Hacking

VVS Stealer: Python Malware Steals Discord Tokens

Published  ·  3 min read

In August 2016, a new type of malware called VVS Stealer emerged. VVS Stealer (also known as VVS $\textdll$) is a Python-based information thief that specializes in capturing Discord Credentials, as well as other sensitive browser information. In April of 2022, researchers from Palo Alto Networks' Unit 42 reported that the malware had been actively marketed via Telegram as “The Ultimate Stealer” since at least that time.

Like many malware products sold as “malware as a service”, VVS Stealer is priced relatively low compared to other similarly functioning malware products, with plans starting at €10 ($12) per week. The malware was initially designed to allow users to easily create their own stealer apps with no programming background, making it an especially enticing option for inexperienced cybercriminals.

To allow it to maintain persistence on an infected machine, VVS Stealer makes a copy of itself in the Windows Startup Folder, where it will run every time the operating system starts. To trick users into thinking they have encountered a fatal error while VVS Stealer continues to run in the background collecting information from their browsers, it will pop up fake Windows Fatal Error Dialogs as a distraction to keep them from quitting the VVS Stealer Application before it has finished its collection process.

VVS Stealer is equipped with a wide range of exfiltration features, such as:
1. Extracting tokens and account information from Discord
2. Browser Data (Cookies, Passwords, Autofill Forms, History) from Chromium and Firefox-based browsers
3. An infostealing screenshot of the infected workstation

Of the list of features, the most concerning is the injection of the VVS Stealer into Discord and taking control over active Discord sessions. The VVS Stealer will terminate Discord and insert an obfuscated JavaScript payload through the use of the Chrome DevTools Protocol (CDP) that monitors user activity in real time, thereby allowing the attacker to take over an active Discord session.

Analysts believe that the VVS Stealer is the product of a French-speaking actor involved in multiple Telegram-based groups providing stolen information. It is evident that there is a high level of sophistication utilized to deploy and disguise this type of malware using a PyInstaller package.

This finding is consistent with other research that has shown how infostealers will often supply stolen administrative credentials to attackers with legitimate businesses. Attackers will use those stolen credentials to distribute malware, thereby creating a cycle of infection and secondary attack (similar to ClickFix).

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067