Cyble Research Labs reported that an upgraded Hazard Token Grabber malware strain is being used at scale to steal user data, with a primary focus on Discord users. The Python-based information stealer, first observed in 2021, has been distributed freely on GitHub while a more advanced version has been marketed through Discord and a dedicated website. Researchers said they identified more than 2,000 related samples in the wild, indicating broad circulation of the malware.
The malware establishes persistence, disables Discord token protection, and exfiltrates stolen data through Discord webhooks. In addition to Discord tokens, it targets Chrome credentials and cookies, Roblox cookies, Windows product details, geolocation data, and information from more than 20 applications and browsers. Its feature set also includes anti-debugging and anti-virtual machine checks consistent with MITRE ATT&CK T1497.001 system-check sandbox evasion techniques, helping it avoid analysis while harvesting victim data.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The initial version of the Python-based Hazard Token Grabber stealer was observed in the wild in 2021. The malware was described as targeting user data, especially Discord-related information.
Cyble Research Labs analyzed an upgraded version of Hazard Token Grabber that was being used by threat actors at scale, with more than 2,000 related samples found during OSINT threat hunting. The research documented free distribution on GitHub, sale of an advanced version via Discord or a website, and extensive data theft and Discord webhook exfiltration capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.