logo

VVS Stealer Attacking Discord Users to Exfiltrate Credentials and Tokens

ID: e972da2f-7776-54e6-869b-6d6bc2742b58

STIX ID: report--e972da2f-7776-54e6-869b-6d6bc2742b58

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

VVS Stealer is a Python-built infostealer distributed as a PyInstaller executable and obfuscated with Pyarmor that steals Discord tokens, account and billing data, and browser-stored credentials from multiple browsers; it persists via the Windows Startup folder, injects JavaScript into Discord to monitor actions, and exfiltrates data via Discord webhooks and HTTP POSTs. The report includes technical details and IOCs (SHA-256 hash, encryption keys, fixed User-Agent, token regex) and notes active marketing on Telegram, highlighting a practical and stealthy threat to Discord users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.