Netskope Threat Labs

Doenerium

ATP Sandbox Adv. HeuristicsAV

Doenerium is an open source token stealer and information grabber that targets Discord tokens, browser credentials, and other data on infected systems. Its source code is freely available, which has produced many forks and modified variants distributed through phishing links, malicious npm packages, and gaming communities. Once it runs, it collects session tokens, passwords, and wallet data and sends them to criminal endpoints such as Discord webhooks.

First seen
February 2024
Last seen
October 2026
Alert Name
Generic.JS.Doenerium.A.00032675
Generic.JS.Doenerium.A.0020FC0C
Generic.JS.Doenerium.A.04BD3BA2
Generic.JS.Doenerium.A.053B4E61
Generic.JS.Doenerium.A.09250E64
Generic.JS.Doenerium.A.09441995
Generic.JS.Doenerium.A.0CA06AD3
Generic.JS.Doenerium.A.0D1CB8CC
Generic.JS.Doenerium.A.0D28F7CC
Generic.JS.Doenerium.A.0F79EE0C