Rising Threat: Vanta Stealer Spreads Through Cracked Software and Gaming Lures
Vanta Stealer, a Python-based information stealer, is spreading rapidly through various channels. The malware collects sensitive data from infected Windows devices, including credentials, cryptocurrency wallet data, gaming accounts, communication-platform sessions, and sensitive files.
The researchers at Point Wild Threat Intelligence found that Vanta Stealer uses layered packaging and obfuscation to make analysis more difficult and delay detection. The sample examined was a 64-bit Windows executable built with PyInstaller, which hides the malware's core logic behind multiple layers.
Vanta Stealer may be distributed through social-engineering lures, including phishing attachments, trojanized installers, cracked software, fake browser or system updates, and malvertising campaigns. Game-focused lures may be especially effective because Vanta Stealer targets Steam, Riot Games, Roblox, Minecraft, and Valorant-related data.
The malware also targets Chromium-based browsers and attempts to gather stored passwords, cookies, payment-card details, and other browser artifacts. This can expose online accounts, active sessions, and saved financial information.