AnarchyGrabber is a Discord-focused credential and token stealing malware family that modifies the Discord client to load attacker-controlled JavaScript each time the application starts. Early variants were primarily used to steal Discord authentication tokens, enabling account hijacking and impersonation. Later variants, notably AnarchyGrabber3, expanded functionality to capture plaintext credentials, interfere with two-factor authentication workflows, and abuse compromised accounts to propagate malicious links or payloads to the victim’s contacts on Discord.
The malware operates by altering Discord client components so malicious scripts are executed within the trusted application context. After forcing the victim to re-authenticate, it captures account data such as login credentials and session material, then exfiltrates the stolen information through Discord webhook infrastructure controlled by the attacker. Infected clients can also remain responsive to attacker commands while the user is connected to Discord, effectively turning compromised accounts into a lightweight botnet for further distribution and post-compromise abuse.
AnarchyGrabber has commonly been distributed through Discord communities and adjacent social channels using lures such as game cheats, hacking tools, token grabbers, and pirated software. It has also been circulated on forums and in videos aimed at users seeking illicit tools. The malware is strongly associated with the gaming and Discord user ecosystem rather than traditional enterprise targeting. Its design complicates detection because the initial installer may terminate after patching the Discord client, leaving the malicious behavior to persist through the modified application rather than a continuously running standalone malware process.
AnarchyGrabber has also influenced later Discord-centric stealers and builders, with other malware families reusing or adapting its techniques for Discord client injection and token theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AnarchyGrabber is referenced as stolen code incorporated into Osno to abuse Discord for credential and data theft by forcing Discord to load malicious JScript modules.
Discord token stealer used to hijack Discord accounts by extracting tokens and exfiltrating them (commonly via webhooks).
Discord token stealer used to steal access tokens and send them back to attackers, enabling account hijacking.
A Discord malware family mentioned only as the basis for TroubleGrabber.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.