Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ViewSonic vCast Vulnerabilities Let Attackers Seize Control
September 28, 2026
Critical Kiteworks Zero-Day Vulnerability Prompts Server Shutdown Warning
September 28, 2026
CISA Warns of Critical Citrix NetScaler RCE 0-Day Vulnerabilities Under Attack
September 28, 2026
Home/Threats/New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies
Threats

New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies

Key Takeaways A new Python-based malware-as-a-service (MaaS) infostealer is actively targeting Windows systems. The malware is designed to exfiltrate sensitive data, including passwords, credit card...

Jennifer sherman
Jennifer sherman
September 28, 2026 5 Min Read
2 0

Key Takeaways

  • A new Python-based malware-as-a-service (MaaS) infostealer is actively targeting Windows systems.
  • The malware is designed to exfiltrate sensitive data, including passwords, credit card information, browser cookies, messaging app tokens, and Wi-Fi credentials.
  • It targets 17 Chromium-based browsers and Firefox, leveraging Windows data protection functions for decryption.
  • The stealer employs various evasion techniques, such as debugger detection, VM checks, and dynamic library loading, to hinder analysis.
  • Persistence is established through both registry entries and scheduled tasks, ensuring reboot survival.

A sophisticated Python-based malware builder has emerged, enabling threat actors to generate customized Windows executables from a single infostealer payload. This “malware-as-a-service” (MaaS) offering is engineered to pilfer a wide array of sensitive user data, including stored passwords, payment card details, and browser cookies, transmitting them to a webhook controlled by the attacker. Beyond browser data, the stealer also compromises messaging application accounts, extracts wireless network passwords, and gathers detailed information about the infected host.

Table Of Content

  • Key Takeaways
  • Python MaaS Infostealer Capabilities
  • Builder Evasion and Detection
  • What You Should Do

Researchers at K7 Security Labs uncovered this two-part toolkit during an investigation into a nested archive. The outer archive, named my new program called 2.rar, contained another compressed file, TokenGrabberBuilder.zip, which housed the builder components. While the packaging mechanism is clear, the exact methods of initial victim compromise and the scale of infections remain unspecified in their findings.

The architecture of this builder-and-payload system mirrors other prevalent MaaS credential theft operations, providing operators with the flexibility to create distinct malware builds. K7 Security Labs noted in their report that the embedded Python stealer can be compiled into a Windows executable using tools like Nuitka or PyInstaller, or it can be deployed as an uncompiled script. This adaptability allows the same core malicious code to manifest in diverse forms, complicating detection efforts.

The immediate repercussions of an infection extend beyond merely compromised passwords. Stolen session cookies can grant unauthorized access to accounts without requiring a password, while exfiltrated payment details and Wi-Fi credentials significantly broaden the scope of potential damage. The aggregation of such valuable data in infostealer logs can fuel further attacks, turning a single compromised machine into a gateway for more extensive breaches.

Python MaaS Infostealer Capabilities

The infostealer’s payload systematically scans user data directories for 17 distinct Chromium-based browsers, extracting saved login credentials, browsing history, credit card information, and active session cookies. When browser databases are locked, the malware copies them to a temporary location, then employs Windows data protection functions and browser-specific encryption keys to decrypt the stored sensitive information. It is crucial to emphasize that this is a Windows-specific threat, not a browser vulnerability exploit.

In addition to Chromium browsers, Firefox is also targeted. The stealer retrieves browsing history and cookie records from Firefox, while its Chromium-focused routines additionally target passwords and payment card details. The extensive number of browsers targeted underscores the malware’s broad reach, specifically highlighting its capability to compromise 17 Chromium-derived applications.

Beyond browser data, the malware actively seeks out Discord tokens and verifies their validity. It also collects Roblox session cookies. These tokens and session cookies are highly prized by attackers as they can enable direct access to user accounts, bypassing the need for a password. Furthermore, the stealer enumerates saved Wi-Fi profiles to extract their associated passwords, adding network credentials to the trove of stolen browser and account data.

The data collection process is rounded out by gathering system and location specifics. The payload records the victim’s public IP address, approximate geographical location, time zone, Windows username, and computer name. All collected data is then compressed into an archive directly within memory and transmitted via the attacker’s pre-configured webhook. This in-memory archiving and exfiltration technique minimizes forensic artifacts on the file system, making detection and analysis more challenging.

Builder Evasion and Detection

The builder component automates the installation of any required Python dependencies and persistently stores the operator’s chosen webhook address for future build sessions. To obscure its communication channel, the webhook address is encoded using XOR and Base64 before being embedded into the payload, effectively thwarting simple string searches for the plain address in compiled executables. Operators can select between two executable compilation methods or opt to maintain the stealer as a raw Python script for further customization.

Upon execution, the stealer implements several anti-analysis measures. It actively checks for the presence of debuggers, scans for indicators of virtual machine environments, and terminates execution on systems with less than 50 GB of available disk space. The malware also employs variable sleep times and delays the loading of certain libraries until they are strictly necessary. These tactics are designed to impede automated analysis systems and short-term sandboxing efforts without altering the core data exfiltration functionality.

For maintaining persistence across system reboots, the payload utilizes two distinct mechanisms: a Windows startup registry entry, deceptively named WindowsUpdate under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and a scheduled task configured to run at logon. This dual-persistence strategy ensures the malware’s survival even if one of the mechanisms is detected and removed. Similar to other Python-based Discord credential stealers, it validates account tokens before transmitting them to the operator, ensuring only active tokens are exfiltrated.

What You Should Do

  • Monitor for Anomalous Activity: Watch for unusual Python package installations, unexpected entries in the Windows startup registry (specifically HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate), and newly created scheduled tasks that run at logon.
  • Inspect Outbound Network Traffic: Look for suspicious outbound connections to unfamiliar webhooks or legitimate services like https://pastebin.com/api/api_post.php if not part of legitimate operations.
  • Review Access to Sensitive Files: Monitor for unauthorized access attempts to browser credential stores (e.g., Login Data, Web Data, Cookies, places.sqlite, cookies.sqlite) and system files related to Wi-Fi profiles.
  • Exercise Caution with Downloads: Double-check the source and integrity of all downloaded files, especially compressed archives, before opening or executing them. Employ strong endpoint detection and response (EDR) solutions.
  • Maintain Up-to-Date Security Software: Ensure all antivirus and anti-malware solutions are current with the latest threat definitions. Implement behavioral analysis to detect suspicious activities rather than relying solely on file hashes, as this malware’s builds can vary.
  • Enable Multi-Factor Authentication (MFA): Utilize MFA on all critical accounts to provide an additional layer of security, even if passwords or session tokens are compromised.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Top Adaptive & Risk-Based Authentication Tools for 2026

Next Post

Cloud Credential Theft: Attackers Exploit Stolen Keys for Cloud Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies
September 28, 2026
Top Adaptive & Risk-Based Authentication Tools for 2026
September 28, 2026
Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us