A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies.
The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook.
The archive included a “TokenGrabber Builder” folder containing a Python builder and an embedded stealer payload.
The structure points to a malware-as-a-service (MaaS) model, allowing multiple affiliates or low-skilled operators to build and deploy individualized samples.
The builder can compile the embedded Python payload into Windows executables using Nuitka or PyInstaller, or save it as a raw Python script.
Nuitka is especially notable because it converts Python code into native binaries, reducing the presence of recoverable Python bytecode and complicating analysis with common Python decompilers.
Before compilation, the
operator supplies a Discord or Telegram webhook address. The builder XOR-encrypts the address with key 0x5A, Base64-encodes it and injects it into the payload.
This approach prevents the webhook from appearing in plaintext and causes separately built samples to carry different encoded configuration values and potentially distinct hashes, weakening simple indicator-based clustering.
The builder also automatically installs dependencies when needed and searches for locally installed Python interpreters through environment paths, common installation directories and Windows Registry locations.