NimGrabber

Malware type
credential-stealer, spyware
Last IoC activity
2026-04-18 00:40:53
Profile updated
2026-07-07 14:53:36

Context

Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Nimgrabber_Auto (yara-rule)

Reports & references

  • medium.com — Investigation Into The State Of Nim Malware Part 2 A28Bffffa671 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nimgrabber (report)

External references