HomeSecurityBeware! New TroubleGrabber Discord malware steals passwords

Beware! New TroubleGrabber Discord malware steals passwords

Security researchers at Netskope have discovered a new malware, dubbed TroubleGrabber, that steals credentials and spreads via Discord attachments. Additionally, the malware uses Discord webhooks to deliver the stolen information to its operators.

TroubleGrabber malware

According to researchers, several hacking groups are using the new information-stealing tool to target gamers on Discord servers and steal passwords and other sensitive information.

TroubleGrabber has similar capabilities to another malware, AnarchyGrabber, which infects users and is also used to collect credentials and disable two-factor authentication (2FA).

Netskope discovered the new malware in October 2020. TroubleGrabber samples (detected as Razy variants) made up over 85% of the 1,650 malware samples targeting Discord users in October.

Attack method

According to the researchers, Discord (like Github) is used to download payloads to the C:/temp folder once a victim is infected with TroubleGrabber.

The malware also uses Discord webhooks to communicate with the attackers' command-and-control (C2) server and send the stolen victims' information

Researchers say TroubleGrabber has the ability to steal a wide range of sensitive information: web browser tokens, Discord webhook tokens, web browser passwords, and system information.

TroubleGrabber itself sends this information to the attackers' Discord servers via messages, using Discord webhooks.

It is said that the group behind the creation of this infostealer is called Itroublve.

Netskope also discovered that a tutorial showing how someone can use TroubleGrabber to create and configure their own Discord servers to host the malware.

Beware! New TroubleGrabber Discord malware steals passwords

Spreading techniques

As we said above, in most cases TroubleGrabber is delivered to victims' computers with drive-by downloads via Discord attachment links.

“We identified more than 1,000 binaries distributed via drive-by download URLs with filenames that present themselves as game cheats, Discord installers, and software cracks,” Netskope researchers said.

The malware spread via Discord in 97.8% of detected infections. A small percentage of infections were transmitted via anonfiles.com and anonymousfiles.io. These are services that allow users to upload files anonymously and for free in exchange for creating a public download link.

Netskope's Thets Labs also shared TroubleGrabber IOCs (indicators of compromise) with Discord, GitHub, YouTube, Facebook ,Twitter , and Instagram (whose platforms were used in attacks) on November 10.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS