Malware can easily abuse Discord features to attack users

Malware
(Image credit: solarseven / Shutterstock)

Cybersecurity experts have successfully demonstrated that the features of gaming-centric messaging platform Discord can easily be abused for malicious purposes.

Researchers from Check Point Research (CPR) have spotted “early signs” of malicious actors interested in exploiting some of Discord’s most useful features to target users of the platform.

“The most prominent sign is a multi-functional malware available to anyone on Github. This malware has the capability to take screenshots, download and execute additional files, and perform keylogging – all by using the core features of Discord,” write CPR researchers Idan Shechter & Omer Ventura.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Discord claims to have 19 million active servers per week that facilitate communication between its 150 millions active users, making it an attractive target for threat actors.

Discord in discord

As they analyzed the malware, which is written in Python, CPR researchers realized that the root of the problem is the Discord API that doesn’t require any type of confirmation or approval. 

Since the API is open for everyone to use, threat actors can use it to program bots that can turn the platform’s features for malicious purposes like malware development, botnet setups, C2 communication and malicious file hosting

Talking of malicious file hosting, a Sophos research claimed that in Q2 2021 it detected 17,000 unique malware URLs in the Discord content delivery network

“Because Discord messages are encrypted, users can’t easily tell if malware is attached to their communications,” says Saryu Nayyar, CEO of security vendor Gurucul.

Bad for business

The problem however doesn’t have an easy solution, and the CPR researchers believe that preventing Discord malware can’t be done without harming the Discord community. 

“All too often, developers emphasize functionality over security, and this is an example of an exploitation that probably could have been addressed with a better software design. But the Discord platform itself has to be able to collect and analyze data in real time to look for and remediate unusual activity,” believes Nayyar.

While the CPR researchers suggest that it’s up to the users’ actions to keep their devices safe, Doug Britton, CEO of cybersecurity talent acquisition firm Haystack Solutions believes that it’s time Discord does some introspection.

“Discord is an amazing product but it needs to take a deep look at the trade off between open functionality and security. Relying on users to recognize malicious intent is not a sustainable solution and becoming a RAT gateway is bad for business,” opines Britton.

Stay safe online with the best antivirus services around

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
DDoS attack
ChatGPT security flaw could open the gate for devastating cyberattack, expert warns
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
Latest in News
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Apple Watch Ultra 2 timer
The Apple Watch is getting a sleep alarm upgrade it probably should have had 10 years ago
Nikon Z5
The Nikon Z5 II could land soon – here's what to expect from Nikon's rumored entry-level full-frame camera
Google Pixel Watch 3
Google Pixel Watches hit with delayed notifications, crashing, and performance issues following Wear OS 5.1 update
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting