INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Infostealer to Steal AI Agent Data

| 2026-10-09 07:40 LOW MEDIUM DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
Warden Stealer, a Rust-based infostealer-as-a-service, has rapidly become one of the most prevalent threats since August 2026. The malware targets over 200 cryptocurrency wallet extensions and 360+ applications across 13 categories, notably collecting AI assistant and agentic coding tool data from Claude, Codex, Grok, and Cursor. Operating through tiered subscriptions ranging from $149 for three days to $1,500 monthly, Warden Stealer employs sophisticated obfuscation techniques, morphing capabilities, and bypasses Application-Bound Encryption to steal browser data. The malware avoids CIS and Baltic countries and is distributed through cracked software, game cheats, malvertising, and ClickFix campaigns, affecting an unknown number of users worldwide.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

420a72••••••••••••••••••••••••••••••••••
419df8••••••••••••••••••••••••••••••••••
8e1bef••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
3d0794••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
0d727a••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
51bc79••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
241df5••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ka•••••.rest
ma•••••.club
zo•••••.club
ka•••••.club
1505f8••••••••••••••••••••••••••
6e680b••••••••••••••••••••••••••
a24a5f••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
CIS CIS cryptocurrencycryptocurrency
Incident Timeline
‎August 2026
Warden Stealer, a Rust-based infostealer-as-a-service distributed via malware-as-a-service model since August 2026, targets various applications and cryptocurrency wallet extensions.
infrastructure Cursor
organisation Claude
organisation ClickFix
organisation Application-Bound Encryption
‎2026/10/09
Threat actors used the Warden Stealer infostealer to target AI agent data on October 9, 2026.
organisation The Rapid Rise
Tactical Metrics
Metrics
infrastructure
‎Cursor
Affected Product
Intelligence Sources