Mercurial Grabber is an open-source Windows infostealer, nominally presented as an educational tool. It collects Discord tokens, Chrome-saved passwords and cookies, Roblox and Minecraft session data, Windows product keys, system information, and screenshots, then exfiltrates the collected data through Discord webhooks. It has been distributed in a malware bundle masquerading as a leaked Grand Theft Auto VI installer, promoted through search-result manipulation, gaming forums, social media, and torrent sites. The campaign used Russian-language lures and targeted prospective game downloaders, deploying Mercurial Grabber alongside remote-access trojans and a destructive Chaos-based wiper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Mercurial Grabber... harvest[s] Discord tokens, Chrome-saved passwords and cookies, Roblox and Minecraft session data.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer that harvests Discord tokens, Chrome credentials and cookies, Roblox and Minecraft session data, Windows product keys, and screenshots, exfiltrating the information through a Discord webhook.
Open-source infostealer embedded in the installer. It collects Discord tokens, Chrome credentials and cookies, Roblox and Minecraft session information, Windows product keys, and host information, then exfiltrates the data through a Discord webhook.
Information stealer that collects Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, host and geolocation information, Windows product keys, and screenshots. It exfiltrates collected data through a Discord webhook.
An information-stealing malware (stealer) referenced in leaked logs; described as being used by ransomware groups to collect victim data from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.