Hoplon InfoSec Logo

Hoplon Infosec · Threat Intelligence

Vanta Stealer Steals Browser Passwords and Gaming Accounts

BySharfunnahar Radia
Published08 Aug, 2026
Vanta Stealer Steals Browser Passwords and Gaming Accounts
Sharfunnahar Radia08 Aug, 2026

Vanta Stealer Can Drain Browser Vaults, Crypto Wallets, and Gaming Accounts in Minutes

A user downloads what looks like a harmless installer, a game cheat or a routine software update. The file opens, the computer keeps running, and nothing seems wrong. There is no ransom note, no locked screen and no obvious warning.

That quiet moment is what makes Vanta Stealer so unsettling.

While the user continues working or launches the game they just downloaded, the malware may already be searching the computer for saved passwords, browser cookies, payment details, account tokens, active sessions, gaming data, cryptocurrency files and private documents.

Security researchers at Point Wild identified Vanta Stealer as a newly analyzed Python-based information stealer packaged as a 64-bit Windows executable. It was built with PyInstaller and protected by several layers of PyArmor, making the code harder to unpack and inspect.

Vanta Stealer steals browser passwords (2)
Identified as a PyInstaller Executable (Source - Point Wild)


The malware is also modular. Its operators can update individual theft tools, including its browser extraction component, without rebuilding the entire program.

Researchers could not confirm how the analyzed sample first reached its victim. The original delivery method was not visible, but the likely routes are familiar: phishing attachments, fake software installers, cracked applications, game cheats, bogus updates, altered code repositories and malicious search advertisements.

In many cases, downloading a file alone may not trigger the infection. The user often has to open or run it. That is why fake installers, cheats and cracked software remain so effective, they persuade the victim to start the malware themselves.

For gamers, this threat becomes personal very quickly.

If you recently installed a cracked game, an unofficial launcher, a cheat, a mod from an unknown source or a file promising free skins, your accounts may be at risk even if the game opened normally and the computer still appears fine.

A Steam, Riot Games, Roblox, Minecraft or Discord account can hold years of progress, purchased items, marketplace value, saved payment methods and private conversations. Losing one is not just a minor inconvenience. It may mean losing money, digital belongings and an online identity built over years.

Vanta targets Chromium-based browsers and searches for saved passwords, cookies, stored payment information, account tokens and active login sessions. Chrome, Edge, Brave and several other browsers use Chromium, so information kept inside those profiles may be exposed.

The analysis does not confirm the same level of targeting against Firefox, so it should not be listed as a verified target without further evidence.

The phrase “browser vault” simply refers to sensitive information stored inside a browser profile. For many people, that browser is the key to almost every part of their online life. It may hold access to email, work platforms, gaming accounts, social media, online stores and financial services.

Vanta does not need to crack every password one by one. It looks in known storage locations and copies whatever it can access from the infected user’s environment. That is one reason it can move so quickly.

This does not mean browser password managers are automatically unsafe. The larger problem begins when the computer itself is compromised. Malware running inside an unlocked user session may try to access the same local data the user can already open.

Anyone who suspects an infection should treat passwords stored on that device as potentially exposed. They should be changed from a separate, trusted phone or computer not from the system that may still be infected.

A reputable standalone password manager may help users create unique passwords and separate them from the browser profile. Even then, no password manager can offer complete protection when powerful malware is already running on an unlocked device.

Passwords are only part of the risk. Vanta also collects browser cookies and session tokens.

Some of those tokens represent accounts that are already signed in. If an attacker can reuse a valid session, they may be able to enter the account without typing the password again.

In some cases, this may also avoid a new two-factor authentication prompt because the service sees the session as previously verified.

Command prompt showing successful extraction of Vanta Stealer PyInstaller files using PyInstxtractor
Source: pointwild (Researchers used PyInstxtractor to unpack the PyInstaller archive and extract main.pyc along with other Python bytecode files.)

Researchers unpacked the PyInstaller archive using PyInstxtractor, which exposed the embedded Python bytecode files. The extraction revealed main.pyc as the malware’s primary script, giving analysts a clearer path for deeper examination.

This is where many users may feel confused. They enabled 2FA and followed good security advice, yet an attacker may still find another route in. It does not mean 2FA is useless. It means the attacker may be trying to use a digital door that was already open.

Two-factor authentication still stops many account takeover attempts and should remain enabled. But after an infostealer infection, changing the password alone may not be enough. The user should also sign out of all devices, revoke active sessions and remove unfamiliar connected applications.

The analyzed Vanta sample also collected data linked to Discord, Steam, Roblox, Riot Games, Valorant, Minecraft and Telegram Desktop. It searched for Mullvad VPN configuration data as well.

The report did not confirm direct targeting of Free Fire or PUBG, so those games should not be described as verified targets.

Discord appears to receive particular attention. Vanta can collect Discord tokens and check them through the service’s API, allowing it to gather more details about the stolen account, including linked payment information, server access and user privileges.

That helps attackers decide which accounts are worth more.

A regular Discord account may be used to impersonate the victim or send malicious links to friends. An account with moderator or administrator access can be far more damaging. Attackers may use the trusted profile to post fake updates, free-skin offers, cheat downloads or malicious files across an entire server.

The first warning may not come from the computer. It may come from a friend asking why the user sent a strange download, an email reporting a login from another country, a missing in-game item or a purchase the account owner never made.

Gaming accounts are valuable because they can contain purchased items, rare skins, marketplace balances, payment methods and access to active communities. Criminals may sell them, transfer digital items, commit fraud or use them to spread malware to teammates who trust the account owner.

Crypto users face an even more serious form of loss.

Vanta searches for wallet-related files and documents that may contain seed phrases, recovery phrases, private keys, wallet configurations or other recovery material.

An infection does not automatically mean every wallet will be emptied. The attacker still needs information that gives them control of the funds. But if a valid private key or recovery phrase is stolen, the wallet may be recreated elsewhere and its assets transferred.

For a crypto user, that loss can be permanent. There may be no bank to call, no transaction to reverse and no password reset that brings the money back.

The available analysis discusses wallet files and recovery material broadly. It does not provide enough evidence to say that every specific wallet, including MetaMask or Trust Wallet, is targeted in exactly the same way.

Removing a wallet extension after the infection does not undo data theft that may already have happened.

If a seed phrase or private key may have been exposed, the safest response is to use a clean device, create a new wallet with a new recovery phrase, move the assets and stop using the old wallet credentials.

A new wallet should never be created on the suspected computer before the system has been properly cleaned or reinstalled.

Hardware wallets reduce some risks because their private keys are designed to remain on the device. They still cannot protect funds if the recovery phrase is stored in a text file, screenshot, browser note or cloud-synced document that malware can steal.

Vanta does not stop at passwords, games and crypto. It may also collect private documents, system information, screenshots, webcam images, Telegram Desktop artifacts and VPN configurations.

That makes the theft feel far more personal.

A screenshot may reveal a private conversation or an open banking page. A document may contain identity or financial information. A webcam image can make the victim feel as though someone has quietly stepped into the room without permission.

These details also give attackers context. They can see which applications are used, which accounts may be valuable and which pieces of stolen information could support fraud, identity theft, extortion or another attack.

The phrase “in minutes” does not mean Vanta defeats every security control one by one. Its speed comes from automation.

Once it starts, the malware searches known folders, gathers browser data, looks for gaming and messaging files, collects wallet material, captures screenshots and records system details. It then writes the totals into a file called Summary.txt.

That summary lets the operator judge the value of the victim without opening every stolen file. It may show how many passwords, accounts, documents or wallet-related items were collected.

Vanta then compresses the material into a ZIP archive and sends it to a predefined command-and-control endpoint through an HTTP POST request.

The archive may include a victim identifier, username, execution mode and system information.

An HTTP POST request is a normal method applications use to send information to a server. Malware can abuse it because the traffic may resemble ordinary web activity.

The report does not clearly confirm whether every part of the stolen material is encrypted during transmission.

Disconnecting the computer from the internet may interrupt the upload if it has not already finished. It cannot recover information that has already reached the attacker.

Perhaps the most troubling part is the silence.

The computer may not slow down. The screen may not flicker. The user may finish playing or working and believe the download was harmless.

The first visible sign may appear hours later as an unknown login, an unexpected password-reset email, a stolen gaming account, a suspicious Discord message or a cryptocurrency transaction the user never approved.

Other warning signs may include unfamiliar active sessions, changed recovery details, unknown processes, antivirus alerts, unexpected network uploads or messages sent from the victim’s accounts.

A slow computer, random pop-up or webcam light may raise suspicion, but none of those signs alone proves that Vanta is present. The opposite is also true: a computer that looks completely normal may still have leaked data.

Antivirus and endpoint tools may detect the malware through known hashes, suspicious processes, credential-access behavior, ZIP archive creation, unusual network traffic or malicious file activity.

Its PyInstaller packaging and PyArmor protection can make analysis and signature-based detection harder, but they do not make Vanta invisible.

A clean security scan does not prove that nothing was stolen. A modified sample may not match existing signatures, and the malware may already have completed its work before it was removed.

Discovering a possible infection can feel overwhelming, especially when several accounts may be involved. The important thing is not to panic or start changing passwords from the same computer. A calm response, taken in the right order, can still limit the damage.

Vanta Stealer execution flow from system discovery and credential collection to ZIP creation and command-and-control upload
Vanta Stealer execution flow showing system discovery, parallel data collection, ZIP archive creation and exfiltration through an HTTP POST request. (Source – Point Wild)



Anyone who thinks they might have been exposed should:

• Unplug the device from Wi-Fi, Ethernet, and any company network.

• Don’t change passwords from the suspected computer while the malware is still active.

• Use a different, trusted phone or computer to secure the affected accounts.

• Protect the main email account first, since it can often reset other passwords.

• Change passwords for accounts like banking, payment platforms, cryptocurrencies, password managers, work services, social media, gaming, and messaging.

• Use a different password for every important account.

• Log out of all active sessions and remove any unknown devices.

• Revoke any unfamiliar connected apps and check recovery settings.

• Look for unauthorized transactions, new withdrawal addresses, or changes in security settings in crypto wallets and exchanges.

• Contact banks or card providers if payment details might have been exposed.

• Tell the company’s IT or security team right away if a work device or business account was involved.

Deleting the suspicious installer isn’t enough.

Vanta may have already done more, like running extra modules, making files, or sending stolen data.

A full cleanup might need a scan of the device, checking running programs, looking for unknown browser extensions, removing unauthorized apps, reinstalling affected software, ending active sessions, and changing passwords from a clean device.

In serious cases, a full Windows reset or reinstall might be the safest choice.

This is especially true if the infection is unclear, sensitive business accounts were used, there was admin access, or cryptocurrency recovery info was on the device.

Before restoring from backups, check carefully.

Restoring the same harmful installer or infected file could bring the threat back.

The best way to stay safe starts before opening a file.

Cracked software, game cheats, unofficial launchers, unexpected attachments, and strange update requests are all high risk.

Software should only come from official sites or trusted stores.

Keep Windows, browsers, and security tools up to date.

Use unique passwords and enable 2FA.Authenticator apps or security keys are usually more secure than SMS when available.

Seed phrases and private keys should always stay offline.

They should never be saved in screenshots, plain text files, browser notes, or cloud documents.

Also, check active sessions, look for login alerts, and remove browser extensions you no longer need.

Even sponsored search results need caution.

Hackers sometimes use fake download pages placed above real ones, so always check the website address before downloading anything.

For a company, the incident might begin with one employee and one bad download, but it can go much further than that.

An employee’s browser might have sessions for email, cloud tools, internal dashboards, collaboration platforms, and VPN services.

If those are stolen, the attacker could get into systems far beyond just the original computer.

Security teams should separate affected devices, watch for unusual ZIP files or outgoing uploads, block known bad files, and review identity, cloud, VPN, and device logs.

Before wiping the system, keep evidence.

This can help find out how the malware came in, which files were used, what info was exposed, whether data left the network, and if other devices or accounts were affected.Point Wild linked the following SHA-256 hashes to the Vanta Stealer campaign:

3bff25e745707056cf4ed6428ee8aace9a1bff2fb4030e32a7c0470a34cbfa62
4bdf15157fc0067af179d11e9ad168816ce99a849fd45332482b0b88a05aeabb
5dbddac39fda06acc703c22935fa24e0b4bcdbc26624a1869fe93cd568cdb9fc
6f20836eef6496695e5f2a5fd81e7dfb8770df38fb1bf67fcf024c1261352daa
09e3ce307b2af3f94a315eba97c094d8d755b3674208cc47ceab3c1630a84ad9
026c85b97a6ddac14c9835d0580228c0a82dd82ce12d8d921c2f3067a12bbb7e
31f3e50e764a090d2dbf759e6cb5f678c5c6a3a5a96ff3a2069ffda520580e52
34a01c2429161a8711adff3495ab1dee4419511c8f45c483f50ac71205f68512
44d48b4876cc99f1781877eae9d1e22e99925079a5a8cd0d9022176f5757baaf
64d85df47edd0187462786ff290f34b080f909a5dda946fa7e83fa3f40aaa878
96cc8dc992e465f5f959c7d1481e3789067a78c83706a3dd7ba5a20eaf32b701
467c192e3aeafbac29ab272575bc76545f371a50670fb4a1cf3104dae30622e0
785d6372f397470c48faa0a9a525b91cb990d0b3ed4b6452e31d75ed179a409c
858fcd9bd05d73d2dcc1496761e2f71fd0bf75fa0ae66eeb7405f788837ec384
3349f0cf1d4f294d7d98ee12e0ce03a40740668b50e5e553d843f233a0021d36
9339c056663e9f57d4b9d34b339cd85048176b9e7d9a20958b7ba190964acd47
a71c4149bcb8a77ca755ff235e91b1e774293cf3d653aaa2c41fe943cd0848f1
aa9268a758b5333d725b4b08350ec35e05b9a86f02d65b83b2d9a51e8859b5cd
b6a7d57fb37a0d9dab8a9e1a81ac6c228fefa4375611bbdf847a775c66cf96c5

These hashes can help security teams search for known samples in antivirus consoles, EDR platforms, SIEM systems and threat intelligence services.

A hash mismatch does not prove that a device is safe. Even a small change to the malware can create a completely different hash.

The real danger of Vanta Stealer is not one extraordinary trick. It is the amount of trust people place in a single computer.

Passwords, gaming accounts, work sessions, private files, payment details and crypto recovery information often sit side by side on the same device. Once that device is compromised, the attacker does not need to break into each part of the victim’s digital life separately. The malware collects the pieces for them.

That is why deleting the infected file is only the beginning. The computer must be cleaned, but the accounts, sessions and information connected to it also need attention.

For the victim, recovery is not simply about fixing a machine. It is about taking back control of a digital life that may have been quietly exposed.

Concerned that an infostealer may have exposed your business accounts or employee devices? Hoplon InfoSec can help assess the risk, contain the threat, and guide your recovery without disrupting normal operations.

 

Was this useful?

React, leave a note, or share it forward.

Leave a note

Share this article

Share this :

03Latest posts

Free · Weekly · No noise

Get the threats that matter, before they reach you.

One short email a week with the breaches, zero-days, and fixes worth your attention — written in plain English, no fear-mongering.