Attackers have weaponized the open-source Python red-teaming tool RedTiger to create an infostealer capable of compromising Discord accounts, stealing cryptocurrency wallet data, and exfiltrating payment information. The malware, distributed as standalone binaries with gaming or Discord-related names, scans infected systems for Discord and browser database files, extracts authentication tokens, and injects malicious JavaScript into Discord's codebase to intercept sensitive events such as logins and purchases. In addition to Discord credentials, the infostealer targets browser-stored passwords, cookies, credit card details, and game account data, with a particular focus on French Discord users.
RedTiger's infostealer component is being abused by threat actors despite its "legal use only" disclaimer on GitHub, as its free distribution and lack of safeguards facilitate malicious use. The malware builder bundled with RedTiger enables attackers to easily generate customized payloads, further increasing the risk of widespread abuse. Security researchers have observed the tool being used to compromise Discord accounts, steal cryptocurrency wallets, and harvest a wide range of personal and financial information from victims' systems.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting said the infostealer weaponized a Python red-teaming tool, adding technical context on how the malware was built and used in attacks against Discord users and crypto wallet holders.
Security reporting described a malware campaign using a RedTiger-based infostealer to steal Discord accounts. The malware was also reported to target sensitive data such as cryptocurrency wallet information.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.