<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps" -->

---
title: What this &quot;VR Chat Modded&quot; experience is really doing?
description: A security researcher walks through a Discord-based social engineering scam targeting VRChat/ChilloutVR players, where a scammer builds rapport via voice call...
canonical: https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: What this &quot;VR Chat Modded&quot; experience is really doing? | daily.dev
og:description: A security researcher walks through a Discord-based social engineering scam targeting VRChat/ChilloutVR players, where a scammer builds rapport via voice call...
og:url: https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps
og:image: https://api.daily.dev/og/posts/4q21ZIVpS.png
og:image:alt: What this &quot;VR Chat Modded&quot; experience is really doing?
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# What this "VR Chat Modded" experience is really doing?

**[Eric Parker](https://daily.dev/sources/ericparker)** · 11 min read · 0 upvotes · 0 comments

## Summary

A security researcher walks through a Discord-based social engineering scam targeting VRChat/ChilloutVR players, where a scammer builds rapport via voice call before convincing the victim to download a fake mod pack. The video traces the malware chain from a low-effort, likely AI-generated website through a PowerShell dropper, anti-analysis checks, and a crypto-wallet-targeting infostealer (dubbed 'BTW stealer') that exfiltrates data via the GoFile API. Despite polished social engineering, the malware itself is sloppy, unobfuscated, and inconsistent in behavior, illustrating that attackers don't need sophisticated malware to succeed, just working malware and effective manipulation.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=nJhkRO-WOng>

## Questions this post answers

### How does the VRChat mod scam on Discord actually work?

Scammers build trust through voice calls, sometimes posing as a friendly gamer, then convince the target to download a fake mod pack from a poorly made website. The download is disguised as a ChilloutVR or VRChat mod installer that actually runs a PowerShell-based infostealer, which installs dependencies like PyCryptodome, checks for running crypto wallets, and exfiltrates stolen data via the GoFile API.

_daily.dev surfaces security writeups like this for developers tracking social engineering and malware trends._

### What does the BTW stealer malware do once executed on a victim's machine?

It extracts itself into a folder, installs Python dependencies including PyCryptodome, runs anti-analysis checks such as screen resolution detection, scans for running crypto wallet processes, logs activity to Discord, and zips stolen data before uploading it to GoFile via its API. The malware is unobfuscated and inconsistent, sometimes failing to run reliably or losing persistence after reboot.

_Track emerging infostealer behavior on daily.dev to spot patterns before they hit your own systems._

### Why do malware scams still target Mac users even when the game isn't available on Mac?

Fake 'macOS coming soon' decoys have appeared in social engineering scams since at least 2019, predating current AI-driven scam techniques, and persist even when illogical, such as a VRChat mod scam including a Mac option despite VRChat never having been released on Mac. The exact motivation remains unclear even to researchers who have tracked this pattern for years.

_daily.dev helps security-minded developers spot recurring scam patterns across gaming and social platforms._

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#discord](https://daily.dev/tags/discord)

[View this post on daily.dev](https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"What this \"VR Chat Modded\" experience is really doing?","url":"https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps"},"datePublished":"2026-09-01T15:23:21.119Z","dateModified":"2026-09-01T15:23:47.554Z","description":"A security researcher walks through a Discord-based social engineering scam targeting VRChat/ChilloutVR players, where a scammer builds rapport via voice call...","image":"https://i.ytimg.com/vi/nJhkRO-WOng/sddefault.jpg","thumbnailUrl":"https://i.ytimg.com/vi/nJhkRO-WOng/sddefault.jpg","isAccessibleForFree":true,"articleSection":"Eric Parker","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Eric Parker","logo":"https://media.daily.dev/image/upload/s--vVcOpkjx--/f_auto/v1724391603/logos/ericparker","url":"https://daily.dev/sources/ericparker"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,discord","timeRequired":"PT11M","video":{"@type":"VideoObject","name":"What this \"VR Chat Modded\" experience is really doing?","description":"A security researcher walks through a Discord-based social engineering scam targeting VRChat/ChilloutVR players, where a scammer builds rapport via voice call...","thumbnailUrl":"https://i.ytimg.com/vi/nJhkRO-WOng/sddefault.jpg","uploadDate":"2026-09-01T15:23:21.119Z","duration":"PT11M","url":"https://api.daily.dev/r/4q21ZIVpS","embedUrl":"https://www.youtube.com/embed/nJhkRO-WOng"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Eric Parker","item":"https://daily.dev/sources/ericparker"},{"@type":"ListItem","position":3,"name":"What this \"VR Chat Modded\" experience is really doing?"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/what-this-vr-chat-modded-experience-is-really-doing--4q21zivps#faq","mainEntity":[{"@type":"Question","name":"How does the VRChat mod scam on Discord actually work?","acceptedAnswer":{"@type":"Answer","text":"Scammers build trust through voice calls, sometimes posing as a friendly gamer, then convince the target to download a fake mod pack from a poorly made website. The download is disguised as a ChilloutVR or VRChat mod installer that actually runs a PowerShell-based infostealer, which installs dependencies like PyCryptodome, checks for running crypto wallets, and exfiltrates stolen data via the GoFile API. daily.dev surfaces security writeups like this for developers tracking social engineering and malware trends."}},{"@type":"Question","name":"What does the BTW stealer malware do once executed on a victim's machine?","acceptedAnswer":{"@type":"Answer","text":"It extracts itself into a folder, installs Python dependencies including PyCryptodome, runs anti-analysis checks such as screen resolution detection, scans for running crypto wallet processes, logs activity to Discord, and zips stolen data before uploading it to GoFile via its API. The malware is unobfuscated and inconsistent, sometimes failing to run reliably or losing persistence after reboot. Track emerging infostealer behavior on daily.dev to spot patterns before they hit your own systems."}},{"@type":"Question","name":"Why do malware scams still target Mac users even when the game isn't available on Mac?","acceptedAnswer":{"@type":"Answer","text":"Fake 'macOS coming soon' decoys have appeared in social engineering scams since at least 2019, predating current AI-driven scam techniques, and persist even when illogical, such as a VRChat mod scam including a Mac option despite VRChat never having been released on Mac. The exact motivation remains unclear even to researchers who have tracked this pattern for years. daily.dev helps security-minded developers spot recurring scam patterns across gaming and social platforms."}}]}
```

