New Discord malware targets NFT and crypto fans

An abstract image of digital security.
(Image credit: Shutterstock)

Researchers have shed light on an ongoing malware campaign that targets cryptocurrency enthusiasts on gaming-centric messaging platform Discord.

Discovered by cybersecurity researchers at Morphisec, the “sophisticated” campaign aims to distribute a malware strain named Babadeda.

“We know that this malware installer [Babadeda] has been used in a variety of recent campaigns to deliver information stealers, RATs [remote access trojans], and even LockBit ransomware,” share the researchers.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Worse still, the researchers observe that Babadeda uses complex obfuscation to bypass most traditional signature-based antivirus solutions.

Elaborate deception

In their breakdown of the malware, the researchers note that the infection chain begins with the threat actors phishing users interested in crypto and NFTs by sending misleading private messages, asking them to download an app in order to access new features and additional benefits. 

What makes the campaign worth paying attention to is the lengths the threat actors go to in an effort to trick victims into installing Babadeda.  

“Because the actor created a Discord bot account on the official company discord channel, they were able to successfully impersonate the channel’s official account,” note the researchers.

Furthermore, the attackers use several other measures to ensure that the delivery chain looks legitimate even to technical users. For instance, they use cybersquatting to make the URLs of the decoy websites resemble that of genuine ones, and in addition to mimic the user interface, also use SSL certificates dished out by Let’s Encrypt to lend an air of legitimacy to the deception.

Shield yourself online with the best firewall apps and services, and ensure your computers are protected with the best endpoint protection tools

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
Image depicting a hand on a scanner
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras