breach
Published 2026-09-24
Verified 2026-09-27

TWEAKOS (Flare): Windows Discord/Telegram stealer + in-bot Stars storefront — first documented stealer-shop same process

Flare Research (blog dated 24 September 2026; Cyber Security News amplify 25 Sep) documents TWEAKOS, a Telegram-native credential theft and monetization workflow recovered after source appeared on Pastebin. Two co-designed Python components share one bot token and admin IDs: a Windows-oriented stealer that persists via Startup / user Run key (no admin needed), harvests Discord tokens from Discord / Discord PTB / Chrome default-profile LevelDB (.log/.ldb), validates them against Discord’s API, drives an interactive Telethon sign-in to mint a fresh Telegram .session, and exfils validated tokens/sessions to hardcoded admin IDs; plus a single-process Telegram bot backend (SQLite) that inventories victims/products/orders and sells “telegram” and “discord” accounts under the TWEAKOS brand with 5%/day time-decay pricing settled in Telegram Stars. Flare assesses this as the first documented case of a stealer and its own storefront running inside the same bot process. Delivery lure and victim count unknown; bot reachability at disclosure not confirmed. No CVE. Distinct from RemControl / Psychedelic Stealer desk cards. Primary: Flare; wire: Cyber Security News 25 Sep 2026.

Product
n/a (Windows Discord/Telegram credential stealer + Telegram bot shop)
Versions
n/a
Exploited in Australia?
unknown
Patch to
Hunt Startup-folder / user Run persistence dropping Python stealers; alert on Telethon session creation and Discord token validation bursts; revoke Discord tokens and Telegram sessions after suspected compromise; monitor Telegram bot commerce patterns if Stars settlement is in scope for your threat model.

Primary: Flare Research — TWEAKOS stealer + Telegram Stars storefront (24 Sep 2026) · Vendor: Flare (research primary) · Cyber Security News — TWEAKOS amplify (25 Sep 2026)

breaches identity