HomeSecurityDiscord becomes an attack tool for distributing malware

Discord becomes an attack tool for distributing malware

A new clipboard hijacker malware is discreetly extracting cryptocurrency from gamers and streamers, exploiting trust within Discord communities.

See also: HawkSec: Discord data is for sale

Discord

The campaign is based on a malicious Windows program, distributed as a supposedly streaming or security tool. Once installed, it silently monitors the user's clipboard, waiting for them to copy a crypto wallet address.

The moment the victim pastes the address into an exchange, wallet, or payment field, the malware replaces it with an address controlled by the attacker, redirecting the funds without any visible trace. The threat actor, known as “RedLineCyber,” targets Discord servers related to gaming, gambling, and cryptocurrency streaming.

The perpetrators cultivate trusting relationships with server members, pose as tool creators, and privately send a file named Pro.exe or peeek.exe. Victims are told that the tool will help them manage or protect wallet addresses during live broadcasts, making it seem useful and not suspicious.

See also: New VVS Stealer targets Discord accounts via Python

Discord becomes an attack tool for distributing malware

Behind this friendly approach lies a targeted theft operation, capable of silently emptying transactions with a single mis-paste. CloudSEK analysts detected the activity by monitoring underground communities and Discord channels used by cybercriminals.

During these human intelligence gathering operations, researchers identified the fake persona “RedLine Solutions” and associated the malware with a Python-based executable packaged with PyInstaller.

Their analysis confirmed that the program does not work like classic information-sniffing malware, but limits its action to a single function: manipulating clipboard data related to popular cryptocurrencies. The severity of the campaign lies in the fact that it targets users exactly where human attention is most relaxed. Many streamers and frequent traders copy and paste long sequences of addresses without checking each character.

See also: Hackers steal Discord accounts via RedTiger

Discord becomes an attack tool for distributing malware

Thanks to its command-and-control-less operation and low system resource consumption, the malware can remain active for long periods of time, waiting for high-value transfers. Blockchain traces linked to the attackers’ embedded wallet addresses already show thefts of Bitcoin, Ethereum, Solana, Dogecoin, Litecoin, and Tron.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS