logo

VVS Stealer Uses Advanced Obfuscation to Target Discord Users

ID: cafd9183-a3e4-5f15-b5df-290b574c8930

STIX ID: report--cafd9183-a3e4-5f15-b5df-290b574c8930

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

...
...

VVS stealer is a Python-based infostealer packaged with PyInstaller and protected with Pyarmor that targets Discord users and multiple browsers to harvest tokens, account and billing details, cookies, passwords and other browser data; it establishes persistence via the Windows startup folder, injects malicious JavaScript into Discord to hijack sessions, decrypts protected payloads (AES-128-CTR tied to Pyarmor licenses), and exfiltrates consolidated archives to Discord webhooks. Palo Alto Networks' analysis shows the malware leverages legitimate obfuscation tools to hinder analysis, is actively developed, and the sample analyzed is time-limited (stops after October 31, 2026), indicating operational use and a need for heightened monitoring of credential theft and account abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.