Skip to main content

Threats Tagged 'discord'

View all threats tagged with 'discord'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: discord

Threats Tagged 'discord'

Click on any threat for detailed analysis and mitigation recommendations

Vidar, a Malware-as-a-Service infostealer first identified in 2018, continues to be distributed through phishing campaigns targeting Korea in the first half of 2026. The threat actor uses phishing emails disguised as job applications and copyright infringement notices, with attachments appearing as Word documents but actually being executables. Vidar employs a Go-based packer, uses Dead Drop Resolver technique via Telegram and Steam profiles to obtain C&C addresses, and implements anti-debugging and anti-VM techniques. The infostealer exfiltrates sensitive information including browser credentials, cookies, browsing history, cryptocurrency wallet data, Discord tokens, Telegram information, Steam data, Azure credentials, and screenshots. Configuration information is downloaded in JSON format, and data collection is performed based on received flags and additional downloaded conditions.

Join the discussion

The article exposes a sophisticated scam targeting Minecraft players through fake 'grief-free' server communities. The SugarSMP website, promising a safe gaming experience, was found to distribute malware-infected mod packs. The malware, named Spark stealer, steals sensitive data including Discord tokens, browser credentials, and crypto wallet information. The threat actors employ social engineering tactics to maintain their fake community's reputation and remove warnings about their activities. Multiple similar websites were discovered, all hosting various types of malware. The scam's persistence mechanisms and social engineering techniques are detailed, along with remediation steps for affected users.

Join the discussion
0

A sophisticated multi-stage malware campaign employs living-off-the-land techniques and in-memory payload delivery to evade security controls. The infection chain begins with a hidden batch file that executes an embedded PowerShell loader, which then injects Donut-generated shellcode into legitimate Windows processes. The final payload is a heavily obfuscated .NET framework implementing advanced anti-analysis techniques, credential harvesting, surveillance capabilities, and remote system control. Data exfiltration occurs via Discord webhooks and Telegram bots. The malware, identified as Pulsar RAT, features live chat functionality and background payload deployment, demonstrating a modern, high-evasion Windows malware operation designed for long-term access and large-scale data theft.

Join the discussion

The VVS Discord Stealer is a Python-based malware designed to exfiltrate sensitive Discord user data including credentials and tokens. It uses Pyarmor with BCC mode and AES-128-CTR encryption to heavily obfuscate its code, evading detection by static and dynamic analysis tools. The malware decrypts encrypted Discord tokens, queries Discord APIs for user information, injects malicious JavaScript into the Discord client to intercept active sessions, and extracts data from multiple web browsers. It achieves persistence by configuring itself to run at system startup and deceives victims by displaying a fake error message. While no known exploits or CVEs are reported, its capabilities pose a medium severity threat. The stealer primarily targets Windows environments where Discord and browsers are installed and relies on user interaction, likely via social engineering. European organizations with significant Discord usage, especially in technology, gaming, media, and education sectors, face risks of credential theft, unauthorized access, data leakage, and operational disruption. Detection requires behavioral and heuristic analysis due to strong obfuscation techniques.

Join the discussion

A spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism was discovered in September 2025. The attack, attributed to BlindEagle, utilized a compromised email account within the organization to bypass security controls. The campaign employed a sophisticated multi-layer attack chain, including a fake web portal, nested JavaScript and PowerShell scripts, steganography, and the deployment of Caminho as a downloader for DCRAT. The attack leveraged legal-themed lures, in-memory execution, and abuse of legitimate services like Discord. BlindEagle's evolution in tactics and use of new tools like Caminho demonstrates their ongoing threat to Colombian institutions.

Join the discussion

Arkanix Stealer is a newly discovered information-stealing malware designed for short-term financial gain. Initially developed in Python, it has evolved into a more sophisticated C++ version employing VMProtect obfuscation and a technique called 'Chrome Elevator' to bypass App Bound Encryption. It targets browsers, crypto wallets, VPN accounts, Steam accounts, and system information. Distributed primarily via Discord and online forums disguised as legitimate tools, it offers threat actors a web panel with premium features for managing stolen data. The malware demonstrates advanced capabilities and rapid evolution, highlighting the ease of launching cybercrime operations for quick profits. While no known exploits in the wild have been reported yet, its medium severity reflects the potential impact on confidentiality and financial assets. European organizations using targeted browsers, crypto wallets, or VPN services are at risk, especially those with users active on Discord or similar platforms. Mitigation requires targeted detection of obfuscated binaries, network monitoring for suspicious domains like arkanix.pw, and user education on social engineering risks. Countries with high crypto adoption and active gaming communities are more likely to be affected.

Join the discussion

Kaspersky researchers uncovered new malicious operations by the Tomiris threat actor targeting foreign ministries, intergovernmental organizations, and government entities. The attacks, which began in early 2025, show a shift in tactics with increased use of implants leveraging public services like Telegram and Discord as command-and-control servers. The group employs various programming languages including Go, Rust, C/C#/C++, and Python to develop reverse shell tools. Some infections lead to the deployment of open-source post-exploitation frameworks such as Havoc and AdaptixC2. The campaign primarily focuses on Russian-speaking users and entities, with additional targets in Central Asian countries.

Join the discussion

A family of four new remote access trojans (RATs) operated by the STD Group has been identified, leveraging Discord as their command and control (C2) channel. These RATs—Minecraft RAT, UwUdisRAT, STD RAT, and Propionanilide RAT—are written in C++ and use a ROT23 cipher to obfuscate Discord bot tokens for C2 communication. The malware has evolved from single payloads to using packers, complicating detection efforts. The RATs enable attackers to perform reconnaissance, execute commands, and maintain persistence on infected systems. Detection is supported by YARA rules and file indicators provided in the analysis. While no known exploits in the wild have been reported yet, the use of Discord for C2 is notable for evading traditional network defenses. European organizations, especially those with high Discord usage or gaming-related sectors, could be targeted. Mitigation requires enhanced monitoring of Discord traffic, endpoint detection tuned for these RAT behaviors, and restricting unauthorized Discord bot usage within corporate environments.

Join the discussion

A new Python-based Remote Access Trojan (RAT) named 'Nursultan Client' targets gamers by masquerading as a legitimate Minecraft client. It uses the Telegram Bot API for command and control, enabling attackers to capture screenshots, access webcams, steal Discord authentication tokens, open URLs, and perform system reconnaissance on Windows machines. Although it attempts persistence, its implementation has flaws. The malware's focus on Discord tokens and gaming users suggests a Malware-as-a-Service model, likely sold to other threat actors. No known exploits in the wild have been reported yet. The threat poses a medium severity risk but could escalate if customized versions improve persistence or evasion. European organizations with gaming communities or employees using Discord and Minecraft are at risk, especially in countries with high gaming engagement and Discord usage. Mitigation requires targeted detection of the fake client, monitoring Telegram API usage, and securing Discord tokens. Countries like Germany, France, the UK, and the Netherlands are most likely affected due to their large gaming populations and technology adoption. The threat is medium severity given its impact on confidentiality and moderate ease of exploitation without user interaction beyond initial infection.

Join the discussion

Inf0s3c Stealer is a sophisticated Python-based malware designed to collect system information and user data. It systematically gathers host identifiers, CPU information, network configuration, and captures screenshots. The malware enumerates running processes, generates directory views, and compiles stolen data into a password-protected archive for exfiltration. It employs various techniques for persistence, including injection into Discord and Windows Startup manipulation. The stealer targets sensitive information such as passwords, cookies, browsing history, and cryptocurrency wallets. It also implements anti-VM checks and can self-delete after execution. The analysis reveals similarities with other malware projects, suggesting potential for rapid iteration and wider distribution.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: discord
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses