A new wave of Discord malware is on the rise - here's what you need to know

Discord
(Image credit: unsplash)

Advanced Persistent Threats (APT) have been observed abusing Discord to target critical infrastructure in Ukraine and steal sensitive data. 

This is according to a new report from Trellix, whose researchers said this was the first time an APT (which are usually state, or state-sponsored groups) abused the popular communication and collaboration platform to exfiltrate information.

According to the report, an unnamed threat actor was engaged in a phishing attack, in which it distributed a OneNote file named “dobroua.one” - a typosquatted name of the Ukrainian non-profit organization dobro.ua. The file urged the reader to make a donation to the Ukrainian cause and offered a button named “Support”. Clicking it runs an embedded Visual Basic Script (VBS) which, after a few steps, starts exfiltrating data via Discord’s webhook.

Highly targeted attacks

On Discord, a webhook is a utility designed to send messages to text channels without the need for the Discord application. It is also an automation feature that, in this particular instance, allows the attacker to send files and other data stored on the victim’s machine.

Trellix believes the attack is highly targeted, as in its telemetry it hasn’t seen any further related samples. “This suggests the attack was targeting only the Ukrainian critical infrastructure organizations where the sample was recovered, and any further stages apart from the ones described could not be retrieved,” they explained.

It’s also worth mentioning, the researchers say, that the campaign was probably in its earlier stages, as the final payload was all about gathering system information. “The actor could deliver a more sophisticated piece of malware to the compromised systems in the future by modifying the file stored in the GitHub repository,” the researchers warn.

One of the reasons Discord isn’t being used by APTs on a bigger scale is the lack of complete control over the C2 server. Should they be compromised, Discord can terminate their account at any time, potentially cutting off access to any sensitive information they might have obtained in the meantime.

Via BleepingComputer

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC