← Back

Warlock Stealer Emerges as an Information-Stealing Platform with Cross-Platform Ambitions

Leer en Español
Print Share

Executive Summary

A new threat marketed under the name Warlock Stealer, through a service identified as Warlock Portal, has begun promoting itself as an integrated platform for stealing, classifying, and exploiting information obtained from Windows and Linux systems.

Its operators advertise a Malware-as-a-Service model with 25 collection modules, support for PE and ELF executables, configurable payload generation, centralized log management, integrated OSINT capabilities, and HVNC functionality for remote interaction with compromised systems.

The service claims to collect browser credentials, cryptocurrency wallets, Telegram sessions, Discord tokens, VPN configurations, password-manager data, SSH keys, AWS and Azure credentials, RDP connections, Wi-Fi passwords, documents, developer-tool data, and credentials associated with artificial intelligence services.

More Than a List of Credentials

Warlock Portal’s offering partly follows the familiar commercial infostealer model: compromise an endpoint, collect valuable information, and centralize the results for subsequent exploitation.

However, the service attempts to differentiate itself through a broader combination of capabilities. Its operators advertise a single builder capable of producing PE and ELF payloads, selecting individual collectors, and linking each build to a specific key without — according to the promotional material — requiring additional compilation or agent installation.

The declared collection scope also extends beyond browser cookies and passwords. Warlock claims to target cloud credentials, SSH keys, remote sessions, developer tools, password managers, browser extensions, and VPN configurations.

The currently available evidence does not yet demonstrate that these capabilities are technically functional as advertised.

The Panel Is Part of the Offensive Proposition

Another relevant component sits outside the malware itself.

Warlock Portal promotes a database where collected logs can allegedly be filtered by country, operating system, and quantities of cookies, passwords, cards, or wallets, while also supporting searches and pivots across the harvested information.

The service further advertises an integrated OSINT workspace for GitHub research and target correlation before deployment.

The commercial proposition therefore appears aimed at transforming a conventional stealer into an intelligence-management platform built around compromised data, where collection, search, classification, and subsequent exploitation coexist within the same interface.

The claimed inclusion of HVNC adds another layer. According to the operators, this capability would enable remote interaction with an endpoint when passive information extraction is insufficient.

Low Price, Reduced Barrier to Entry

Warlock Portal also advertises a particularly accessible pricing structure: subscriptions starting at $25.99 per month, quarterly and annual plans, and a $200 lifetime license, with payment accepted through several cryptocurrencies.

Stealer-as-a-Service offerings reduce the need for individual operators to develop malware, infrastructure, and management panels on their own. If Warlock delivers even a substantial portion of the functionality it promotes, its pricing could lower the barrier to accessing a broad set of collection capabilities for actors with limited technical resources.

A Name That Requires Caution

The name Warlock already appears in public research associated with a separate ransomware operation. Microsoft has documented deployments of Warlock ransomware linked to Storm-2603 activity, including exploitation of Microsoft SharePoint.

At present, there is no evidence linking Warlock Stealer or Warlock Portal to that ransomware ecosystem.

Analytical Closing

Warlock Stealer is still at a stage where the commercial promise significantly exceeds the technical evidence currently available. But that promise is already informative.

Its operators are not presenting merely another cookie-and-password collector. They describe a platform that would combine information theft, remote access, cross-platform targeting, cloud credentials, developer data, OSINT, and centralized victim management within a single service.

How much of that architecture actually exists remains unknown.

The next indicators — samples, campaigns, infrastructure, commercialized logs, or customer activity — will help distinguish functional capability from the language used to attract buyers.

For now, Warlock Stealer should be treated as a potentially emerging threat whose commercial proposition warrants monitoring, while its capabilities remain supported primarily by the claims of its own operators.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved