VVS Stealer Attacking Discord Users to Exfiltrate Credentials and Tokens
ID: e972da2f-7776-54e6-869b-6d6bc2742b58
STIX ID: report--e972da2f-7776-54e6-869b-6d6bc2742b58
Feed Name: cybersecurityNews.com
VVS Stealer is a Python-built infostealer distributed as a PyInstaller executable and obfuscated with Pyarmor that steals Discord tokens, account and billing data, and browser-stored credentials from multiple browsers; it persists via the Windows Startup folder, injects JavaScript into Discord to monitor actions, and exfiltrates data via Discord webhooks and HTTP POSTs. The report includes technical details and IOCs (SHA-256 hash, encryption keys, fixed User-Agent, token regex) and notes active marketing on Telegram, highlighting a practical and stealthy threat to Discord users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
