PC gamers targeted in new Discord phishing scam

Discord
(Image credit: Discord)

Cybersecurity researchers have run into a new phishing campaign that is being promoted via messages on the gaming-centric messaging platform Discord.

Researchers from Malwarebytes caught wind of the campaign that promises a free Discord Nitro subscription by asking users to link to their Steam account. 

Discord Nitro is a paid membership plan on the popular Voice over IP (VoIP) and instant messaging platform, which offers several perks. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Threat actors have run phishing campaigns riding on the popularity of Discord Nitro earlier as well. However the scam is unique in that it doesn’t go after the victim’s Discord credentials. 

Using Discord Nitro as a lure, instead of handing over the signup process to the official Steam service, the fraudsters use a fake Steam login page that’s deceptively similar to the original, in order to make away with the victim’s Steam credentials.

Deceptive misdirection

Breaking down the campaign, the researchers share that the phishing scam is being conducted through several Discord accounts controlled by the threat actors, as well as through automated bots that send other users links to what is supposedly a guide on how to upgrade to Discord Nitro for free for a month.

"See, here free nitro 1 month, just link your Steam account and enjoy," reads the phishing messages sent to Discord users.

The link however ferries victims to a phishing website with a fake pop-up Steam login page that even has the audacity of getting users to verify that the victims have keyed in their correct Steam credentials. 

“Note that the fake pop-up window displays the proper “steamcommunity.com” domain—but do not be fooled. This is just another way for scammers to make fake things look believably real,” warn the researchers, who say they’ve found more than a hundred other scammy domains registered to the IP address used by the threat actors in this scam.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Steam scam alert.
Watch out, this convincing Steam scam could risk your entire game library
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Latest in Security
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
Latest in News
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
DJI Mavic 3 Pro
More DJI Mavic 4 Pro leaks seemingly reveal launch date, price and key features of the triple camera drone – here's what to expect
Android 16 logo on a phone
Here's how Android 16 will upgrade the screen unlocking process on your Pixel
Man sitting on sofa, drinking coffee, looking at phone in surprise
Thousands of coffee lovers warned to stop using their espresso machines immediately after reports of burns and lacerations