TroubleGrabber is a Windows credential-stealing malware family associated with Discord-centric distribution and exfiltration workflows. It emerged in 2020 and was used by multiple threat actors, with activity heavily oriented toward gamer communities through lures themed as Discord Nitro generators, cheats, installers, and cracked software. The malware is notable for abusing Discord infrastructure both to distribute payloads through public attachments and to exfiltrate stolen data through Discord webhooks, while some variants also retrieve additional components from GitHub.
TroubleGrabber is designed to steal Discord tokens, browser-stored credentials, webhook tokens, external IP information, and detailed host profiling data. Observed components collect operating system and hardware details, browser passwords, and tokens from Discord client variants and browsers, then package and transmit the results to attacker-controlled webhook endpoints. Some builds also terminate and restart Discord processes to facilitate token theft. The malware ecosystem included a builder attributed to the online persona “Itroublve,” enabling other actors to generate customized stealer binaries by supplying their own webhook destinations and optional behaviors.
Observed payload chains used a first-stage executable to download and run multiple scripts and utilities, including components for browser password recovery and token harvesting. The malware can remove temporary artifacts after execution and, depending on builder options, may restart or shut down the victim system. Distribution was observed primarily through Discord attachment links and drive-by download pages, with additional hosting on file-sharing services. More than a thousand generated binaries and widespread use across numerous Discord server channels indicate that TroubleGrabber functioned as a scalable malware-as-a-builder ecosystem rather than a single static sample family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Uses https://myexternalip.com/raw to query the external IP address of the victim and saves it to the location “C:\temp\ip_address.txt”
Performs curl posts of username, time and date, IP address, SystemInfo, and Discord, PTB, and Canary tokens via webhooks to the attacker’s Discord server
Uses Windows system info with the switch ‘findstr’ and wmic commands to find the “Domain,” “OS Name,” “OS Version,” “System Manufacturer,” “System Model,” “System type,” “Total Physical Memory,” “Disk drive,” “Hard Drive Space,” “Serial number,” and “cpuname”’
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of malware previously hosted on Discord using public attachment URLs.
A separate Discord malware family that spreads via GitHub and is mentioned for comparison/background.
A credential-stealing malware family distributed primarily via Discord attachments and drive-by downloads. It downloads additional payloads from Discord and GitHub, steals browser tokens, Discord webhook tokens, browser passwords, IP address, and system information, and exfiltrates the data back to attackers through Discord webhooks/messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.