It takes your saved passwords, your Wi-Fi key and your child's Roblox session
Two items on this stealer's shopping list stand out, because most of them do not bother with either: the password to your home Wi-Fi, and Roblox session cookies.
K7 Security Labs took apart a nested archive found inside a file with the almost charming name "my new program called 2.rar", and what was in it is not quite malware. It is a factory. TokenGrabberBuilder lets someone type in a Discord or Telegram address where they would like the stolen data delivered, press a button, and receive a Windows program of their very own, compiled with Nuitka or PyInstaller so that it turns up looking like any ordinary .exe.
The program it builds works through 17 Chromium-based browsers, Chrome, Edge, Brave and the rest, plus Firefox, and calls on Windows' own data protection functions to unseal the saved passwords, card details, browsing history and session cookies inside them. Then it collects Discord tokens, Roblox cookies, the stored Wi-Fi profiles complete with their keys, and a sketch of the machine down to its timezone and rough location. It arranges to start twice over: a registry entry under Run named WindowsUpdate, and a scheduled task that fires at logon.
Because every operator builds their own, no two copies look alike, which is the whole point and why checking files against a list of known bad ones does so poorly here. All of it still depends on somebody opening an archive and running what is inside, and archives like these circulate as game cheats, cracked software and, well, somebody's new program. If you think one was opened on your PC, change the Wi-Fi password along with everything else, and Tendvane's network scan will show you what is actually connected to that network afterwards.