PyArmor - Tool

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
January 2, 2026
Last Seen
July 4, 2026

PyArmor is a tool tracked across 5 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed January 2, 2026; most recent activity July 4, 2026.

Related Threat Clusters

  • Armored Likho APT Targets Power Grids with BusySnake Stealer Malware

    A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…

    7 articles · Updated July 4, 2026
  • JDownloader Website Compromised to Distribute Malware to Users

    The JDownloader website was hacked between May 6 and May 7, 2026, to serve malicious installers for Windows and Linux users. Attackers replaced legitimate download links with malicious payloads, specifically targeting…

    11 articles · Updated May 9, 2026
  • ProxySmart Software Powers Global SIM Farm Cybercrime Operations

    Infrawatch's investigation reveals that ProxySmart, a Belarus-based software platform, is enabling the operation of 87 SIM farms across 17 countries, including 94 locations in the U.S., Europe, and South America. These…

    6 articles · Updated April 22, 2026
  • VVS Stealer Malware Targets Discord Accounts with Python Code

    VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…

    7 articles · Updated January 5, 2026
  • VVS Stealer Malware Targets Discord Users with PyArmor Obfuscation

    VVS Stealer, a Python-based malware family, has been marketed on Telegram since April 2025. This malware specifically targets Discord users to exfiltrate sensitive credentials, tokens, and browser data while utilizing…

    3 articles · Updated January 3, 2026

Recent Intelligence Reports

  • New APT Group Hits Power Grids in Three Countries with AI-Crafted Malware — Techtimes · July 4, 2026
  • JDownloader Website Supply Chain Attack: Installers Replaced with Python RAT Malware ... — Rescana · May 10, 2026
  • JDownloader site hacked to replace installers with Python RAT malware — Bleepingcomputer · May 9, 2026
  • Inside The Mobile Farm The Oem Stack Powering Us 4g 5g Proxy Networks — infrawatch.com · April 22, 2026
  • Researchers Uncover ProxySmart Software Powering 90+ SIM Farms — Infosecurity-Magazine · April 22, 2026
  • VVS Stealer: PyInstaller Malware Steals Discord Tokens — Socprime · January 5, 2026
  • VVS Stealer Uses Advanced Obfuscation to Target Discord Users — Infosecurity-Magazine · January 5, 2026
  • Pyarmor-obfuscated VVS Stealer targets Discord, browser data — Scworld · January 5, 2026

CVSS v3.1 Breakdown