CharlieKirk Grabber, also known as KirkG, is a Python-based Windows infostealer first observed in the wild in February 2026. Packaged into standalone executables using PyInstaller, it uses a modular builder that lets operators select collection features and configure Discord webhooks or Telegram bots. Distribution mechanisms include phishing emails, cracked software, game-cheat downloads, and social-media lures.
The malware performs rapid, concurrent data collection under the logged-in user's context. It profiles the host and network environment, forcibly terminates browsers to unlock their databases, and steals passwords, cookies, autofill data, and browsing history from Chromium- and Firefox-based browsers. It decrypts stored browser credentials, retrieves saved Wi-Fi passwords through native Windows utilities, and collects Discord authentication tokens and account details. Additional collection includes desktop screenshots, Minecraft session files, and Steam session data, enabling credential compromise and session hijacking.
Collected information is staged locally and compressed into a ZIP archive. The archive is uploaded to GoFile, and its download link is sent to the operator through a configured Discord webhook or Telegram bot over HTTPS. The malware then deletes its staging directory and archive. Silent execution, suppressed subprocess windows, and use of legitimate Windows utilities support its short-lived, smash-and-grab behavior rather than sustained remote control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware collects: Minecraft Session Files: Steam Session Data: These files may enable account hijacking without requiring password re-entry.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer family mentioned as active in the wild.
Information-stealing malware family mentioned as active in the wild; specific capabilities not detailed in the provided content beyond being a stealer/grabber.
Open-sourced infostealer intended to harvest sensitive information/credentials from infected hosts.
Python-based Windows infostealer packaged as a PyInstaller-built executable. It rapidly collects credentials and session data (browser passwords/cookies/autofill/history, Wi‑Fi credentials), profiles the host (username/hostname/HW UUID/external IP), kills browser processes to access password stores, archives data to ZIP, exfiltrates to GoFile, and notifies operators via Discord webhook or Telegram bot. Uses living-off-the-land tools (TASKKILL, NETSH, SYSTEMINFO, PowerShell) and attempts to add Microsoft Defender exclusions; may attempt UAC elevation and persistence via scheduled tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.