New WARDEN Stealer Targets 330+ Apps and 200 Crypto Extensions on Windows

New malware-as-a-service (MaaS) offering “WARDEN” has emerged on cybercrime forums, pitching a Windows infostealer that blends credential theft, cryptocurrency hijacking, and payload delivery behind a single, feature-rich control panel.

Marketed by the operator using the handle “WardenStealer,” the platform appears aimed at traffickers and other financially motivated actors who want turnkey data-theft and monetization workflows with minimal operational overhead.

According to the KrakenLabs Team, WARDEN is a 64‑bit stealer, clipper, and loader for Windows that combines data theft with campaign automation rather than focusing on a single monetization route.

New WARDEN Stealer Targets Windows

The seller claims each 500–600 KB build communicates via a custom encrypted binary protocol instead of HTTP or JSON, with per-build encryption keys and chunked log uploads designed to reduce detection by network sensors.

Configurations such as which data types to collect or which URLs to use for second-stage payloads can reportedly be adjusted remotely without rebuilding the binary, and “private” and “shared” Cloudflare-backed gates provide automatic failover if a primary endpoint is blocked.

From a data-theft perspective, WARDEN positions itself as a broad-coverage infostealer targeting both Chromium and Gecko-based browsers to harvest passwords, session cookies, autofill data, and full browser histories.

WARDEN Stealer (Source: KrakenLabs_Team)
WARDEN Stealer (Source: KrakenLabs_Team)

Beyond credentials, the stealer is advertised as capturing payment-card and billing records, as well as data from more than 330 desktop applications, including messaging clients, VPN tools and potentially productivity or gaming platforms.

The clipper component is tuned for cryptocurrency theft: it monitors the clipboard for Bitcoin, Ethereum and other wallet formats and replaces them with attacker-controlled addresses, while also targeting over 200 cryptocurrency browser extensions to extract wallet information directly.

The platform also markets more advanced tradecraft capabilities that align with recent trends in stealer and loader ecosystems.

Claimed features include the ability to bypass browser App-Bound Encryption in order to access otherwise protected credential stores, inject code into system processes to improve stealth and persistence, and detect virtual machines and sandboxes used by analysts to reduce the chance of early detection.

As a loader, WARDEN can purportedly fetch and execute additional malware via attacker-supplied URLs, allowing operators to chain in ransomware, remote access trojans or additional stealers as needed.

Screenshots shared by the seller show a polished web-based control panel with dashboards for real-time log processing, per-country and per-campaign statistics, and time-series charts tracking volumes of wallets, cards, passwords and cookies harvested over time.

An operator can filter and bulk-download logs, receive Telegram notifications for high-value captures, and generate password-protected traffic reports, all with multilingual interface support.

The malware is advertised as compatible with Windows 7 through Windows 11, while incorporating a hard-coded geofencing policy that excludes victims in CIS and Baltic countries, a pattern seen repeatedly across Eastern European crimeware ecosystems.

Pricing is positioned to lower the barrier to entry: the actor offers a free three-day trial plus an additional four days in exchange for a public review, and lists a “personal” subscription at 349 USD per month.

For traffickers who already control large volumes of compromised traffic, WARDEN’s blend of credential theft, cryptocurrency-focused clipping and loader functionality combined with resilient Cloudflare-hosted gates and campaign-management tooling could provide a one-stop shop for monetizing infections at scale.

However, at this stage all technical details, performance claims and bypass guarantees originate solely from the threat actor’s own marketing and have not been independently verified by third-party researchers or incident-response teams.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories