PyArmor Obfuscation as a Method to Hinder Static and Signature-Based Analysis
ID: 8e8ae267-f4d8-575e-a04d-7b9a6dfc14f7
STIX ID: report--8e8ae267-f4d8-575e-a04d-7b9a6dfc14f7
Feed Name: GBHackers
Threat Score
**VVS Stealer** is a Python-based infostealer actively marketed to threat actors that targets Discord users and web browsers to exfiltrate tokens, credentials, cookies, and browsing data; it is packaged with PyInstaller and heavily obfuscated using Pyarmor (BCC mode) and AES-128-CTR to hinder analysis, and it persists via Startup folder copies while exfiltrating data over Discord webhooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
