K7 Details Python TokenGrabber Stealer for 17 Browsers
K7 describes TokenGrabber, a Python infostealer builder that steals browser, Discord, Roblox and Wi-Fi data and posts it to webhooks.
K7 Labs, also called K7 Security Labs in one outlet, analyzed TokenGrabber, a Python malware-as-a-service builder that produces a Windows infostealer left as a script or compiled with Nuitka or PyInstaller. The payload harvests saved passwords, payment-card data, browsing history and session cookies from 17 Chromium-based browsers; one report includes Firefox in that full collection, while the other limits Firefox to history and cookies. It also takes Discord tokens, Roblox session cookies and Wi-Fi passwords, and the later report adds host and location details, with browser master keys decrypted via Windows DPAPI and AES-256-GCM. Stolen data is archived—as a StolenData zip or an in-memory archive—and posted over HTTP to an operator webhook described as XOR- and Base64-obfuscated; one source names Discord or Telegram and cites XOR key 0x5A. The stealer persists through an HKCU Run value named WindowsUpdate and a logon (ONLOGON) scheduled task, and it checks for analysis environments, including debuggers, virtual machines and disks under 50 GB. According to the second report, K7 has not determined how the malware is delivered or how many systems were infected.
- On 2026-09-28, K7 Labs (called K7 Security Labs in one report) described TokenGrabber, a Python malware-as-a-service builder for a Windows infostealer.
- Operators can leave the payload as a script or compile it with Nuitka or PyInstaller; one report says it was found in a nested archive.
- It steals passwords, payment cards, history and cookies from 17 Chromium browsers. Sources disagree on Firefox: one includes it in that full set; the other limits Firefox to history and cookies.
- It also collects Discord tokens, Roblox session cookies and Wi-Fi passwords; the later report adds host and location details. Browser master keys are decrypted with Windows DPAPI and AES-256-GCM.
- Data is sent by HTTP POST to an operator webhook obfuscated with XOR and Base64 (XOR key 0x5A in one report). One source names Discord or Telegram and a StolenData zip; the other describes an in-memory archive.
- Persistence uses an HKCU Run value named WindowsUpdate and a logon (ONLOGON) scheduled task. Anti-analysis includes debugger and VM checks and an exit if the disk is under 50 GB.
- K7 did not establish the delivery method or how many machines were infected.
Coverage timelineoldest first · each row is one article
- · 2d agoNew Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
GBHackers· 50
K7 Labs details a Python infostealer MaaS builder harvesting credentials, cards and session cookies from 17 Chromium browsers plus Firefox.
- · 1d agoPython MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers
Cyber Security News· 49
K7 Labs analyzed a Python malware-as-a-service builder that steals browser passwords, cards, and cookies from 17 Chromium browsers.