most alarming update (v1.9) is Warden’s explicit targeting of AI coding agents and developer environments. As evidenced by leaked payload folders, the malware actively targets directories for Claude Code, Codex CLI, Discord, GitHub, and SSH Keys.

Applications retrieved by Warden
Compromised application directories extracted by Warden, found in Hudson Rock’s Cavalier, showcasing specific targeting of developer tools like Claude Code and Codex CLI.

Furthermore, log extractions (such as a compromised .claude.json file) show the stealer successfully exfiltrating raw primaryApiKey values and detailed OAuth account data tied to Anthropic/Claude accounts. By grabbing these CLI tokens, attackers are bypassing traditional web logins entirely, gaining direct, programmatic access to premium AI models, organizational workspaces, and potentially sensitive source code passing through these tools.

Claude API Keys Stolen
A stolen .claude.json configuration file exposing an active primaryApiKey, granting attackers programmatic access to the victim’s AI limits and workspaces.
SSH Keys Stolen
Exfiltrated SSH config and known_hosts files. This data is critical for attackers looking to pivot and execute lateral movement into corporate infrastructure.
System Information Log
System information file retrieved by the stealer, proudly bearing the “Stealed by Warden” tag alongside victim hardware details.

Crypto Devastation: Auto-Bruteforcing Wallets

While developer keys are lucrative, Warden’s approach to cryptocurrency is purely devastating. It supports over 200 crypto wallet extensions and desktop apps, covering 96 different networks (EVM and non-EVM alike).

However, the real game-changer is its Auto-Bruteforce Engine. When Warden steals an encrypted wallet, it doesn’t just rely on standard password lists. It dynamically builds a custom dictionary from the victim’s own stolen log – using their browser passwords, logins, emails, search queries, and autocomplete data. It then applies over 490 mutation rules, generating up to 20 million password candidates per wallet.

The financial impact is staggering. In a recent update, the developers boasted about the efficiency of their new checker and bruter engine. Over just a few days, the system scanned over 61,700 addresses, successfully cracking 66% of wallets that contained a balance. The developers claim this single run netted attackers a cumulative volume of over $485,000.

Warden Financial Claims
Warden’s developers boasting on the forums about nearly half a million dollars stolen via their dictionary auto-bruteforce engine over just a few days.

Inside the Minds of the Threat Actors: An Interview with Warden

To completely understand what’s going on in a market that has been growing rapidly over the last few years, it is mandatory to know which players are dominating it. A recent brief interview conducted by security researcher g0njxa sheds light on the philosophy and technical choices behind Warden.

Note: The interview was originally conducted in Russian. Both the original text and English translations are provided below.

What is Warden?
Warden – MaaS стиллер нового поколения. Крутой UI/UX вместе с криптом прямо из коробки. Warden – a next-generation MaaS styler. Cool UI/UX along with crypto right out of the box.
Is there a history behind this name Warden?
Один из наших разработчиков исследовал сбор парольных менеджеров, и как-то получилось название. В качестве референса взяли Bitwarden – ничего сверхъестественного. One of our developers researched password manager collections, and somehow a name came out. We used Bitwarden as a reference – nothing extraordinary.
How many people do you think have used Warden? Approximately
Сейчас активно пользуются около 110 человек. Общее число пользователей мы не знаем, но оно явно больше. Currently, about 110 people are actively using it. We don’t know the total number of users, but it’s clearly more.
Since when has the stealer been operating?
Разработка шла с начала 2026 года, а в публичный доступ вышли 21 июля. Проект совсем свежий, но это не мешает нам ломать устои рынка. Нам интересно делать что-то новое. Development began in early 2026, and the project was made available to the public on July 21. The project is quite new, but that doesn’t stop us from breaking the market’s conventions. We’re interested in doing something new.
What makes Warden different from competitors? What do you offer your clients to convince them to choose your product?
Главное, на мой взгляд, – честность. Люди очень недоверчиво относятся к MaaS-стиллерам после всего, что произошло вокруг Lumma… С технической стороны у нас: действительно красивая и проработанная панель… билды, чистые на WD Cloud, максимальная простота но при этом очень обширная функциональность. In my opinion, the most important thing is honesty. People are very distrustful of MaaS stealers after everything that happened around Lumma, and we were initially met with distrust as well. But now the situation is gradually changing for the better. From a technical standpoint, we have: a truly beautiful and well-developed panel… builds that are clean on WD Cloud; maximum simplicity, yet very extensive functionality.
Why did you decide to release a stealer in Rust language?
Выбор Rust объясняется нашим опытом работы с ним. Нам очень нравится его устройство, удобство и в какой-то степени безопасность… Плюс он дает очень хорошие возможности при морфинге кода… Our choice of Rust is due to our experience working with it. We really like its structure, usability, and, to some extent, its safety… Plus, it provides very good opportunities for code morphing, and overall it’s a very pleasant language for a high-load project like ours.
Do you leverage AI for developing? How much of the original codebase was AI-assisted?
Да, мы пользуемся AI. Детали работы с LLM раскрывать не буду. Они помогают в ресерче и иногда очень помогают в разработке. Думаю, что те, кто не использует LLM, сильно отстанут от рынка… Yes, we use AI. I won’t disclose the details of how we work with LLMs. They help with research and sometimes are very helpful in development. I think that those who don’t use LLMs will fall far behind the market and progress in general. In terms of significance, this technology is comparable to the creation of the internet for me.
In forums, you define Warden as a combination of “stealer, clipper, and loader”. Where is the development of Warden focused on?
Пока основной фокус – стиллер. Но готовится обновление, которое сдвинет акцент на более интересные вещи… For now, the main focus is the stealer. But an update is in the works that will shift the focus to more interesting things. Right now, as I’m writing this, the second developer is working on the second version of the clipper. I won’t reveal the rest of the details yet 🙂
You describe a feature of Warden as the “only true morpher on the market”. Can you describe this?
Глядя на билды других стиллеров, я так и не понял, где они нашли там морфер. Чаще всего это обычный LLVM-пасс… Наш морфер работает на трёх уровнях: PE layout, AST, IR, ASM. Это позволяет делать билды, которые довольно сильно отличаются друг от друга… Looking at the builds of other stealers, I still didn’t understand where they found the morpher. Most often, it’s just a regular LLVM pass for obfuscation… We actually spent a lot of time studying the similarities between PE files. Our morpher works at three levels: PE layout, AST, IR, ASM. This allows us to create builds that differ quite significantly from each other.
What would you say to those “information security experts” who are trying to track Warden?
Мы тоже за вами следим!!! We’re watching you too!!!

Conclusion

Warden Stealer is a prime example of the professionalization of cybercrime. With subscription tiers reaching up to $1,500/month for “Enterprise” users, dedicated customer support, and continuous feature updates, it operates like a legitimate SaaS company. Its ability to silently bypass modern AV, coupled with its aggressive targeting of both AI developer tools and cryptocurrency, makes it a critical threat that security teams and developers must actively defend against.

Protect Your Organization

To learn more about how Hudson Rock protects companies from imminent intrusions caused by info-stealer infections of employees, partners, and users, as well as how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us here:

https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:

www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!

Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Continue reading

Related articles

Free Tools Check your exposure