Vanta Stealer — Python Infostealer Targeting Crypto Wallets
Summary
Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2026-07-28
Point Wild's Lat61 Threat Intelligence Team (researchers Prathamesh Shingare and Kedar Shashikant Pandit) published the primary technical dissection of Vanta Stealer, documenting its PyInstaller/PyArmor architecture, dynamic module retrieval, targeted data categories, exfiltration mechanism, and 20 SHA256 IOCs.
Point Wild Threat Intelligence2026-08-06
Cyberpress published a report confirming Vanta Stealer distribution through cracked software, game cheating tools, and fake software update pages, corroborating the Point Wild findings.
Cyberpress2026-08-06
Rankiteo catalogued the threat with a severity rating of 85/100, noting the malware's targeting of Discord, Telegram, Roblox, and Minecraft alongside browser passwords and cryptocurrency wallets.
Rankiteo Blog2026-08-07
PCRisk documented Vanta Stealer in its malware removal guide database, providing antivirus detection names across Avast, Combo Cleaner, Microsoft Defender, and Kaspersky, and listing suspected distribution vectors.
PCRisk2026-08-07
GBHackers reported on Vanta Stealer's use of PyArmor obfuscation, its cross-platform Python base, and its targeting of browser passwords, crypto wallets, and Discord tokens.
GBHackers2026-08-10
CyberSecurityNews reported that Vanta Stealer empties browser vaults, crypto wallets, and gaming accounts, describing its speed of data extraction on compromised Windows systems.
CyberSecurityNews2026-08-15
HackRead published coverage confirming gamers, cryptocurrency users, and web application users as the primary target demographics, and detailing the malware's harvesting of Steam, Valorant, Roblox, and Minecraft accounts alongside wallet seed phrases.
HackReadDecision Log
- #1publish⛓ pending8/15/2026, 11:03:30 PMhash: 8e3Qx3P76dKAucQ7njbKvFUzjdfvydxLZp6DCKiMkb2M
4 of 7 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 11:03:22 PM
last updated: 8/16/2026, 7:16:34 AM
avoid.net — verified advice for a post-truth world