typeentityconfidencehighcreated2026-07-25updated2026-07-25infostealerpythonpyinstallerdiscord-webhookbrowser-theftcryptocurrency

XLABB Grabber

Python infostealer packaged via PyInstaller, self-branded "XLABB Grabber" and promoted through Telegram channel t.me/blxstealer. Targets browser credentials, Discord tokens, cryptocurrency wallet extensions, Roblox cookies, Telegram tdata, and system information. Exfiltrates via Discord webhook embeds and file attachments.

Builder lineage

  • PyInstaller 2.1+ one-file build
  • Python 3.11 runtime bundled
  • No anti-analysis, no obfuscation — all IOCs in plaintext co_consts
  • Builder dates to at least June 2024 (Discord avatar asset timestamp)

Capabilities

  • browser-credential-harvesting
  • discord-token-theft
  • cryptocurrency-wallet-extension-theft
  • discord-webhook-c2-exfil
  • system-information-enumeration
  • telegram-tdata-harvest
  • roblox-cookie-theft
  • browser-injection-script-fetch
  • file-io-secondary-exfil

Pages where observed

  • /intel/analyses/24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a.html