Discord: New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies

Discord: New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies

Python-Based Info-Stealer Targets Browsers and Wi-Fi Credentials in MaaS Campaign

Researchers at K7 Labs uncovered a Python-based information-stealing malware campaign that harvests sensitive data from 17 Chromium-based browsers, Firefox, and Wi-Fi networks. The malware, distributed via a TokenGrabber Builder framework, operates under a malware-as-a-service (MaaS) model, allowing low-skilled operators to generate customized Windows payloads.

The builder, found in a nested RAR archive (my new program called 2.rar), enables attackers to compile Python-based stealers into Windows executables using Nuitka or PyInstaller. Nuitka’s conversion of Python code into native binaries complicates analysis by reducing recoverable bytecode. Operators configure data exfiltration via Discord or Telegram webhooks, which are XOR-encrypted (key 0x5A) and Base64-encoded to evade detection.

The stealer targets browser data including saved credentials, payment-card details, browsing history, and session cookies by accessing SQLite databases in Chromium and Firefox profiles. It decrypts Chromium’s master key using Windows DPAPI and handles newer AES-256-GCM-encrypted entries, while also extracting Firefox’s places.sqlite and cookies.sqlite. Additionally, it steals Wi-Fi profiles via netsh wlan show profiles, Discord tokens, and Roblox session cookies (.ROBLOSECURITY).

Persistence is achieved through a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) disguised as WindowsUpdate and an ONLOGON scheduled task. The malware employs anti-analysis techniques, checking for debuggers, virtual machines, and sandbox environments.

Collected data including IP addresses, usernames, and system details is bundled into StolenData_.zip and exfiltrated via HTTP POST to the attacker’s webhook, minimizing disk-based artifacts. Behavioral detection signals include unexpected pip.exe execution, browser database access by untrusted processes, and outbound webhook traffic.

Indicators of compromise (IoCs) include hashes such as 610f0c65a3f8e88559f89ed90ea9ee5c and 429ed63ab3fbda8d22d0ac750ecfe8cc, with domains and IPs defanged to prevent accidental resolution. The campaign highlights the risks of archive-delivered malware and the need for behavior-based monitoring.

Source: https://gbhackers.com/python-infostealer-campaign/

Discord cybersecurity rating report: https://www.rankiteo.com/company/discord

"id": "DIS1790583884",
"linkid": "discord",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'General Users, Organizations'}],
 'attack_vector': 'Malware-as-a-Service (MaaS), Nested RAR Archive',
 'data_breach': {'data_encryption': 'Data encrypted via XOR (key 0x5A) and '
                                    'Base64-encoded for exfiltration',
                 'data_exfiltration': "Yes, via HTTP POST to attacker's "
                                      'webhook',
                 'file_types_exposed': 'SQLite databases (Chromium/Firefox '
                                       'profiles), ZIP archives '
                                       '(StolenData_.zip)',
                 'personally_identifiable_information': 'Yes (saved '
                                                        'credentials, payment '
                                                        'details, session '
                                                        'cookies, Wi-Fi '
                                                        'profiles)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Browser data (credentials, '
                                             'payment details, history, '
                                             'cookies), Wi-Fi profiles, '
                                             'Discord tokens, Roblox session '
                                             'cookies'},
 'description': 'Researchers at K7 Labs uncovered a Python-based '
                'information-stealing malware campaign that harvests sensitive '
                'data from 17 Chromium-based browsers, Firefox, and Wi-Fi '
                'networks. The malware, distributed via a TokenGrabber Builder '
                'framework, operates under a malware-as-a-service (MaaS) '
                'model, allowing low-skilled operators to generate customized '
                'Windows payloads.',
 'impact': {'data_compromised': 'Saved credentials, payment-card details, '
                                'browsing history, session cookies, Wi-Fi '
                                'profiles, Discord tokens, Roblox session '
                                'cookies',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'Windows systems with Chromium-based browsers, '
                                'Firefox, Wi-Fi networks'},
 'initial_access_broker': {'entry_point': 'Nested RAR archive (my new program '
                                          'called 2.rar)'},
 'lessons_learned': 'Risks of archive-delivered malware, need for '
                    'behavior-based monitoring, challenges in analyzing '
                    'Python-based malware converted to native binaries',
 'motivation': 'Financial Gain, Data Theft',
 'post_incident_analysis': {'corrective_actions': 'Enhance monitoring for '
                                                  'behavioral indicators '
                                                  '(e.g., pip.exe execution, '
                                                  'browser database access), '
                                                  'improve detection of '
                                                  'archive-delivered malware, '
                                                  'restrict webhook traffic',
                            'root_causes': 'Malware-as-a-Service (MaaS) model '
                                           'enabling low-skilled operators, '
                                           'use of Python-based stealers '
                                           'compiled into native binaries, '
                                           'evasion techniques (XOR/Base64 '
                                           'encryption, anti-analysis checks)'},
 'recommendations': 'Implement behavior-based monitoring, restrict access to '
                    'browser databases, monitor outbound webhook traffic, '
                    'educate users on risks of archive-delivered malware',
 'references': [{'source': 'K7 Labs'}],
 'response': {'enhanced_monitoring': 'Behavior-based monitoring for unexpected '
                                     'pip.exe execution, browser database '
                                     'access by untrusted processes, and '
                                     'outbound webhook traffic',
              'third_party_assistance': 'K7 Labs'},
 'title': 'Python-Based Info-Stealer Targets Browsers and Wi-Fi Credentials in '
          'MaaS Campaign',
 'type': 'Information Stealer'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.