VVS Stealer, a new python malware steals Discord credentials
ID: f9fe8392-c7ce-50e7-b887-531758ed9766
STIX ID: report--f9fe8392-c7ce-50e7-b887-531758ed9766
Feed Name: Security Affairs
Threat Score
**VVS Stealer** is a Python-based infostealer sold via Telegram (since at least April 2025) that uses PyInstaller and heavy Pyarmor obfuscation to steal Discord credentials/tokens, browser passwords, cookies, and other system data, hijack sessions via injected JavaScript, maintain persistence, and exfiltrate data through Discord webhooks; Palo Alto Networks researchers deobfuscated and analyzed samples to reveal these capabilities and the malware's technical details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
