Hackers use emoji to dispatch malware — and even governments are being attacked, so be on your guard

HTML code
(Image credit: Shutterstock.com / BEST-BACKGROUNDS)

Potentially dangerous malware that allows threat actors to communicate with command and control (C2) servers using emojis sent via Discord has been highlighted as a key element of recent cyberespionage attacks on Indian government entities.

The report from cybersecurity firm Volexity reveals the Disgomoji malware is currently used exclusively by a Pakistan-based threat actor that the firm is tracking as UTA0137.

Though Disgomoji is a modification of ‘discord-c2’, a previously known public project, it seems to be specifically targeting the Indian government, owing to its laser-focus on systems running the Linux distribution BOSS. 

Emoji and malware

Volexity believes that Initial access to Indian government infrastructure was secured via phishing attacks. From there, UTA0137 could communicate with their target servers via emojis posted in dedicated command channels in a Discord server.

More broadly, Disgomoji can survive reboots, and copy files back and forth between connected USB devices and local system folders so that they can be leveraged by an attacker later.

The emojis used to execute commands on a server are straightforward. For instance, the ‘camera with flash’ emoji takes a screenshot, ‘Backhand Index Pointing Down’ downloads a file, ‘Fox’ zips all firefox profiles on a target device, and so on.

UTA0137’s Disgomoji attack campaigns date back as far as mid-2023. Discord’s ability to bring down the offending servers are hampered by the way the malware manages tokens, allowing the attacker to simply update the client configuration to keep the operation going.

Given this, Disgomoji’s open source nature, and its features that seem tailor-made for espionage, it’s possible that further strains could be used in future attack campaigns aimed at governments.

More from TechRadar Pro

TOPICS
Luke Hughes
Staff Writer

 Luke Hughes holds the role of Staff Writer at TechRadar Pro, producing news, features and deals content across topics ranging from computing to cloud services, cybersecurity, data privacy and business software.

Read more
Angry emoji
Not even emoji are safe from hackers - smiley faces can be hijacked to hide data, study claims
Telegram
New Golang malware is hijacking Telegram to help itself spread
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
Latest in Pro
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Racks of servers inside a data center.
Modernizing data centers: an efficient path forward
Dr. Peter Zhou, President of Huawei Data Storage Product Line
Why AI commonization is so important for business intelligent transformation and what Huawei’s data storage has to offer
Wix automation
The world's leading website builder aims to save businesses time with new tool
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over