A new ransomware called “AXLocker” has been detected, which encrypts files and demands a ransom, while also stealing victims’ Discord accounts.

When someone logs into Discord with credentials , the platform sends back a user authentication token that is stored on the device. This can be used either to log in as a user or to retrieve account information using API requests.
Cybercriminals often go after these types of tokens because they give them access to accounts or allow them to misuse accounts for other malicious activities.
See also: Hive ransomware: Extorted over 100 million
As Discord has become the most popular community for NFT platforms and cryptocurrency groups, stealing a moderator token or other verified community member could allow threat actors to commit fraud and steal money.
AxLocker ransomware: A new major threat
Cyble researchers recently analyzed a sample of the new AXLoker ransomware and discovered that in addition to encrypting files , the victim's Discord tokens are also stolen.
As a ransomware, AXLoker is not particularly “sophisticated” nor does it have anything special that sets it apart from other ransomware. When executed, it targets files with specific extensions and excludes certain folders.
AXLoker uses the AES algorithm to encrypt files, but does not append any special extension to encrypted files – they appear with their regular names.
AXLoker then sends information such as victim ID, system details, and Discord tokens to the attackers' Discord channel via a webhook URL.
See also: ARCrypter ransomware: Targets organizations around the world
To steal the Discord token, AxLocker ransomware will scan the following directories to find and extract tokens using regular expressions:
- Discord\Local Storage\leveldb
- discordcanary\Local Storage\leveldb
- discordptb\leveldb
- Opera Software\Opera Stable\Local Storage\leveldb
- Google\Chrome\User Data\\Default\Local Storage\leveldb
- BraveSoftware\Brave-Browser\User Data\Default\Local Storage\leveldb
- Yandex\YandexBrowser\User Data\Default\Local Storage\leveldb
Eventually, the ransom note, informing the victim that data has been encrypted and explaining how to contact the attackers to purchase a decryption tool.
The attackers give victims 48 hours to contact them, but do not mention the ransom amount in the note.

Although the primary targets of this ransomware appear to be consumers rather than businesses, everyone should remain vigilant.
See also: CommonSpirit Health: Ransomware attack likely affects millions of Americans
If you see that AxLocker ransomware has targeted computer , urgently change your Discord password to invalidate the token stolen by the ransomware.
This won't help you recover your files, but it will stop any further damage to your accounts, data , and groups you're a part of.
Ransomware is one of the most critical cybersecurity problems on the internet and arguably the most powerful form of cybercrime plaguing organizations and individual users today. It has quickly become one of the most significant and profitable malware families among Threat Actors (TA).
More details about AxLocker ransomware can be found in Cyble's report
Source: www.bleepingcomputer.com
