TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
TWEAKOS Stealer (TL-2026-2715) is a medium-severity malware campaign, first published 2026-09-27. It has no confirmed attribution, affects Discord Inc. Discord Desktop/Web Client (local authentication token, maps to 10 MITRE ATT&CK techniques (T1005, T1036, T1056), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2715
- Threat ID
- TL-2026-2715
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in TWEAKOS Stealer
Malware and tooling: TWEAKOS, telegram, Telegram Bot API, Telethon
TWEAKOS is a two-component Python malware ecosystem uncovered by Flare after its source code leaked on Pastebin: a Windows stealer that harvests Discord authentication tokens and hijacks Telegram accounts via a Telethon-scripted login flow, feeding a same-process Telegram bot that lists, prices, and sells the stolen accounts for Telegram Stars.
How TWEAKOS Stealer works
TWEAKOS surfaced on 2026-09-24 when Flare's dark-web/Pastebin monitoring flagged a post containing the Python source of a Windows stealer, along with a hardcoded Telegram bot token and two hardcoded operator (admin) Telegram IDs. Pivoting on that bot token and admin-ID pair across Flare's platform surfaced a second, substantially larger Python component (v2) that reuses the identical credentials -- a long-lived Telegram bot process that functions simultaneously as the malware's command-and-control channel and as a stolen-account storefront, backed by a SQLite database (tweakos_data.db) tracking victims, products, buyers, orders, and operator actions.
The stealer (v1) targets two distinct classes of accounts. For Discord, it scans the Local Storage LevelDB directories (.log/.ldb files) used by the standard Discord client, the Discord PTB/canary build, and Chrome's default profile, applying regex matching -- including a pattern for tokens beginning with "mfa." -- to locate authentication tokens. Each candidate token is validated against the live Discord API endpoint discord.com/api/v9/users/@me; only tokens that return HTTP 200 are exfiltrated, bundled with the associated account's user tag. For Telegram, the stealer uses the Telethon client library to interactively walk a victim through account takeover: it prompts for a phone number, a login code, and -- if enabled -- the account's cloud (two-step) password, inspecting password state via a GetPasswordRequest() call. This produces a fresh, fully authorized Telegram session without ever changing the victim's actual password, which the source code's own comments acknowledge ("the code may generate a new password string when none exists, but it never actually changes the account password"). The resulting {phone}.session file is located on disk and exfiltrated via separate sendMessage/sendDocument calls to the two hardcoded admin Telegram IDs.
Persistence is minimal and user-scoped: the frozen-executable build copies itself to the Startup folder as SystemHelper.exe (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\), while the script-mode build instead writes a SystemHelper value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run -- neither requires administrator privileges. A referenced but unrecovered follow-on payload, WindowsSecurityChecker.exe, is invoked in code with the lure caption "Critical security update. Run it," though its actual functionality could not be confirmed. Operators can also trigger a per-victim blocker_{uid}.vbs script that raises a vbSystemModal Russian-language pop-up ("VASH KOMPYUTER ZABLOKIROVAN!" -- "YOUR COMPUTER IS BLOCKED!") directing the victim to a discord.gg/tweakos invite link, which Flare found invalid/expired during analysis.
The v2 bot backend closes the loop into a functioning criminal marketplace: stolen Telegram and Discord accounts are listed as products priced in Telegram Stars, with an automatic get_current_price() decay function applying a 5%-per-day discount capped at 70% off and floored at a 1-Star minimum -- an explicit acknowledgment that stolen-credential value decays with age. Flare notes this is the first documented case of a stealer and its own storefront operating inside the same bot process and token. However, the researchers also identified a runtime gap: the stealer's exfiltration messages and the bot's product-ingestion handler use different message formats and field-naming conventions, so the recovered code does not by itself prove that every stolen credential reliably becomes a marketplace listing -- some compromised accounts may reach the operators without appearing in tweakos_data.db. No CVE applies (this is credential-theft malware and its associated marketplace infrastructure, not a software vulnerability), no confirmed threat-actor attribution exists, and the initial delivery/infection vector and victim count remain unknown. Whether the exposed Telegram bot backend is still operational was not confirmed by Flare at publication.
MITRE ATT&CK techniques used in TL-2026-2715
Collection
Defense Evasion
Credential Access
T1056 Input Capture; T1528 Steal Application Access Token; T1555 Credentials from Password Stores
Command and Control
T1071 Application Layer Protocol
Persistence
T1547 Boot or Logon Autostart Execution
Resource Development
T1585 Establish Accounts; T1587 Develop Capabilities
Impact
Affected products and versions in TWEAKOS Stealer
- Discord Inc. — Discord Desktop/Web Client (local authentication token storage)
Vulnerable versions: Not a software vulnerability -- the client's local-storage token persistence is abused, not exploited
Fixed in: N/A - Telegram FZ-LLC — Telegram (phone/login-code/cloud-password authentication flow, scripted via the Telethon MTProto client library)
Vulnerable versions: Not a software vulnerability -- the standard account-login flow is socially engineered/scripted, not exploited
Fixed in: N/A
Remediation for TWEAKOS Stealer
Immediate actions
- Invalidate/terminate all active Telegram sessions for any account suspected of exposure (Settings > Devices > Terminate All Other Sessions)
- Revoke exposed Discord authentication tokens by changing the Discord account password, which invalidates previously issued tokens
- Remove SystemHelper.exe from the Startup folder and delete the corresponding HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemHelper registry value if present
- Treat any unsolicited request for a Telegram login code or cloud (two-step) password as malicious and refuse to share it, per Flare's own guidance
Workarounds
- Avoid running unverified Python scripts or 'security checker' utilities claiming to fix or update Discord/Telegram
- Train users that legitimate Telegram or Discord support never requests a login code or a cloud/two-step password
Longer-term hardening
- Enable Telegram two-step verification (cloud password) and Discord multi-factor authentication on all accounts
- Monitor endpoint telemetry for processes reading Discord/Discord PTB/Chrome Local Storage LevelDB directories followed by outbound requests to discord.com/api/v9/users/@me
- Monitor for outbound HTTPS traffic to api.telegram.org (sendMessage/sendDocument) correlated with creation of new .session files on the host
- Alert on creation of files matching {phone}.session or session_{uid}.session naming patterns outside a legitimate Telegram Desktop installation
Timeline of TWEAKOS Stealer
- Researchers test the discord.gg/tweakos invite link referenced in the blocker_{uid}.vbs coercion script and find it invalid/expired, leaving the operational status of the Telegram bot backend unconfirmed.
- Flare completes analysis of both components, documenting the Discord token-theft flow, the Telethon-based Telegram session-hijacking flow, the tweakos_data.db marketplace schema, and the shared-infrastructure evidence linking the two components.
- Flare pivots on the exposed Telegram bot token and admin IDs across its platform, surfacing a second, substantially larger Python component (v2) that shares the identical bot token and admin IDs -- the marketplace/C2 backend.
- TWEAKOS v1 stealer source code is posted to Pastebin, exposing a hardcoded Telegram bot token and two hardcoded admin IDs; Flare's monitoring flags the post as high severity.
- Security Boulevard, Cyberpress, Cryptika Cybersecurity, and Rankiteo republish/summarize the Flare research, widening coverage of the TWEAKOS stealer and marketplace.
- Flare publishes its research as 'TWEAKOS Uncovered: A Telegram-Driven Stealer and C2 Ecosystem for Discord and Telegram Tokens,' and Cyber Security News publishes independent coverage of the findings.
- TWEAKOS coverage is included in the 'This Week in 4n6' weekly digital-forensics community roundup for week 39 of 2026.
Sources cited for TWEAKOS Stealer
- TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- TWEAKOS Uncovered: A Telegram-Driven Stealer and C2 Ecosystem for Discord and Telegram Tokens
- TWEAKOS Uncovered: A Telegram-Driven Stealer and C2 Ecosystem for Discord and Telegram Tokens
- TWEAKOS Stealer Uses Telegram Bot C2 to Harvest Discord Tokens and Session Data
- TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- Telegram: TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
- Week 39 - 2026
More in malware
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments
Detection coverage for TL-2026-2715
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2715 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.