Hackers Are Pushing Malware Using Discord

Researchers working with digital security firms RiskIQ and Check Point independently discovered that threat actors have ramped up their use of the Discord platform to distribute malicious software, primarily remote access trojans or RATs.

This is not the first time Discord's legitimate features intended for normal use have been abused by hackers. The Discord platform is a communication service that includes voice and video chat, as well as organized servers and channels or rooms used for text chat. Discord also has its own storage servers and allows users to attach files in chats and channels, and those files are hosted using the Discord content delivery network or CDN.

It is this component of the service that bad actors have been actively using to store and distribute malware. The research team at RiskIQ counted as many as 27 different families of malware being delivered through Discord's CDN. Malicious files being stored on the Discord CDN include executables, DLLs and different document and archive files.

The types of malicious files being distributed in the sampling examined by the research team included trojans, backdoors and password stealers.

The examination of this issue was largely prompted by the increasing popularity of Discord. Even though the service started largely as an alternative to Teamspeak and was mostly a voice-chat service for gamers, it has evolved significantly since its inception and is now used by over 350 million people all over the world.

This body of users now also includes companies and organizations that have opted to use Discord as their "in-house" communication medium. This means that consequently those systems are also potentially exposed to this malware. While the damage for a home user may not be dramatic or significant, in the grand scheme of things, a password stealer landing on a networked machine in an organization has much bigger implications when it comes to security.

As RiskIQ highlighted in their report, the trend of threat actors using legitimate CDN or cloud hosting services to store and distribute their malware is an ongoing issue that is not showing any signs of slowing down.

October 25, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.