Discord is fast becoming a favorite tool among cybercriminals

Discord Desktop Client
(Image credit: Shutterstock / Konstantin Savusia)

As people around the world turned to video games to stay occupied while under lockdown during the pandemic, cybercriminals took note and launched new campaigns with the aim of targeting gamers according to new research from Zscaler.

These attacks often exploit the popularity of certain games such as Among Us to lure players into downloading fake versions which serve malware. However, cybercriminals have also begun to deploy ransomware, credential stealers and cryptominers to target gamers as well.

One thing that many of these new campaigns share in common is the fact that cybercriminals have begun to leverage the group-chatting platform Discord as a CDN for hosting their malicious payloads. While using the service to host payloads is not new, there was an uptick in the number of cybercriminals doing so last year.

For instance, an attacker can upload a malicious file on a Discord channel and share its public link with others who use the service as well as with those that don't. Even worse, a file sent from Discord is there forever so even if an attacker deletes a file shared via the service, its link can still be used to download the malicious file.

Discord CDN

In a new report, Zscaler's ThreatLabZ team explained how its researchers have observed multiple payloads including the Epsilon ransomware, Redline stealer, XMRig miner and Discord token grabbers shared using the service.

Many of the malicious files used in these campaigns are renamed as pirated or gaming software in an effort to trick gamers into downloading them. Cybercriminals also use file icons related to popular games to entice users into opening them.

At the same time, attackers are also using Discord for command-and-control (C&C) communication as we saw last year with a new version of the AnarchyGrabber trojan. For those unfamiliar, C&C servers are remote hosts that are used to send commands to malware to be executed on an infected computer.

In their report on the matter, Zcaler's Avinash Kumar, Aditya Sharma and Abhay Kant Yadav explained how Discord's growing popularity outside of gaming and its CDN capabilities have made the service popular among cybercriminals, saying:

“Discord is primarily a chatting platform built for gamers and is becoming increasingly popular among other professional communities for sharing information. We’re observing an increase in the usage of the Discord app to deliver malicious files by attackers. Due to the static content distribution service, it is highly popular among threat actors to host malicious attachments that remain publicly accessible even after removing actual files from Discord.” 

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'