TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace

TWEAKOS Stealer (TL-2026-2715) is a medium-severity malware campaign, first published 2026-09-27. It has no confirmed attribution, affects Discord Inc. Discord Desktop/Web Client (local authentication token, maps to 10 MITRE ATT&CK techniques (T1005, T1036, T1056), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2715

Threat ID
TL-2026-2715
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-09-27
Last reviewed
2026-09-27
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
18

Malware and tooling in TWEAKOS Stealer

Malware and tooling: TWEAKOS, telegram, Telegram Bot API, Telethon

TWEAKOS is a two-component Python malware ecosystem uncovered by Flare after its source code leaked on Pastebin: a Windows stealer that harvests Discord authentication tokens and hijacks Telegram accounts via a Telethon-scripted login flow, feeding a same-process Telegram bot that lists, prices, and sells the stolen accounts for Telegram Stars.

How TWEAKOS Stealer works

TWEAKOS surfaced on 2026-09-24 when Flare's dark-web/Pastebin monitoring flagged a post containing the Python source of a Windows stealer, along with a hardcoded Telegram bot token and two hardcoded operator (admin) Telegram IDs. Pivoting on that bot token and admin-ID pair across Flare's platform surfaced a second, substantially larger Python component (v2) that reuses the identical credentials -- a long-lived Telegram bot process that functions simultaneously as the malware's command-and-control channel and as a stolen-account storefront, backed by a SQLite database (tweakos_data.db) tracking victims, products, buyers, orders, and operator actions.

The stealer (v1) targets two distinct classes of accounts. For Discord, it scans the Local Storage LevelDB directories (.log/.ldb files) used by the standard Discord client, the Discord PTB/canary build, and Chrome's default profile, applying regex matching -- including a pattern for tokens beginning with "mfa." -- to locate authentication tokens. Each candidate token is validated against the live Discord API endpoint discord.com/api/v9/users/@me; only tokens that return HTTP 200 are exfiltrated, bundled with the associated account's user tag. For Telegram, the stealer uses the Telethon client library to interactively walk a victim through account takeover: it prompts for a phone number, a login code, and -- if enabled -- the account's cloud (two-step) password, inspecting password state via a GetPasswordRequest() call. This produces a fresh, fully authorized Telegram session without ever changing the victim's actual password, which the source code's own comments acknowledge ("the code may generate a new password string when none exists, but it never actually changes the account password"). The resulting {phone}.session file is located on disk and exfiltrated via separate sendMessage/sendDocument calls to the two hardcoded admin Telegram IDs.

Persistence is minimal and user-scoped: the frozen-executable build copies itself to the Startup folder as SystemHelper.exe (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\), while the script-mode build instead writes a SystemHelper value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run -- neither requires administrator privileges. A referenced but unrecovered follow-on payload, WindowsSecurityChecker.exe, is invoked in code with the lure caption "Critical security update. Run it," though its actual functionality could not be confirmed. Operators can also trigger a per-victim blocker_{uid}.vbs script that raises a vbSystemModal Russian-language pop-up ("VASH KOMPYUTER ZABLOKIROVAN!" -- "YOUR COMPUTER IS BLOCKED!") directing the victim to a discord.gg/tweakos invite link, which Flare found invalid/expired during analysis.

The v2 bot backend closes the loop into a functioning criminal marketplace: stolen Telegram and Discord accounts are listed as products priced in Telegram Stars, with an automatic get_current_price() decay function applying a 5%-per-day discount capped at 70% off and floored at a 1-Star minimum -- an explicit acknowledgment that stolen-credential value decays with age. Flare notes this is the first documented case of a stealer and its own storefront operating inside the same bot process and token. However, the researchers also identified a runtime gap: the stealer's exfiltration messages and the bot's product-ingestion handler use different message formats and field-naming conventions, so the recovered code does not by itself prove that every stolen credential reliably becomes a marketplace listing -- some compromised accounts may reach the operators without appearing in tweakos_data.db. No CVE applies (this is credential-theft malware and its associated marketplace infrastructure, not a software vulnerability), no confirmed threat-actor attribution exists, and the initial delivery/infection vector and victim count remain unknown. Whether the exposed Telegram bot backend is still operational was not confirmed by Flare at publication.

MITRE ATT&CK techniques used in TL-2026-2715

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading

Credential Access

T1056 Input Capture; T1528 Steal Application Access Token; T1555 Credentials from Password Stores

Command and Control

T1071 Application Layer Protocol

Persistence

T1547 Boot or Logon Autostart Execution

Resource Development

T1585 Establish Accounts; T1587 Develop Capabilities

Impact

T1657 Financial Theft

Affected products and versions in TWEAKOS Stealer

  • Discord Inc. — Discord Desktop/Web Client (local authentication token storage)
    Vulnerable versions: Not a software vulnerability -- the client's local-storage token persistence is abused, not exploited
    Fixed in: N/A
  • Telegram FZ-LLC — Telegram (phone/login-code/cloud-password authentication flow, scripted via the Telethon MTProto client library)
    Vulnerable versions: Not a software vulnerability -- the standard account-login flow is socially engineered/scripted, not exploited
    Fixed in: N/A

Remediation for TWEAKOS Stealer

Immediate actions

  • Invalidate/terminate all active Telegram sessions for any account suspected of exposure (Settings > Devices > Terminate All Other Sessions)
  • Revoke exposed Discord authentication tokens by changing the Discord account password, which invalidates previously issued tokens
  • Remove SystemHelper.exe from the Startup folder and delete the corresponding HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemHelper registry value if present
  • Treat any unsolicited request for a Telegram login code or cloud (two-step) password as malicious and refuse to share it, per Flare's own guidance

Workarounds

  • Avoid running unverified Python scripts or 'security checker' utilities claiming to fix or update Discord/Telegram
  • Train users that legitimate Telegram or Discord support never requests a login code or a cloud/two-step password

Longer-term hardening

  • Enable Telegram two-step verification (cloud password) and Discord multi-factor authentication on all accounts
  • Monitor endpoint telemetry for processes reading Discord/Discord PTB/Chrome Local Storage LevelDB directories followed by outbound requests to discord.com/api/v9/users/@me
  • Monitor for outbound HTTPS traffic to api.telegram.org (sendMessage/sendDocument) correlated with creation of new .session files on the host
  • Alert on creation of files matching {phone}.session or session_{uid}.session naming patterns outside a legitimate Telegram Desktop installation

Timeline of TWEAKOS Stealer

  • Researchers test the discord.gg/tweakos invite link referenced in the blocker_{uid}.vbs coercion script and find it invalid/expired, leaving the operational status of the Telegram bot backend unconfirmed.
  • Flare completes analysis of both components, documenting the Discord token-theft flow, the Telethon-based Telegram session-hijacking flow, the tweakos_data.db marketplace schema, and the shared-infrastructure evidence linking the two components.
  • Flare pivots on the exposed Telegram bot token and admin IDs across its platform, surfacing a second, substantially larger Python component (v2) that shares the identical bot token and admin IDs -- the marketplace/C2 backend.
  • TWEAKOS v1 stealer source code is posted to Pastebin, exposing a hardcoded Telegram bot token and two hardcoded admin IDs; Flare's monitoring flags the post as high severity.
  • Security Boulevard, Cyberpress, Cryptika Cybersecurity, and Rankiteo republish/summarize the Flare research, widening coverage of the TWEAKOS stealer and marketplace.
  • Flare publishes its research as 'TWEAKOS Uncovered: A Telegram-Driven Stealer and C2 Ecosystem for Discord and Telegram Tokens,' and Cyber Security News publishes independent coverage of the findings.
  • TWEAKOS coverage is included in the 'This Week in 4n6' weekly digital-forensics community roundup for week 39 of 2026.

Sources cited for TWEAKOS Stealer

More in malware

Detection coverage for TL-2026-2715

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2715 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats