A newly analyzed sample, disguised inside a file named “my new program called 2.rar,” has exposed a Malware-as-a-Service (MaaS) operation that lets low-skill actors mass-produce Windows infostealers.
Peeling back the archive revealed a second payload, TokenGrabberBuilder.zip, containing a “TokenGrabber Builder” folder with a Python-based build tool and an embedded stealer payload a structure designed to separate malware generation from deployment so one builder can arm many operators simultaneously.
Rather than shipping a static script, the builder auto-installs its own dependencies at startup, letting anyone run it on a clean Python environment without manual setup a detail that also creates a detection opportunity, since unexpected pip.exe activity from non-development processes is abnormal behavior worth flagging.
New Python Infostealer Kit “TokenGrabber Builder”
The builder’s most telling feature is webhook handling. Each operator’s Discord or Telegram webhook is XOR-encoded with the key 0x5A, then Base64-encoded before being embedded as a string literal, decoded only at runtime by a function labeled _x().
According to K7, this means every generated binary carries a unique encoded endpoint, deliberately breaking hash-based correlation between samples and complicating attribution.

Operators can then choose between three build options: Nuitka compilation (explicitly marketed in the tool’s interface as offering “stronger AV evasion” by producing binaries with no recoverable Python bytecode), PyInstaller (faster, but unpackable with tools like pyinstxtractor), or a raw, uncompiled script for manual tuning.
The embedded stealer, functionally mirrored in a standalone sample called stealer.py, encrypts every sensitive string API endpoints, registry paths, SQL queries with the same 0x5A XOR cipher, then loads risky libraries only when needed to minimize observable startup activity.
Before acting, it runs four anti-analysis checks: detecting attached debuggers via IsDebuggerPresent(), scanning for VirtualBox, Xen, QEMU, or Parallels processes, verifying total disk capacity exceeds 50 GB, and injecting randomized sleep delays tied to the process ID to outlast sandbox timeouts.
For persistence, it writes itself to the registry Run key under the deceptive name “WindowsUpdate” and simultaneously creates a hidden ONLOGON scheduled task using CREATE_NO_WINDOW flags.

Its collection scope is extensive: credentials, cookies, and saved cards from 17 Chromium-based browsers via DPAPI and AES-256-GCM decryption; Firefox history and plaintext cookies; Wi-Fi passwords via netsh wlan show profiles key=clear; Discord tokens validated live against Discord’s API; and Roblox .ROBLOSECURITY session cookies. It also geolocates the victim through IP lookup and gathers the Windows username and machine name.
All stolen data is zipped in-memory using BytesIO, avoiding disk writes, named StolenData_<USERNAME>.zip, and exfiltrated via HTTP POST to the decoded webhook.
Because webhook encoding varies per build, static signatures lose effectiveness quickly. Defenders should instead watch for anomalous pip.exe execution, new Run-key or scheduled-task entries, netsh wlan enumeration, browser database access, unexplained POST requests to unfamiliar endpoints, and in-memory ZIP creation tied to data collection.
Indicators of Compromise
| Hash | Detection Name |
| 610f0c65a3f8e88559f89ed90ea9ee5c | Password-Stealer ( 006dba241 ) |
| 429ed63ab3fbda8d22d0ac750ecfe8cc | Password-Stealer ( 006dba241 ) |
| 9ffe0e45c7a3f20e4481206c1c3b0854 | Trojan ( 006e632e1 ) |
Users are advised to avoid downloading executables from unverified sources and to run updated endpoint security capable of behavioral detection rather than signature matching alone.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.