New Infostealer Can Steal Passwords, Cards, Cookies and Wi-Fi Keys From Windows PCs
K7 Labs analyzed a Python infostealer builder that steals Windows browser secrets, cards, cookies, Discord tokens, and Wi-Fi passwords.
K7 Security Labs analyzed a Python infostealer builder, distributed as TokenGrabberBuilder.zip inside a nested archive, that generates customized Windows payloads. The embedded stealer.py harvests credentials, payment cards, history, and cookies from Chromium and Firefox, Discord tokens, Roblox session cookies, and plaintext Wi-Fi passwords via netsh. It obfuscates the webhook, checks for debuggers and virtual machines, and persists through a deceptive WindowsUpdate Run key plus an ONLOGON scheduled task. Stolen data is packed in memory as StolenData_<USERNAME>.zip and posted to an operator-controlled webhook.
- Builder outputs Windows payloads via Nuitka, PyInstaller, or raw Python.
- Targets at least 17 Chromium browsers plus Firefox profiles.
- Steals passwords, cards, cookies, Discord tokens, Roblox cookies, and Wi-Fi keys.
- Persists with an HKCU Run key and an ONLOGON scheduled task.
- Exfiltrates an in-memory StolenData zip to a configured webhook.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 429ed63ab3fbda8d22d0ac750ecfe8cc | 0c65a3f8e88559f89ed90ea9ee5c Password-Stealer ( 006dba241 ) 429ed63ab3fbda8d22d0ac750ecfe8cc Password-Stealer ( 006dba241 ) 9ffe0e45c7a3f20e4481206c1c3b |
| md5 | 610f0c65a3f8e88559f89ed90ea9ee5c | icators alone. Indicators of Compromise Hash Detection Name 610f0c65a3f8e88559f89ed90ea9ee5c Password-Stealer ( 006dba241 ) 429ed63ab3fbda8d22d0ac750ecf |
| md5 | 9ffe0e45c7a3f20e4481206c1c3b0854 | d63ab3fbda8d22d0ac750ecfe8cc Password-Stealer ( 006dba241 ) 9ffe0e45c7a3f20e4481206c1c3b0854 Trojan ( 006e632e1 ) Note: IP addresses and domains are int |
Full article776 words · extracted from gbhackers.com · click to collapse
A Python-based infostealer builder that enables threat actors to generate customized Windows payloads capable of stealing browser credentials, payment-card data, session cookies, Discord tokens, Wi-Fi passwords and extensive system information.
Rather than functioning as a single-use stealer, the package includes a builder interface and an embedded payload, providing a model consistent with Malware-as-a-Service operations.
Operators can configure an attacker-controlled webhook, choose a compilation method and generate separate Windows binaries for distribution.
This design can help affiliates deploy samples with distinct hashes and exfiltration infrastructure, complicating correlation and signature-based detections.
The builder automatically installs required Python dependencies when launched, reducing setup requirements for criminals operating in clean Python environments.
That behavior makes unexpected pip.exe activity from non-development applications a potentially useful detection signal.

The payload reverses this process at runtime, preventing the webhook from appearing as plaintext within the compiled executable.
Operators can build payloads with Nuitka, PyInstaller or save the malware as a raw Python script.
Nuitka is particularly notable because it compiles Python code through C into a native executable, limiting the usefulness of Python-bytecode recovery tools.
The builder reportedly advertises this route as offering stronger antivirus evasion, while PyInstaller produces a package that can often be unpacked to recover .pyc bytecode.
The builder also excludes non-essential Python libraries such as tkinter, matplotlib, numpy and pandas to reduce file size and potentially minimize its detection footprint.
K7 Security Labs said in a report shared with GBhackers, the malware was found inside a suspicious nested archive chain, beginning with a RAR file named “my new program called 2.rar” and a ZIP archive called “TokenGrabberBuilder.zip.”
Python-based infostealer
The embedded payload, tracked as stealer.py, is designed for Windows and targets at least 17 Chromium-based browsers.
The interface stores the selected webhook address in a local webhook.txt file, then embeds the destination into the generated stealer. Before insertion, the URL is XOR-encrypted with the 0x5A key and Base64-encoded.

It accesses browser databases including Login Data, History, Web Data and Cookies to collect saved usernames, passwords, browsing activity, stored payment-card details and session cookies.
To decrypt protected Chromium credentials, the malware obtains the browser’s encrypted master key from the Local State file and uses Windows DPAPI, followed by AES-GCM decryption where applicable.
Firefox is also targeted through profile directories under %APPDATA%\Mozilla\Firefox\Profiles.
The stealer reads places.sqlite for browsing history and cookies.sqlite for session cookies, which can expose authenticated web sessions even where a password is not directly stolen.
The malware additionally runs netsh wlan show profiles and uses the key=clear option to retrieve saved Wi-Fi credentials in plaintext.
It searches Discord LevelDB storage for tokens, validates potentially active tokens through Discord’s API, and hunts for .ROBLOSECURITY cookies that could enable unauthorized access to Roblox accounts.
To frustrate analysis, the stealer stores sensitive strings as Base64-encoded data encrypted with XOR. It dynamically loads higher-risk modules only when needed and checks for debuggers through the Windows IsDebuggerPresent() API.

It also terminates when it detects virtualization-related processes, identifies a disk smaller than 50 GB or encounters sandbox-like execution conditions.
For persistence, the malware writes a deceptive WindowsUpdate entry to HKCU\Software\Microsoft\Windows\CurrentVersion\Run and creates an ONLOGON scheduled task.
The dual method gives the payload multiple opportunities to relaunch after reboot or user sign-in.
Collected data is compressed into an in-memory archive named StolenData_<USERNAME>.zip, limiting artifacts left on disk.
The archive can include public IP information, country, city, ISP, coordinates, timezone, username and hostname alongside stolen browser and wireless data.
It is then sent through an HTTP POST request to the operator’s configured webhook.
Defenders should watch for suspicious access to browser credential stores, unusual netsh Wi-Fi-profile queries, unexpected Run-key modifications, newly created scheduled tasks, anomalous pip.exe execution and outbound uploads to untrusted webhook services.
Because each build can carry different configuration data and hashes, behavioral detections are likely to be more reliable than static indicators alone.
Indicators of Compromise
| Hash | Detection Name |
| 610f0c65a3f8e88559f89ed90ea9ee5c | Password-Stealer ( 006dba241 ) |
| 429ed63ab3fbda8d22d0ac750ecfe8cc | Password-Stealer ( 006dba241 ) |
| 9ffe0e45c7a3f20e4481206c1c3b0854 | Trojan ( 006e632e1 ) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.