Urgent Alert: VVS Stealer Malware Targets Discord Users Now

UPDATE: A new and dangerous malware known as VVS Stealer is actively targeting Discord users, posing an immediate threat to millions of accounts. This Python-based malware has been circulating since at least April 2025, but security experts at Palo Alto Networks have just revealed its alarming capabilities.

The VVS Stealer is designed to steal Discord tokens—digital keys that keep users logged in without a password—allowing hackers to access personal profiles, read private messages, and even pilfer billing and credit card information. With Discord being a primary communication hub for gamers, the implications of this malware are serious and widespread.

This malware operates by displaying a fake “Fatal Error” message to trick users into rebooting their systems. Once activated, it performs a Discord Injection, modifying Discord files and introducing a malicious script directly into app folders. This enables attackers to monitor user traffic, steal backup codes, and intercept login details, especially during password changes.

VVS Stealer extends its reach beyond Discord, infiltrating popular web browsers including Chrome, Edge, Brave, and Opera to extract saved passwords, cookies, and autofill data. It even takes screenshots of users’ desktops, bundling stolen information into a file named USERNAME_vault.zip, which it sends back to hackers using webhooks.

What’s particularly alarming is the commercial aspect of this malware operation. It is being sold on Telegram like a subscription service, with prices starting as low as €10 for a week, and climbing up to €199 for a lifetime license. Researchers from Deep Code have identified key operatives behind this malware, including individuals known as Rly and 93R (Rexko), indicating that these attackers have deep ties to the communities they exploit.

The version of VVS Stealer currently in circulation is programmed to expire on October 31, 2026, but it remains a very real threat until then. Users are urged to remain vigilant; if a suspicious error message appears on your screen, do not rush to restart your system. This could be an attempt by VVS Stealer to embed itself deeper into your device.

Stay informed and protect your accounts. Share this urgent warning with fellow Discord users to ensure they are aware of this emerging threat.