Discord bots are being used in information-stealing campaigns (2024)

Discord bots are being used in information-stealing campaigns (1)

Hackers have been observed using Discord to grab data harvested on compromised computers, experts have warned.

In a new report, Trellix cybersecurity researcher Gurumoorthi Ramanathan detailed the malware and the data exfiltration techniques it used.

According to the report, the threat actors built a sophisticated infostealer called NS-STEALER. They’re distributing it via ZIP archives impersonating cracked software. When a victim extracts the archive file, they will find a Windows shortcut titled “Loader GAYve” which, if executed, will deploy a malicious Java program. This program will do two things: first it will create a folder called "NS-<11-digit_random_number>", to which it will store all of the information harvested. Then, it will start grabbing the data.

Cost-effective data exfiltration

NS-STEALER will look for information stored in more than two dozen browsers - cookies, credentials, and autofill data. Then, it will start taking screenshots of the infected device, grabbing system information, and the list of programs installed on the device. It will then pull Discord tokens, as well as Steam, and Telegram session data.

Finally, it will exfiltrate all of the above to a Discord Bot channel.

"Considering the highly sophisticated function of gathering sensitive information and using X509Certificate for supporting authentication, this malware can quickly steal information from the victim systems with [Java Runtime Environment]," Ramanathan said.

“The Discord bot channel as an EventListener for receiving exfiltrated data is also cost-effective."

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

This is hardly the first time hackers found a way to abuse Discord for their nefarious purposes. In fact, Discord has been abused for years now. Back in 2020, researchers from MalwareHunterTeam found a remote access trojan (RAT) that used Discord as a command and control (C2) server. That same year, researchers saw a version of the AnarchyGrabber trojan used to steal victims’ plain text passwords and even command an infected client to spread malware to their Discord friends.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Most Popular
Discord bots are being used in information-stealing campaigns (2024)

FAQs

Discord bots are being used in information-stealing campaigns? ›

Hackers have been observed using Discord to grab data harvested on compromised computers, experts have warned. In a new report, Trellix cybersecurity researcher Gurumoorthi Ramanathan detailed the malware and the data exfiltration techniques it used.

Can Discord bots steal information? ›

The new Java-based information-stealing malware, NS-STEALER, has emerged and leverages Discord bots to exfiltrate sensitive data from compromised systems discreetly. Based on reports, an independent, comprehensive analysis published last week revealed the sophisticated techniques employed by this malicious software.

Are Discord bots a security risk? ›

Bots given permissions they don't need

While rare, bots can get hacked or used for malicious purposes, and if they have admin access to your server, they can access a lot of valuable information and security details.

Are there malicious Discord bots? ›

But they're not all good because Discord bots can also spread malware. For example, they can blast messages with malicious links to various users. So don't trust bots you don't recognize and cautiously use ones created by other users.

What is the Discord bot that spies? ›

SPY SECURITY IS A PRE CONFIGURED SECURITY BOT. WHICH WILL PROTECT YOUR SERVER AGAINST ANY TYPE OF SMART NUKE ATTEMPTS. NOTE- To save resources and make it fast, the bot will leave the server if it has less then 25 members.

Can bots steal your info? ›

While bots have many helpful purposes, they have unfortunately become a tool for malicious actors to gain fraudulent access to financial accounts, personal information and even company-wide systems.

Does Discord send info to police? ›

We provide emergency disclosure responses only when enough information is provided for Discord to, in good faith, believe that the exigent situation requires disclosure of user information, as outlined in 18 U.S.C. § 2702. We do not disclose information for emergency requests unless they are from law enforcement.

Can you trust Discord bots? ›

Discord has a lot of amazing bots, but some can also be a threat of hacking, leaking data or spamming.

Can Discord bots listen to you? ›

A discord music bot capable of performing commands via voice recognition in addition to text commands. Listens to one user in the voice channel only and uses wake word detection to determine when a command is being voiced.

Is Discord selling my data? ›

Respecting user privacy is a key part of that mission. We don't sell your personal information. Our business is based on subscriptions and paid products, not from selling your personal information to third parties.

How do I know if a Discord bot is safe? ›

A verified bot is a bot that has been verified by Discord and has additional API permissions. Verification of bots is a secure system which allows Discord to add new features for developers, while making sure that all bots which use it are safe.

What can Discord bots see? ›

Basic user profile information of server members (e.g., usernames, avatars, banners, discriminators, and nicknames); Roles that members have in the server; Metadata about messages (e.g., day and time sent);

What is an example of a malicious bot? ›

Here are some common examples of malicious bots: Malicious chatterbots: A malicious chatterbot can hit message boards, chat rooms, apps, and websites with spam and advertising.

Can Discord be used for spying? ›

It's been a while, I am seeing a lot of discord bots are being created every day. But then I saw one type of bot which is not just a regular bot. It's a spyware. Literally, it can automatically spy on you and track your process and also steal your credentials.

What is the Discord bot that detects NSFW? ›

SFW Bot is a powerful Discord bot engineered to ensure your server remains Safe for Work (SFW). It utilizes a sophisticated neural network trained on thousands of images to automatically detect and delete inappropriate content. Helps to moderate and keeps your community clean effortlessly.

What is the #1 Discord bot? ›

MEE6: The Best All-in-One Discord Bot

Keep each user happy with the auto-mod. From filtering out spam to detecting bad behavior, MEE6 features will provide a good experience for your server, even when the mods aren't watching.

Can you get hacked by bots? ›

Malware bots and internet bots can be programmed/hacked to break into user accounts, scan the internet for contact information, to send spam, or perform other harmful acts. To carry out these attacks and disguise the source of the attack traffic, attackers may distribute bad bots in a botnet – i.e., a bot network.

Can Discord servers get your info? ›

Information we collect automatically

We also collect information automatically from you when you use Discord. This includes: Information about your device. We collect information about the device you are using to access the services.

Is it safe to give Discord bots admin? ›

The Administrator permission is a special permission on a Discord role in that it grants every Discord permission and allows users with that permission to bypass all channel-specific permissions. Because of this granting this role to any user or bot should be done with the utmost caution and on an as-needed basis.

Is Discord safe for personal information? ›

You can use Discord safely, as long as you're careful and avoid common Discord risk factors. Like any social media platform, Discord does require some personal information from its users, and that data could be leaked if Discord suffers a data breach.

Top Articles
HackTool:Win32/Crack Malware
How To Make Money On FeetFinder (2024) | Ecommerce Fastlane
Food King El Paso Ads
Mrh Forum
Linkvertise Bypass 2023
Mcoc Immunity Chart July 2022
سریال رویای شیرین جوانی قسمت 338
Optimal Perks Rs3
How Far Is Chattanooga From Here
Crime Scene Photos West Memphis Three
When Is the Best Time To Buy an RV?
PGA of America leaving Palm Beach Gardens for Frisco, Texas
Tripadvisor Near Me
Detroit Lions 50 50
No Strings Attached 123Movies
Apne Tv Co Com
Telegram Scat
Rams vs. Lions highlights: Detroit defeats Los Angeles 26-20 in overtime thriller
Pizza Hut In Dinuba
Milspec Mojo Bio
Apply for a credit card
Amazing deals for DKoldies on Goodshop!
Cvs El Salido
Conan Exiles Sorcery Guide – How To Learn, Cast & Unlock Spells
Happy Life 365, Kelly Weekers | 9789021569444 | Boeken | bol
Play Tetris Mind Bender
Meridian Owners Forum
Znamy dalsze plany Magdaleny Fręch. Nie będzie nawet chwili przerwy
Miller Plonka Obituaries
Taylored Services Hardeeville Sc
Bridgestone Tire Dealer Near Me
Package Store Open Near Me Open Now
Average weekly earnings in Great Britain
Gr86 Forums
Plato's Closet Mansfield Ohio
Hair Love Salon Bradley Beach
Log in or sign up to view
AsROck Q1900B ITX und Ramverträglichkeit
Admissions - New York Conservatory for Dramatic Arts
Bismarck Mandan Mugshots
Wisconsin Women's Volleyball Team Leaked Pictures
1Exquisitetaste
Doublelist Paducah Ky
Tfn Powerschool
Television Archive News Search Service
The Many Faces of the Craigslist Killer
Canvas Elms Umd
Value Village Silver Spring Photos
New Zero Turn Mowers For Sale Near Me
Rovert Wrestling
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 6692

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.