logo

VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion

ID: c1c43a1f-f8b9-509f-9ad0-d4404a387e8c

STIX ID: report--c1c43a1f-f8b9-509f-9ad0-d4404a387e8c

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2026-01-02

Date Updated: 2026-04-28

Author: Pranay Kumar Chhaparwal and Lee Wei Yeong

...
...

This report provides a technical analysis of VVS stealer (aka VVS $tealer), a Pyarmor-obfuscated Python infostealer marketed on Telegram that targets Discord users and numerous Chromium- and Firefox-based browsers to exfiltrate tokens, credentials, cookies, history and autofill data; it also injects an obfuscated JavaScript payload into the Discord Electron application to hijack sessions, achieves persistence via the Startup folder, displays a fake fatal error, and uses AES-based protections and BCC-mode compiled components to evade analysis. The analysis includes decompilation and deobfuscation methodology, cryptographic details, example IOCs (SHA-256 hashes and Discord webhook URLs), and recommended protections and incident response contacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.