Vanta Stealer: Python Malware That Collects Your Entire Digital Life Like a Compulsive Hoarder
Point Wild Threat Intelligence dissects Vanta Stealer, a Python-based cross-platform information-stealing malware packaged with PyInstaller and protected by multiple layers of PyArmor obfuscation. The malware targets a broad range of applications including Chromium browsers, Discord, Telegram, Steam, cryptocurrency wallets, and more, harvesting credentials, tokens, payment data, screenshots, and sensitive documents. The analysis walks through the attack chain, PyInstaller archive extraction, PyArmor deobfuscation using PyArmor Static Unpack, and the malware's modular execution flow. The findings highlight an emerging trend of Python malware adopting commercial code-protection technologies to hinder reverse engineering.