logo

VVS Stealer, a new python malware steals Discord credentials

ID: f9fe8392-c7ce-50e7-b887-531758ed9766

STIX ID: report--f9fe8392-c7ce-50e7-b887-531758ed9766

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**VVS Stealer** is a Python-based infostealer sold via Telegram (since at least April 2025) that uses PyInstaller and heavy Pyarmor obfuscation to steal Discord credentials/tokens, browser passwords, cookies, and other system data, hijack sessions via injected JavaScript, maintain persistence, and exfiltrate data through Discord webhooks; Palo Alto Networks researchers deobfuscated and analyzed samples to reveal these capabilities and the malware's technical details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.