Known malicious kithighstealer

Warden Stealer: command-and-control servers of the Rust infostealer sold as a service

family: warden-stealer-2026-10

Command-and-control servers of Warden Stealer, a Rust infostealer sold as a subscription service since mid-2026 (earlier tracked as CallbackBeaver). It steals browser passwords and cookies (including a bypass of Chrome's App-Bound Encryption), more than 200 crypto-wallet extensions, messenger, password-manager, 2FA and VPN data, and the local data of AI coding tools (Claude, Codex, Cursor, Grok): tokens, MCP credentials and conversation history. A clipboard clipper swaps copied wallet addresses for the operator's. Customers spread it through ClickFix pages, cracked software, game cheats and malicious ads, usually as a loader that injects the stealer into explorer.exe. A match means a scan of one of these servers, or a page that contacted one. Each server sits behind Cloudflare, and a browser visit gets a Cloudflare 520 error or Cloudflare's own suspected-malware warning page, never content of its own.

Anchors

SMQL queryrun
contacted_host:lemanruss.website OR contacted_host:lemanruss1.website OR contacted_host:lemanruss2.website OR contacted_host:lemanruss3.website OR contacted_host:lemanruss4.website OR contacted_host:kertc4.website OR contacted_host:tony-soprano.club OR contacted_host:recap-check.org OR contacted_host:cap-recheck.org OR contacted_host:verifytrtr.vip OR contacted_host:erifytrtr1.vip OR contacted_host:luqiuid91.com OR contacted_host:errakgrwenmjibedi.cc OR contacted_host:rogaldorn1.website OR contacted_host:web05-cloudupdate.com OR contacted_host:web03-azureupdate.com OR contacted_host:skibidistealer.team OR contacted_host:konradkertc6.website OR contacted_host:kertc3.website OR contacted_host:aksdaodsaodsaodsadoasdasod.best

Provenance

Added: 2026-10-09 16:31
Exact hostnames only. The published list holds about 256 servers, more than one hunt can carry, so this hunt keeps the ones live in October 2026: the newest published servers (rogaldorn1[.]website, web05-cloudupdate[.]com, web03-azureupdate[.]com, skibidistealer[.]team, konradkertc6[.]website, kertc3[.]website, aksdaodsaodsaodsadoasdasod[.]best) and the verification-themed ones that a lure page is the most likely to contact (recap-check[.]org, cap-recheck[.]org, verifytrtr[.]vip, erifytrtr1[.]vip, luqiuid91[.]com, errakgrwenmjibedi[.]cc; public threat lists also tie some of these to ClearFake / ClickFix chains). The operators register servers in numbered batches named after Warhammer 40,000 primarchs and other jokes (redlable, kertc, konradkertc and rogaldorn on .website, each numbered 1 to 6). Seven hosts here are not in the published list and are included as an assessment from that pattern, not from a sample: lemanruss[.]website and lemanruss1 to lemanruss4[.]website (registered 2026-10-09), kertc4[.]website and tony-soprano[.]club (twin of the published tony-sopranos[.]club). Each behaves like the published servers. Before the 2026-10-08 attribution, public threat lists labelled many of these servers 'unknown stealer' or 'ACR Stealer'. Two published servers, macfilecloud8[.]com and websreamyard[.]com, are also listed publicly as macOS Atomic Stealer infrastructure, so at least one customer appears to run both. The builds avoid systems in CIS and Baltic countries.

Sightings (9)

HostScanScriptMatchWhen
rogaldorn1.website8304b9eb…—query2026-10-09 16:33
tony-soprano.club441d4223…—query2026-10-09 16:33
kertc4.website984fd73d…—query2026-10-09 16:33
lemanruss4.website67b7645b…—query2026-10-09 16:33
lemanruss3.websitee4c06caa…—query2026-10-09 16:33
lemanruss2.website1f7544d7…—query2026-10-09 16:33
lemanruss1.website023dac4d…—query2026-10-09 16:33
lemanruss.website34998b77…—query2026-10-09 16:33
errakgrwenmjibedi.ccf47106b6…—query2026-10-09 16:33