Kids are earning pocket money selling malware on Discord

ID theft
Image credit: Pixabay (Image credit: Future)

A group of minors has been spotted building, advertising and selling various malware and ransomware strains on Discord, earning pocket money for themselves in the process.

Cybersecurity experts from Avast recently discovered a Discord server in which a group of hackers discussed building, upgrading and selling malware families such as Lunar, Snatch and or Rift.

After a closer inspection of the discussion, researchers concluded that the group consisted of mostly minors, as they kept mentioning their parents and teachers, as well as throwing various age-related insults at each other.

To join the group, and essentially become the user of the malware-as-a-service, one must pay a fee, which ranges from anywhere between €5 and €25. Avast says up to 100 accounts have paid to access one such group.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Trickery and deception

The group in question builds and exchanges various types of malware, including those with password-stealing capabilities, infostealers, those capable of mining various cryptocurrencies for the attackers, and in some cases, even running ransomware attacks.

When it comes to distributing the malware, the process is more-or-less the usual, with a little twist. The crooks create a YouTube video, demonstrating a crack for commercial software or a popular computer game, and include a download link for the fake crack in the description.

To help build authenticity, other members of the Discord group then add comments to the video, thanking the author for their contribution and “confirming” that the file on the download link is actually legitimate.

This, Avast claims, is a lot more sinister, compared to the usual practice of using bots to add comments, as it’s almost impossible to detect fraud when genuine accounts support a video.

Spreading ransomware, infostealers, and other malware might be an illegal, malicious practice, but with this group, in many instances, it’s all perceived as pranking, Avast concluded.

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Magnifying glass enlarging the word 'malware' in computer machine code
Microsoft Teams and AnyDesk abused to deploy dangerous malware, so be on your guard
Latest in Security
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Dark Web monitoring
A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Latest in News
Google Cloud logo
Google to acquire cloud security platform Wiz in $32 billion deal
FCC filing for the Nothing CMF Buds 2 Plus
Nothing’s next-gen CMF cheap earbuds slated to arrive within the month, but don’t expect hi-res audio support
John Loeffler holding the Ryzen 7 7800X3D
Great news! The best gaming CPU ever made is finally available for it's original MSRP again
Garmin Instinct 3
A new Garmin study hints at the link between burning calories and happiness, and I've got good and bad news
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
MacBook Air M4
Apple's rumored foldable iPad tipped to launch sooner than expected with an exciting software twist