VVS Stealer is a data-theft malware family that, in its latest variant, is obfuscated with PyArmor.
Overview
VVS Stealer is a data-theft malware family that, in its latest variant, is obfuscated with PyArmor. It targets Discord data and browser-stored credentials, such as tokens and cookies, enabling account hijacking and credential theft. The use of PyArmor obfuscation signals an ongoing effort to evade detection and complicate analysis, making this a notable risk to Discord users and browser ecosystems.
Related Threat Clusters
-
VVS Stealer Malware Targets Discord Accounts with Python Code
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…
7 articles · Updated January 5, 2026
Recent Intelligence Reports
- Pyarmor-obfuscated VVS Stealer targets Discord, browser data — Scworld · January 5, 2026