VVS Stealer, also known as VVS $tealer, is a Python-based infostealer malware that specifically targets Discord users to exfiltrate sensitive credentials, tokens, and browser data. The malware has been actively marketed on Telegram since April 2025 and is notable for its use of PyArmor, a legitimate Python obfuscation tool, to evade static analysis and signature-based detection. By employing techniques such as bytecode encryption, BCC mode (converting Python functions into compiled C code), and AES-128 encryption in CTR mode, VVS Stealer significantly complicates reverse engineering and analysis efforts by security professionals.
Technical analyses reveal that the malware's obfuscation methods make it highly stealthy and effective, with its code protected against standard decompilers and string extraction. Security researchers have detailed the multi-step deobfuscation process required to analyze VVS Stealer, highlighting the growing trend of malware authors leveraging advanced obfuscation tools to bypass traditional security controls. Organizations are advised to employ advanced detection and prevention solutions to mitigate the risks posed by such sophisticated threats targeting popular platforms like Discord.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a detailed report on January 2, 2026 describing how VVS Stealer uses PyInstaller packaging and PyArmor obfuscation, including BCC mode and AES-128-CTR encryption, to evade analysis. The report also shared indicators of compromise such as sample hashes and Discord webhook URLs used for exfiltration.
Analysis of VVS Stealer revealed it steals Discord tokens and account data, injects malicious JavaScript into the Discord client to hijack sessions, and harvests browser cookies, passwords, history, and autofill data. The malware also establishes persistence via the Windows Startup folder, uses fake error pop-ups to distract victims, and exfiltrates stolen data through Discord webhooks and HTTP POST.
VVS Stealer, a Python-based infostealer targeting Discord users, was being sold on Telegram by at least April 2025 using low-cost subscription and lifetime-license offerings. Reporting also links its operation to French-speaking actors active in stealer-related communities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.