HomeSecurityNitroHack malware: Distributed via Discord

NitroHack malware: Distributed via Discord

New malware is being distributed that pretends to be a scam offering you the premium Discord Nitro service for free, but instead steals user tokens stored in various browsers, credit card information, and then tries to spread it to others.

Discord

An open platform like Discord that makes it easy to modify the JavaScript files used by the client is used by threat actors to convince the user to perform a malicious action/modification.

These modifications help the NitroHack malware steal a user's Discord user tokens, steal stored credit cards , and spread the malware to your friends via Discord DMs.

Malware turns Discord client into trojan

Last week, MalwareHunterTeam detected a new malware called NitroHack, which modifies the Windows Discord client to turn it into an account-stealing Trojan.

This malware is distributed to friends of infected users via Discord DM messages that promote it as a way to get the premium Discord Nitro service for free.

NitroHack malware: Distributed via Discord

If a user downloads the promoted file and launches it, NitroHack will modify the file %AppData%\\Discord\0.0.306\modules\discord_voice\index.js and add malicious code to the bottom.

To see what has changed, below is the original discord_voice\index.js file and the maliciously modified version.

Discord
Original Archive
Discord
Maliciously modified version

Using these stolen user tokens, the threat actor can then log in to Discord as the victim.

To steal these tokens, NitroHack will copy browser databases for Chrome, Discord, Opera, Brave, Yandex Browser, Vivaldi, and Chromium and scan them for Discord tokens. When it's done, the list of tokens found will be published to a Discord channel under the attacker's control.

How to check if your Discord client is infected

If you are concerned that you may have been infected, you can open %AppData%\\Discord\0.0.306\modules\discord_voice\index.js with Notepad and make sure there are no modifications at the end of the file.

A normal, unmodified file will end with the following line:

NitroHack malware: Distributed via Discord

If your client has anything else after this and you haven't made any intentional modifications, your client is probably infected.

The only way to remove NitroHack is to uninstall the Discord program and reinstall it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS