Roblox: New Windows Infostealer Targets 17 Browsers to Steal Passwords and Credit Cards

Roblox: New Windows Infostealer Targets 17 Browsers to Steal Passwords and Credit Cards

Python-Based Windows Infostealer Distributed via Nested Archive Targets Credentials and Payment Data

Security researchers have identified a Python-based Windows infostealer spreading through a deceptive nested archive file, my new program called 2.rar. The malware, delivered via TokenGrabberBuilder.zip, is designed to harvest credentials, payment-card details, browser cookies, Wi-Fi passwords, Discord tokens, Roblox session cookies, and system information.

The attack leverages a Malware-as-a-Service (MaaS) model, enabling operators to generate customized executables with attacker-controlled webhook settings. The builder automates Python dependency installation, ensuring functionality even on systems without a preconfigured development environment. Webhook URLs are stored in webhook.txt, encrypted via XOR (0x5A key) and Base64 encoding to evade detection and produce unique malware samples.

Operators can compile the payload using Nuitka (converting Python to native binaries), PyInstaller (bundling into a single executable), or distribute it as a raw script for further modification. The malware scans for Python installations across environment paths, registry keys, and common directories to ensure compatibility.

To evade analysis, the stealer employs obfuscation, anti-debugging checks, and delayed execution tactics, including:

  • Detecting debuggers, virtualization processes, and small disk sizes (<50 GB).
  • Dynamically loading libraries and decoding strings only during runtime.
  • Implementing variable sleep periods to disrupt sandbox analysis.

For persistence, the malware creates a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) under the deceptive name WindowsUpdate and sets a scheduled task to launch at user logon.

The infostealer targets 17 Chromium-based browsers, extracting saved credentials, browsing history, credit-card details, and session cookies from Login Data, Web Data, and Cookies databases. It decrypts browser data using Windows DPAPI to recover encryption keys from the Local State file. Firefox users are also affected, with the malware accessing places.sqlite and cookies.sqlite for browsing data.

Indicators of Compromise (IoCs) include the following hashes:

  • 610f0c65a3f8e88559f89ed90ea9ee5c (Password-Stealer)
  • 429ed63ab3fbda8d22d0ac750ecfe8cc (Password-Stealer)
  • 9ffe0e45c7a3f20e4481206c1c3b0854 (Trojan)

The campaign highlights the growing sophistication of Python-based infostealers, combining MaaS accessibility, anti-analysis techniques, and multi-browser credential theft to maximize impact.

Source: https://cyberpress.org/windows-infostealer-targets-browsers/

Roblox TPRM report: https://www.rankiteo.com/company/roblox

"id": "rob1790929429",
"linkid": "roblox",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'End users, organizations'}],
 'attack_vector': 'Nested archive file (RAR/ZIP)',
 'data_breach': {'data_encryption': 'DPAPI (for browser data), XOR + Base64 '
                                    '(for webhook URLs)',
                 'data_exfiltration': 'Yes',
                 'file_types_exposed': ['Login Data',
                                        'Web Data',
                                        'Cookies',
                                        'places.sqlite',
                                        'cookies.sqlite'],
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Credentials',
                                              'Payment-card details',
                                              'Browser cookies',
                                              'Wi-Fi passwords',
                                              'Discord tokens',
                                              'Roblox session cookies',
                                              'System information']},
 'description': 'Security researchers have identified a Python-based Windows '
                'infostealer spreading through a deceptive nested archive '
                'file, *my new program called 2.rar*. The malware, delivered '
                'via *TokenGrabberBuilder.zip*, is designed to harvest '
                'credentials, payment-card details, browser cookies, Wi-Fi '
                'passwords, Discord tokens, Roblox session cookies, and system '
                'information. The attack leverages a Malware-as-a-Service '
                '(MaaS) model, enabling operators to generate customized '
                'executables with attacker-controlled webhook settings. The '
                'builder automates Python dependency installation, ensuring '
                'functionality even on systems without a preconfigured '
                'development environment. Webhook URLs are stored in '
                '*webhook.txt*, encrypted via XOR (0x5A key) and Base64 '
                'encoding to evade detection and produce unique malware '
                'samples.',
 'impact': {'data_compromised': 'Credentials, payment-card details, browser '
                                'cookies, Wi-Fi passwords, Discord tokens, '
                                'Roblox session cookies, system information',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'Windows systems with Python installations'},
 'initial_access_broker': {'entry_point': 'Nested archive file (*my new '
                                          'program called 2.rar*, '
                                          '*TokenGrabberBuilder.zip*)'},
 'motivation': 'Financial gain, credential theft, data exfiltration',
 'post_incident_analysis': {'root_causes': 'Malware-as-a-Service (MaaS) model, '
                                           'lack of Python environment '
                                           'validation, weak anti-malware '
                                           'detection'},
 'references': [{'source': 'Security researchers'}],
 'title': 'Python-Based Windows Infostealer Distributed via Nested Archive '
          'Targets Credentials and Payment Data',
 'type': 'Infostealer'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.