XLABB Grabber
Python infostealer packaged via PyInstaller, self-branded "XLABB Grabber" and promoted through Telegram channel t.me/blxstealer. Targets browser credentials, Discord tokens, cryptocurrency wallet extensions, Roblox cookies, Telegram tdata, and system information. Exfiltrates via Discord webhook embeds and file attachments.
Builder lineage
- PyInstaller 2.1+ one-file build
- Python 3.11 runtime bundled
- No anti-analysis, no obfuscation — all IOCs in plaintext
co_consts - Builder dates to at least June 2024 (Discord avatar asset timestamp)
Capabilities
browser-credential-harvestingdiscord-token-theftcryptocurrency-wallet-extension-theftdiscord-webhook-c2-exfilsystem-information-enumerationtelegram-tdata-harvestroblox-cookie-theftbrowser-injection-script-fetchfile-io-secondary-exfil
Pages where observed
- /intel/analyses/24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a.html