{"id":10840,"date":"2026-02-21T10:03:47","date_gmt":"2026-02-21T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/21\/charliekirk-grabber-stealer-attacking-windows-systems-to-exfiltrate-login-credentials\/"},"modified":"2026-02-21T10:03:47","modified_gmt":"2026-02-21T10:03:47","slug":"charliekirk-grabber-stealer-attacking-windows-systems-to-exfiltrate-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/21\/charliekirk-grabber-stealer-attacking-windows-systems-to-exfiltrate-login-credentials\/","title":{"rendered":"CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials"},"content":{"rendered":"<p>    CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new Python-based infostealer called CharlieKirk Grabber has been identified targeting Windows systems, with a focused goal of stealing stored login credentials, browser cookies, and session data. <\/p>\n<p>The malware is built to work as a \u201csmash-and-grab\u201d threat \u2014 it launches quickly, collects whatever sensitive data it can find, and disappears before the user notices anything unusual.<\/p>\n<p>The malware arrives as a Windows executable, packaged through a tool called PyInstaller, which bundles all its Python code into a single self-contained file that runs without requiring Python to be installed on the target machine. <\/p>\n<p>It borrows its name and political imagery from Turning Point USA to exploit social engineering. The malware is typically delivered through phishing emails, cracked software packages, game cheat downloads, or social media-based lures.<\/p>\n<p><a href=\"https:\/\/www.cyfirma.com\/research\/charliekirk-grabber-a-python-based-infostealer\/\" id=\"https:\/\/www.cyfirma.com\/research\/charliekirk-grabber-a-python-based-infostealer\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cyfirma researchers identified the malware<\/a> and noted that it uses a builder-style structure, which makes it modular. <\/p>\n<p>This means that whoever operates it can freely configure the command-and-control (C2) settings \u2014 such as a Discord webhook or a Telegram bot \u2014 and switch specific collection modules on or off before deploying the final executable.<\/p>\n<p>Once active on a system, CharlieKirk Grabber profiles the host by collecting the username, hostname, hardware UUID, and the <a href=\"https:\/\/cybersecuritynews.com\/russia-released-list-of-ip-addresses\/\" id=\"8787\" target=\"_blank\" rel=\"noreferrer noopener\">external IP address<\/a>. <\/p>\n<p>It forcibly kills running browser processes using the Windows TASKKILL tool, unlocking access to saved password databases. <\/p>\n<p>The stolen data \u2014 covering passwords, cookies, autofill entries, browsing history, and Wi-Fi credentials \u2014 is then bundled into a ZIP archive and uploaded to the GoFile file-hosting platform. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjjhFQHry6JtF14KV3veAVsiVr28ZBPqlTomItcVoxTswrCyryPSHFqZ_3huvc9ZPD_dOR0-JAX773hottgF6Cb7_pPzcySHahm0G1f40Qtm4qmdt5hjhRHzzkUOgojJtfXtNg9LLo4wh4pJWteGEg8bYnVEimQVU0uaW7n86zHOjZK2p9oU99UT5ylPY\/s16000\/CharlieKirk%2520Grabber%2520Stealer%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"CharlieKirk Grabber Stealer (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">CharlieKirk Grabber Stealer (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>A download link is immediately sent to the attacker over HTTPS through either a <a href=\"https:\/\/cybersecuritynews.com\/exela-stealer-attacking-discord-users\/\" id=\"44438\" target=\"_blank\" rel=\"noreferrer noopener\">Discord webhook<\/a> or a Telegram bot, keeping all communications encrypted.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-living-off-the-land-how-charliekirk-stays-hidden\"><strong>Living Off the Land: How CharlieKirk Stays Hidden<\/strong><\/h2>\n<p>What makes this stealer particularly difficult to detect is its heavy use of legitimate Windows tools that are already part of every installation. <\/p>\n<p>Instead of deploying suspicious third-party files, the malware uses NETSH.EXE to retrieve saved Wi-Fi passwords, SYSTEMINFO.EXE to map hardware and OS details, and PowerShell to silently add itself to Microsoft Defender\u2019s exclusion list. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjmgxWtkTjMTkHbC539zBCjHJMMu9QKqh8dLiDIgggp4ur4HDNbZ0rzag2IEGcgg9Y2OijCxwqZHSRp9AH1fJgMOzx1u8YnbTElOUv8SPhUdhkivTw-gTJx4vowKJt6hYqSRBK7qLDp4QWnGaBC76bI2guWnGG0OwZmWU0ha1AgJa8bwPaAVtJd1714JEk\/s16000\/UAC%2520elevation%2520attempt%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"UAC elevation attempt (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">UAC elevation attempt (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>This method, known as \u201cliving off the land,\u201d lets malicious actions blend in with normal administrative behavior, helping it avoid signature-based detection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzm_T472qdmmEv4xLaH2Fjfm3YOLTrI1yX7uwJVvQCSdqO7AKjAPicRY9zYxsgm7ll2PslU6v_0Xb641FhDpOzMuCs70MM6SdzADfbUljCNXItabSLdR51QqnTPEUUX_EdWwpFF3KVjgrW0MEM9IzG4Au9H3Mn2B7uXMZwQNjwE6JvDiQn4_9i8YTBHIE\/s16000\/Discord%2520Token%2520Theft%2520and%2520Account%2520Validation%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"Discord Token Theft and Account Validation (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">Discord Token Theft and Account Validation (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>Organizations should enforce <a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" id=\"88334\" target=\"_blank\" rel=\"noreferrer noopener\">Multi-Factor Authentication<\/a> across all critical services and restrict browser-based password storage through enterprise policy. <\/p>\n<p>Security teams should monitor for <a href=\"https:\/\/cybersecuritynews.com\/browser-extensions-can-harm-your-organization\/\" id=\"70539\" target=\"_blank\" rel=\"noreferrer noopener\">unusual browser process<\/a> termination events, outbound HTTPS traffic to Discord, Telegram, or GoFile, and any PowerShell activity in user-writable directories. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8yCAd1oShyfp-DUt1CKsz_crt5gZJMwlQEeipuDhC91lH3rZBv3rghbH0tYzIQunWLJJyjyax6dtWWgwdhSnQAWvjq1uYH6uzUChEHBgMIkrt2PPm3403NYS_ystYiDeGyc02FZ4SVt6rq75feeCjSE7pKG917QyICHCf9rvcE-AJFRrtZFvV3tdnwrM\/s16000\/Credential%2520and%2520File%2520Extraction%2520Activity%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"Credential and File Extraction Activity (Source - Cyfirma)\"><figcaption class=\"wp-element-caption\">Credential and File Extraction Activity (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>Execution from temporary paths such as\u00a0<code>%TEMP%<\/code>\u00a0and\u00a0<code>%APPDATA%<\/code>\u00a0should be blocked using AppLocker or Windows Defender Application Control (WDAC).<\/p>\n<p>Indicators of Compromise (IOC):-<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Value<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CharlieKirk.exe<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">File Size<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">19.58 MB<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">File Type<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Executable (PE32)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">MD5<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>598adf7491ff46f6b88d83841609b5cc<\/code><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>f56afcdfd07386ecc127aa237c1a045332e4cc5822a9bcc77994d8882f074dd1<\/code><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">First Seen in Wild<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">February 2026<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">C2 Channel<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Discord Webhook \/ Telegram Bot API<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Exfiltration Platform<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">gofile.io<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>MITRE ATT&amp;CK Mapping:-<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Tactic<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Technique ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Technique<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Discovery<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1082<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">System Information Discovery<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Discovery<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1033<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">System Owner\/User Discovery<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Credential Access<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1555.003<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Credentials from Password Stores (Web Browsers)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Credential Access<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1552.001<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Unsecured Credentials: Credentials in Files<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Collection<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1560<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Archive Collected Data<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Defense Evasion<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1202<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Indirect Command Execution (LOLBins)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Defense Evasion<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1562.001<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Impair Defenses: Disable or Modify Security Tools<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Persistence<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1053.005<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Scheduled Task\/Job: Scheduled Task<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Privilege Escalation (Conditional)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1548.002<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Abuse Elevation Control Mechanism (UAC)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Exfiltration<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1041<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exfiltration Over C2 Channel<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Exfiltration<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">T1567.002<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exfiltration to Cloud Storage<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/charliekirk-grabber-stealer-attacking-windows-systems\/\">CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/charliekirk-grabber-stealer-attacking-windows-systems\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials A new Python-based infostealer called CharlieKirk Grabber has been identified targeting Windows systems, with a focused goal of stealing stored login credentials, browser cookies, and session data. The malware is built to work as a \u201csmash-and-grab\u201d threat \u2014 it launches quickly, collects whatever sensitive data [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10840","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10840"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10840"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10840\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}