Warden Stealer Spreads Through ClickFix, Malvertising, Cracked Software and Game Cheats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A fast-growing Windows information stealer called Warden Stealer is being spread through ClickFix lures, malicious advertisements, cracked software downloads, and fake game cheats.

The malware is sold as a malware-as-a-service offering, allowing different criminal operators to create their own builds, choose targets, and use separate command-and-control servers.

Its main goal is to steal browser data, passwords, cookies, cryptocurrency wallet details, application data, and other sensitive files from infected systems.

The threat stands out because it does not operate as a basic credential stealer. Warden Stealer includes its own loader for placing the payload into memory and a cryptocurrency clipper that can replace copied wallet addresses with criminal-controlled addresses.

It has rapidly become one of the more common stealers seen by Gen’s user base, alongside families such as Vidar, Amatera, and Remus.

Analysts and researchers from Gen Digital identified the malware as Warden Stealer after linking a previously tracked family called CallbackBeaver to underground advertisements, technical features, loader behavior, and clipper configuration used by the Warden operation.

Gen Threat Labs said the first observed builds appeared in early May 2026, while the developers publicly promoted the service from August 2026.

Warden Stealer

Warden Stealer operators can choose their own delivery method, which has helped the malware spread through several common social-engineering routes.

One route is ClickFix, where a victim is shown a fake CAPTCHA, Cloudflare check, or browser verification page and is told to copy and run a command.

That command can silently fetch the loader and begin the infection chain. The method depends on user action, making it harder for basic download-focused security checks to spot before execution.

Readers can compare this technique with Cyber Security News reporting on the fake CAPTCHA delivery method, where victims were persuaded to run clipboard-delivered PowerShell commands.

Warden Stealer advertised on an underground forum (Source - Gen Digital)
Warden Stealer advertised on an underground forum (Source – Gen Digital)

Malvertising creates another route. Criminals can use paid or poisoned search results to send users to pages posing as software portals, browser updates, productivity tools, cheats, or free utilities.

Cracked programs and pirated installers remain especially useful because users may expect warnings, password-protected archives, or instructions to disable security software.

Fake gaming tools use the same trust gap: a cheat package may appear to be a mod, unlocker, or performance tool but instead launches a loader.

This pattern closely follows recent fake game cheat campaigns that used GitHub and Reddit content to push Vidar onto gaming systems.

Rust Code, Loader, and Evasion Features

Written in Rust, Warden Stealer is built to make reverse engineering and static detection more difficult. Its samples are regularly changed, heavily obfuscated, and morphed between builds.

The loader generally reconstructs the stealer in memory and injects it into a running process, often the Windows shell process associated with the taskbar. Earlier samples also targeted processes such as msiexec.exe and dllhost.exe.

The loader stores the payload in encoded data, decodes it with a build-specific Base64-like alphabet, and decompresses it before injection.

It then uses Windows APIs including VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread to run the payload inside another process.

Some samples are padded with very large PE overlays, a tactic that can cause slow scanning, sandbox timeouts, or file-upload problems in analysis systems.

Warden Stealer also checks for virtual machines before collecting data. It looks for firmware, CPU-vendor, registry, and display-device signs linked to VMware, VirtualBox, KVM, Xen, QEMU, and other analysis environments.

Warden Stealer’s web panel overview (Source – Gen Digital)

If it believes the system is virtualized, it stops its reporting worker. This behavior can reduce the visibility researchers and automated sandbox tools receive from live samples.

The stealer focuses heavily on Chromium- and Gecko-based browsers, wallet extensions, password managers, VPN clients, messengers, two-factor authentication tools, and locally stored files.

A major concern is its effort to bypass Chromium Application-Bound Encryption, or ABE, which is intended to protect browser passwords and cookies.

Warden searches browser memory for an encrypted v20_master_key, injects a small code stub into the browser process, and uses CryptUnprotectMemory in that process to recover the key needed to read protected browser data.

Warden Stealer also targets files linked to locally installed AI assistants and coding agents, including Claude, Codex, Grok, and Cursor.

These folders may contain access and refresh tokens, MCP configuration files, saved credentials, prompt histories, chat databases, and project context.

This is not a flaw in the AI tools themselves; it is endpoint theft after a Windows device is infected. Earlier coverage of AI agent token theft explains why these files can expose connected cloud services, source code, internal hosts, and reusable API secrets.

The malware can also fetch and execute extra payloads from links supplied by its command server. It uses certutil.exe to download files into the temporary directory, then can start EXE, MSI, BAT, or CMD payloads.

This gives operators a path to add other malware after the original infection. Its combination of browser theft, token collection, process injection, and extra-payload support makes it more than a single-purpose stealer.

Similar risks are visible in Remus browser theft techniques, which also use ClickFix lures and seek browser, wallet, and AI-related data.

Organizations should block the listed domains, hunt for the supplied hashes, and review systems where users recently ran commands from a CAPTCHA or verification page.

Security teams should investigate unusual certutil.exe downloads, unexpected browser-process injection, CreateRemoteThread behavior, and suspicious execution from temporary folders.

Browser credentials, cookies, active sessions, wallet data, API keys, and AI-agent tokens should be treated as exposed after a confirmed infection.

Affected users should isolate the device, reset passwords from a clean machine, revoke active browser and AI-service sessions, rotate API keys and connected-service credentials, and review account activity.

Downloading software only from official vendor sites, avoiding cracks and cheats, and refusing any website instruction to paste commands into Windows remain the simplest ways to reduce exposure.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 006510ce1da2b7410376f0788c19e55616eb4bcc30072d25b7d0871dc32aa11c
0d727a4ef1178e767afdd0080ba1ebda0f24ac52b639f0501021affd8f88d26a
63959ef6309cd01b5d3c7262a3a41394dca2db2dc74bd030a517b7e23a2c3fef
77c8266935bc040c992ab70abd402bd203b9c12e7548c80b84fd21308c250f0e
77cc246272f2af21b64bbc6c6173d57affee97eb0ccf747d89492d06d4c52865
abcc49cd8a9b08a18ad9e516ec13350e01a05f04f1c5e025080e1c0e3b4bec36
b855f6883391e25f1a91692bef76771065b4b0436a014de5b25aa9d0de6238e4
dd1c3b2bfe32b41902ffe875e568f52f44f0900209b9cb447c9ae4444a5dce4e
ea9debbe4b3d11bf6c986af63a94e13ceb2a1cbc167a642697fcabc9e8a50439
ff85bb43e546fac541443006878828c47958c1d55dfa32c529651bfcc12832f1
Warden Loader samples
SHA-256 04beeb716a79661ea770138558dbdebccb493bf6b4b1ec37f19b9c028dea98d5
159b472e0e0bdc05933da64032761cbd042b6cc5dc4e1cd11d5ef7af5180b972
3d0794fca8ae2ca80eee463b11557d696c48c8ddf17f5e2917cc33fbf0596842
51bc797e783b6a765e174736ff12a711a243099f4e19739388e5bce1548a448d
5b6ec081f385d91273a79c6645cd0f932539dc267863e5d243657a8ccb5ca351
6e47d6da0e2ab2226ee033e75c7b9b41e4e908d6f71b47d0ce7477a492fb418e
a396ccfb5547f04cef4be18ed076bb2c62c571268306d201b6177188f05723f1
cc1f2ae885d317e6c520ea6d219370630c1c7a8fe600b89d0d78fdee28174ff4
e62b24142e7244573cf37cef55b175fbba6a43ac4592d30f8b061dda8866c9b3
fea9538084b70e9681fd8104b9319792c4d8c2701ae145ec31dc26e7526f2ae0
Warden Stealer samples
SHA-256 241df5a4ee38658329025152807fcd69b7e40361428000bb56d14cadeb48b437 Early Warden Stealer build tracked by Gen Digital from May 2026
C2 domains backtoblack7[.]com
berff3788[.]com
bobroviysmex[.]shop
bomboclat[.]rest
brodyagup[.]com
culture-shock[.]club
diseazhjw[.]cloud
dojaekrt[.]cc
dojaekrt[.]forum
dojaekrt[.]trade
erifytrtr1[.]vip
ggresp[.]com
hotelcalifornia[.]club
hroffice[.]work
incoming[.]rent
jgkawdq[.]cloud
kaiangelsystems[.]rest
kaifdlyaw[.]com
kaliop-weda[.]club
konradkerz40000[.]work
library2000[.]com
luqiuid91[.]com
macfilecloud8[.]com
matie-bal[.]club
modicontools[.]com
Extracted Warden Stealer command-and-control domains
C2 domains nextlanding[.]net
nweenwew234[.]cc
patduggan[.]com
pianolovers[.]club
piska-sosidka-govno[.]asia
plainhorizon[.]org
publisher99[.]com
rabbids-sixseven[.]cc
recap-check[.]org
rocks56[.]com
rrrrrrrfffff[.]club
russianaltushkawantdickinside[.]club
sfgiantslive[.]com
skibidiclipper[.]pw
skibidiproliv[.]com
skibidistealer[.]team
systemformating[.]rest
verifytrtr[.]vip
vlad-nazarenko2004[.]club
web03-azureupdate[.]com
webex-028ue2[.]com
wosback[.]cc
zalupka[.]website
zolotoy[.]club
zxcwork[.]com
Extracted Warden Stealer command-and-control domains

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Warden Stealer Spreads Through ClickFix, Malvertising, Cracked Software and Game Cheats appeared first on Cyber Security News.