NimGrabber
- Malware type
- credential-stealer, spyware
- Last IoC activity
- 2026-04-18 00:40:53
- Profile updated
- 2026-07-07 14:53:36
Context
Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Nimgrabber_Auto (yara-rule)
Reports & references
- medium.com — Investigation Into The State Of Nim Malware Part 2 A28Bffffa671 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nimgrabber (report)