HomeSecurityDiscord is increasingly being used to distribute malware

Discord is increasingly being used to distribute malware

Discord is increasingly being used for malicious activity by hackers and APT groups , to distribute malware , steal data , and steal authentication tokens.

Discord malware

A new report from Trellix explains that the platform is now also being used by APT hackers, who are abusing Discord to target critical infrastructure.

And unfortunately, Discord has failed to implement effective measures, so far, to deter cybercriminals and decisively address the problem.

Discord is being used to distribute malware

Threat actors abuse Discord in three ways: leveraging the content delivery network (CDN) to distribute malware, modifying the Discord client to steal passwords, and abusing Discord's webhooks to steal data from the victim's system.

See also: Lumma Stealer distributed via Discord CDN

Discord's CDN is commonly used to deliver malicious payloads to the computer , helping attackers evade AV detection as the files are sent from the trusted domain "cdn.discordapp.com".

According to Trellix, at least 10,000 malware samples use the Discord CDN to load second-stage payloads onto systems.

The second-stage payloads received via Discord's CDN are mainly the RedLine stealer, Vidar, AgentTesla, zgRAT, and Raccoon stealer.

Regarding the misuse of Discord webhooks for data theft, Trellix reports the following 17 malware that have been used since August 2021:

  • MercurialGrabber
  • AgentTesla
  • UmbralStealer
  • Stealerium
  • Sorano
  • zgRAT
  • SectopRAT
  • NjRAT
  • Caliber44Stealer
  • InvictaStealer
  • StormKitty
  • TyphonStealer
  • DarkComet
  • VenomRAT
  • GodStealer
  • NanocoreRAT
  • GrowtopiaStealer

This malware collects credentials, browser cookies, cryptocurrency wallets, and other data from infected systems and then uploads them to a Discord server controlled by the attackers using a webhook. The attackers can then collect the stolen data.

See also: AI algorithm detects MitM attacks on military vehicles

The biggest “offenders” for 2023 are, so far, Agent Tesla, UmbralStealer, Stealerium, and zgRAT.

Discord is increasingly being used to distribute malware

Like Discord's CDN, webhooks give cybercriminals the ability to steal datawithout being detected by network monitoring tools.

Additionally, webhooks are easy to set up and use with minimal coding knowledge, while allowing for real-time export and are cost-effective.

APT hacking groups turn to Discord

Trellix now says that sophisticated threat are starting to use Discord.

Researchers highlighted a case where an APT group targeted critical infrastructure in Ukraine using spear-phishing.

The malicious emails contain a OneNote pretending to come from a non-profit organization in Ukraine. It contains an embedded button that triggers the execution of VBS code when clicked.

The code decrypts a series of scripts that establish communication with a GitHub repository to download the final payload, which leverages Discord's webhooks to extract data.

“APT groups are known for their sophisticated and targeted attacks, and by infiltrating widely used communication platforms like Discord, they can effectively establish long-term footholds within networks, compromising critical infrastructure and sensitive data,” says Trellix.

See also: RomCom backdoor targeted participants of the Women Political Leaders (WPL) Summit

Unfortunately, the platform's popularity and encrypted data exchange combined with increasingly sophisticated threats and the fact that the features being abused serve legitimate purposes for most users, make it nearly impossible for Discord to discern malicious behavior.

Also, blocking suspicious accounts does not prevent malicious actors from creating new ones and continuing their activities. Therefore, abuse of Discord will likely continue, and attacks may become even more sophisticated.

Discord 's ongoing struggle with malware attacks

Discord is trying to address this threat. It implements strict policies to prevent malicious activity on platform , but unfortunately it's not enough. 

However, identifying and combating malware is an ongoing effort. Continuous improvement of detection, validation and response mechanisms is needed so that the platform remains one step ahead of cybercriminals. Discord, like all other online communication services, is targeted by malicious users. The effort on the part of the platforms is only one side of the issue. It is also vital that users themselves take responsibility for their security, by better controlling their sources, avoiding opening suspicious messages, attachments and links, and keeping their systems protected.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS