logo

Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens

ID: 67d2348b-f6c4-5cd4-9f3e-94ca60daedec

STIX ID: report--67d2348b-f6c4-5cd4-9f3e-94ca60daedec

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Mayura Kathir

...
...

Vanta Stealer is a modular, Python-based infostealer packed with PyInstaller and protected by layered PyArmor obfuscation; it dynamically retrieves extraction modules, enriches stolen Discord tokens via the Discord API, collects browser credentials, crypto wallets, gaming and VPN artifacts, and packages results with metadata into ZIP archives that are uploaded to a hard-coded C2, illustrating a sophisticated, maintainable commodity malware design that hampers static analysis and enables efficient operator triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.