logo

Mercurial Grabber Malware Builder

ID: 5c79a789-778b-5ff5-aaa0-a7940eab8365

STIX ID: report--5c79a789-778b-5ff5-aaa0-a7940eab8365

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-11-28

Date Updated: 2026-07-17

...
...

Mercurial Grabber is an open-source C# stealer builder that has been repurposed by threat actors to harvest browser credentials and cookies (Chrome, Roblox, Minecraft), Windows product keys, Discord tokens, system and geolocation details, and screenshots. The analysis documents its persistence, anti-VM/anti-debug checks, embedded SQLite and AES-GCM encryption, configurable C2 communications, MITRE ATT&CK mappings, IoCs (SHA-1/SHA-256 hashes), and recommends standard defensive measures (MFA, updates, antivirus, cautious handling of pirated software and phishing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.