Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Data breach at government tech giant Conduent balloon affects millions more Americans

Fundamental raises $255 million in Series A for new big data analytics initiative

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New VVS Stealer malware targets Discord accounts via obfuscated Python code
Identity

New VVS Stealer malware targets Discord accounts via obfuscated Python code

userBy userJanuary 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 5, 2026Ravi LakshmananThreat Intelligence / Windows Security

Cybersecurity researchers have revealed details of a new Python-based information stealer called VVS Stealer (also known as VVS $tealer) that can collect Discord credentials and tokens.

Palo Alto Networks Unit 42 reports that the thief was allegedly sold on Telegram in April 2025.

“The VVS stealer code has been obfuscated by Pyarmor,” researchers Pranay Kumar Chhaparwal and Lee Wei Yeong said. “This tool is used to obfuscate Python scripts to thwart static analysis and signature-based detection. Pyarmor can be used for legitimate purposes as well as for building stealth malware.”

It’s being promoted as the “ultimate steal” on Telegram and is available for a weekly subscription of 10 euros ($11.69). You can also purchase them in different price ranges. At 20 euros ($23) per month, 40 euros ($47) per three months, 90 euros ($105) per year, or 199 euros ($232) for a perpetual license, it’s one of the cheapest products on sale.

cyber security

According to a report published by Deep Code in late April 2025, the stealer is believed to be the work of a French-speaking attacker who is also active in stealer-related Telegram groups such as Myth Stealer and Еуes Steаlеr GC.

Pyarmor-protected VVS Stealer malware is distributed as a PyInstaller package. Once launched, the stealer adds itself to the Windows startup folder and sets persistence so that it starts automatically after the system restarts.

It also displays a fake “fatal error” pop-up alert that instructs the user to restart the computer to resolve the error and steal extensive data.

Discord data (tokens and account information) Web browser data from Chromium and Firefox (cookies, history, passwords, autofill information) Screenshots

VVS Stealer is designed to perform Discord injection attacks in order to hijack active sessions on compromised devices. To accomplish this, first close the Discord application if it is already running. It then downloads an obfuscated JavaScript payload via Chrome DevTools Protocol (CDP) from a remote server responsible for monitoring network traffic.

“Malware authors are increasingly leveraging sophisticated obfuscation techniques to evade detection by cybersecurity tools, making malicious software difficult to analyze and reverse engineer,” the company said. “Python is easy to use for malware authors, and this threat uses complex obfuscation, resulting in a highly effective and stealthy malware family.”

cyber security

The disclosure was made by Hudson Rock as it details how attackers are using information thieves to siphon administrative credentials from legitimate companies and leverage their infrastructure to distribute malware through ClickFix-style campaigns, creating self-perpetuating loops.

“A significant percentage of the domains hosting these campaigns are legitimate businesses whose administrative credentials have been stolen by the very information thieves currently being distributed, rather than malicious infrastructure set up by attackers,” the company said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article50 interesting scientific facts about our incredible world
Next Article Flutterwave acquires Nigeria’s Mono in rare African fintech exit
user
  • Website

Related Posts

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

February 5, 2026

Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories

February 5, 2026

Buyer’s Guide to AI Usage Control

February 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Data breach at government tech giant Conduent balloon affects millions more Americans

Fundamental raises $255 million in Series A for new big data analytics initiative

Eleven Lab CEO: Voice is the next interface for AI

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.