Discord Chat Service Users Be Alert

November 11th, 2019
Discord Chat Service Users Be Alert

Do you use the Discord chat service?

Be advised that malware developers have been using the service to host various types of malware and use it as a command and control server.
They are abusing the chat client to force it to perform a variety of malicious behavior.

Unfortunately, this is not a new problem. Anyone familiar with the chat service knows that it has a long history of being abused. In fact, discord allows its members to use a chat channel where other users can download them.

Additionally, users can even right-click on a hosted file to get a sharable download link. In practice, this is one of the ways that hackers are abusing the system. These sharable links work even for non-Discord users, which gives malicious actors a convenient place to stash harmful files.

Even more impressive is that the uploader can delete the file 'inside Discord' itself, but the URL may apply to download it. Consequently, this means the chat service gives the outward appearance of removing the file, it still exists on the server. This gives malware developers an incredibly convenient, completely anonymous method of hosting their files.

Discord contains a feature called 'Webhooks' that allows third-party applications or websites to send messages to a Discord channel. In addition, the server owner receives a URL used with the Discord API to send messages to a specified channel. Previous malware that has infected a user can be used to exfil collected data directly to the attacker.

In conclusion, if you use Discord chat service, beware. To say that the chat service has problems is an understatement.


Leave a comment!

Your email address will not be published. Required fields are marked *