216.73.216.6

VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion

· Published 20/01/2026 17:02 · Modified 20/01/2026 19:15

Export JSON

Essential information

Published
20/01/2026 17:02
Modified
20/01/2026 19:15
Tags
2026-01-02 2026-01-20 aes encryption browser data theft discord encryption infostealer obfuscation persistence pyarmor python vvs stealer webhook
Related entities
3 observables, 12 techniques (mitre)

Description

This analysis examines the , a -based malware targeting users to steal sensitive information like credentials and tokens. The stealer employs for , hindering analysis and detection. Key capabilities include exfiltrating data, injecting malicious code into processes, extracting web browser data, achieving , and displaying fake error messages. The malware uses AES-128-CTR and leverages webhooks for data exfiltration. Advanced techniques like 's BCC mode and string are detailed. The analysis demonstrates how legitimate tools can be misused to create stealthy malware, highlighting the need for improved defenses against credential theft and account abuse.

External references