logo

PyArmor Obfuscation as a Method to Hinder Static and Signature-Based Analysis

ID: 8e8ae267-f4d8-575e-a04d-7b9a6dfc14f7

STIX ID: report--8e8ae267-f4d8-575e-a04d-7b9a6dfc14f7

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**VVS Stealer** is a Python-based infostealer actively marketed to threat actors that targets Discord users and web browsers to exfiltrate tokens, credentials, cookies, and browsing data; it is packaged with PyInstaller and heavily obfuscated using Pyarmor (BCC mode) and AES-128-CTR to hinder analysis, and it persists via Startup folder copies while exfiltrating data over Discord webhooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.