Among the malicious files we discovered in Discords network, we found game cheating tools that target games that integrate with Discord, in-game. This technique was frequently used across malware distribution campaigns associated with RATs, stealers and other types of malware typically used to retrieve sensitive information from infected systems, the Talos team explained. Thanks for reading and sorry if it was a bit long. And while other methods of hosting malware can be taken offline or blocked when a hacker's server is discovered, the Slack and Discord links are harder to take down or block users from accessing. lol my friend thought this was real and posted on his server. I was forced to delete my Discord account. October 20, 2022. Every company and organisation has data of value to cybercriminals who sell it on the Dark Net. This antiav.bat script runs from the %TEMP% directory on the system immediately after the user launches the program. The Discord API has turned into an effective tool for attackers to exfiltrate data from the network. Thanks in large part to the global. This may enable users to focus more closely on who theyre interacting with and for what reasons. This simulated exercise will take place at the WEF's annual 'Cyber Polygon' digital event. Discord operates its own content delivery network, or CDN, where users can upload files to share with others. the only time it happened was 2 years ago and maybe on another social network but it wont this time xd, Theyre literally doing it again sending the same message, Just saw one today, I dont believe this crap and neither should anyone really. Cookie Notice Lockbit is by far this summers most prolific ransomware group, trailed by two offshoots of the Conti group. To mitigate the risks, more focus on least privilege is needed, as its still too common for users to run with local admin rightsEmail and office applications provide a number of hardened settings to combat malware and phishing; however, not enough organizations make use of them. Its not unusual for Agent Tesla malware to download payloads as part of its infection process, but it was unexpected to find that the payload was also hosted in DIscords CDN. Attacks will continue to span the entire attack surface, leaving IT teams scrambling to cover every possible avenue of attack. Following successful infection, the data stored on the system is no longer available to the victim and the following ransom note is displayed, the report said. But the platform remains a dumping ground for malware. Ciscos Talos cybersecurity team said in a report on collaboration app abuse this week that during the past year threat actors have increasingly used apps like Discord and Slack to trick users into opening malicious attachments and deploy various RATs and stealers, including Agent Tesla, AsyncRAT, Formbook and others. It is the essential source of information and ideas that make sense of a world in constant transformation. :trollface: problem? Please broadcast on all servers where you have admin permissions or are owners and can ping to broadcast the warning. I didnt thought this was going to be real so I searched it up on google and this thread came up. The learning curve for building a token logger is not very steep. Files may be uploaded to a given collaboration tool, enabling users to create external links for the file. The links don't have to be delivered to victims inside of Slack or Discord. Turn off your router for about 3-5 hours (or even more if you want to stay safer) and when you turn it back on, your IP will change. "We are working to enhance our processes to make it easier to report these types of issues, improve the way these issues are internally routed for faster triaging, and dedicate more resources to proactively identifying this type of abuse," the spokesperson writes. The team also observed campaigns associated with Pay2Decrypt LEAKGAP ransomware, which used the Discord API for C2, data exfiltration and bot registration, in addition to Discord webhooks for communications between attacker and systems. Amid isolating sanctions, a Russian tech giant plans to launch new Android phones and tablets. Retweets. DO NOT AND I MEAN DO NOT BELIEVE THIS! If possible, send this to your friends as well to spread the message more quickly, I repeat, stay safe. The growing popularity of the game-centric text and voice chat platform has not failed to draw the attention of malware operators. Hashtag Trending, May 27, 2021 - Amazon buys MGM; FICO report . Moderators and even owners who believe in these lies are just ridiculous, and they are spreading the word in their own servers as well. With more organizations using Discord as a low-cost collaboration platform, the potential for harm posed by the loss of Discord credentials opens up additional threat vectors to organizations. In addition to message and stream routing, Discord also acts as a content delivery network for digital content of all types. WASHINGTON A ransomware attack paralyzed the networks of at least 200 U.S. companies on Friday, according to a cybersecurity researcher whose company was responding to the incident. The C2 communications occur via webhooks. Press question mark to learn the rest of the keyboard shortcuts. As is common with Remcos infections, the malware communicated with a command-and-control server (C2) and exfiltrated data via an attacker-controlled DNS server, the report added. The computer has to support USB-C DisplayPort VESA Alternate Mode for the 4K port to function. One Discord network search turned up 20,000 virus results, researchers found. This has led to a large amount of Discord token-stealers being implemented and distributed on GitHub and other forums. Employees report attacks via Agent Tesla, AsyncRAT, FormBook and other infections. Discord provides a persistent, highly-available, global distribution network that malware operators can take advantage of, as well as a messaging API that can be adapted easily to malware command and controlmuch in the way Internet Relay Chat, and more recently Slack and Telegram, have been used as C2 channels. Reading time: 15 minutes. ", Unless you click links they send you, they can't get your IP or any personal detail. In March, Acer refused to pay the $50 million ransom to REvil. A significant percentage of these credential stealers target Discord itself. It never has been any of the hundreds of times people have spread such stupid chain mail. According to the 2021 SonicWall Cyber Threat Report the world has seen a 62% increase in ransomware since 2019. The ACSC Annual Cyber Threat Report 2019-20 is accessible via the website. Request sponsorship information Featured Speakers For speaking opportunity, please contact us at hello@thetehgroup.com This means users are overwhelmed as they communicate with different or sometimes the same people across multiple platforms. Please be careful tomorrow. It also makes it an ideal platform for abuse by malicious actors. Spread this post to any of your friends who came across something like this, report people who do the things mentioned in num 6. Files can be uploaded to Slack, and users can create external links that allow the files to be accessed, regardless of whether the recipient even has Slack installed.. This can easily be avoided by blocking the person, reporting him, and closing the DM. Hunting through telemetry, we found 58 unique malicious apps that can be run on Android devices. Instead, they simply take advantage of some little-examined features of those collaboration platforms, along with their ubiquity and the trust that both users and systems administrators have come to place in them. Whoever actually did has 3 brain cells. Social media has turned into a playground for cyber-criminals. It's fake, the discord staff and developers etc will do a annoucement about It because CBs arereally dangerous so ofc they will do a annoucement about It so It's fake. That's what you guys need to know. During the timeframe of that research, we found that four percent of the overall TLS-protected malware downloads came from one service in particular: Discord. It also provides an ever-growing, target-rich environment for scammers and malware operators to spread malicious code to steal personal information and credentials through social engineering. Once credentials are stolen, they are often used to continue to steal other credentials through social engineering. These included a number of banking-focused malware and spyware, as indicated by the Sophos detections below: In our 90 day telemetry lookback, we found 205 URLs on the Discord domain pointing to Android .apk executables (with multiple, redundant links to duplicate files). The attackers . Green Goblin also has two identities, of Harold Osborn and Green Goblin. "Right now it appears to be peaking.". Discord servers, including the free ones, can also be configured to interact with third-party applicationsbots that post content to server channels, apps that provide additional functionality built on top of Discord, and games that directly connect to Discords messaging platform. The Sketchy Plan to Build a Russian Android Phone. "After gaining access to victims' networks, Royal actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting . It will also require security vendors to step up and use the telemetry to detect and block attacks within these communication channels.. This reminds me of the Instagram hoax where it some crap that goes like "instagram is deleting accounts on old servers, post this to keep your account saved" or whatever. "What we're seeing is a proliferation of social media-based attacks," said Ron Sanders, the staff director for Cyber Florida. iOS and iPadOS are now on version 14.6 . Presently, Discord lacks client verification methods to prevent impersonation via stolen access tokens. Files hosted on Discord also included multiple Android malware packages, ranging from spyware to fake apps that steal financial information or transactions. The reasons for that growth seem pretty easy to understand. I advise no one to accept any friend requests from people you don't know, stay safe. They can also be served up over email, where hackers can far more easily trawl for victims en masse, impersonate a victim's colleagues, and reach users with whom they have no previous connection. At the time of writing, Discord does not implement client verification to prevent impersonation by way of a stolen access token, according to Talos. What to Do When Your Boss Is Spying on You. You may never get hacked by accepting a request. Cyber Attack Event Manila Series provides the Philippines' IT executives an opportunity to gather for a day of networking, collaboration, knowledgetransfer through peer-led keynotes, breakouts, panels, and networking sessions. When a human opened the file, macros immediately delivered the payload. The trick, the team said, is to get users to click on a malicious link. The functionalities that make it easy to hack into a collaboration platform arent unique to Discord or Slack. We also encountered several ransomware families hosted in the Discord CDNlargely older ones, usable only to cause harm, as theres no longer a way to pay the ransom. Stay safe from these scams as they occur more often. In mitigating collaboration tool app risks, experts advocate for a multi-pronged approach. Since Colonial Pipeline is a significant fuel provider, this ransomware attack seriously impacted petroleum, diesel, and jet fuel supplies across the East Coast of America. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Discord, collaboration tools & the malware you may not know about, White House cyber security strategy shifts burden to providers, Phishing is what type of attack? Please spread awareness. The World Economic Forum (WEF) will stage a 'cyber attack exercise' in July, it has been revealed, as the group prepares for what it describes as 'the potential for a cyber pandemic'. An attack against the UK's . I'm not 100% sure, but i heard that tomorrow is a cyber attack event, on all social media platforms including discord there will be people trying to send you gore, extreme profanity, porn, racist slurs, and there will also be ip grabbers, hackers and doxxers. 30 Dec, 2022, 01.13 PM IST When WIRED reached out to Discord and Slack, a Discord spokesperson said that the company does proactively scan for malware in files that are hosted on its platform, takes down any hosted malware that's reported to it by users or security researchers, and seeks to identify groups of users who are abusing its tools for cybercriminal purposes. But while it installed the browser, it also dropped an Agent Tesla infostealer. 244. Since the Tor site for Petya is dead, its not clear if this file was shared with the intent of extortion, or if it was meant to simply disable the recipients computer. New comments cannot be posted and votes cannot be cast. Change control and vulnerability management as core security controls should be in place as well. I have been warning people away from Discord as well. However, there are some things I want to clarify. The Biden administrations new strategy would shift the liability for security failures to a controversial target: the companies that caused them. 3. However, some other things might happen.Gore/Extreme Profanity/Porn/Racist Slurs:Someone might add you as a friend to send you these things. Fortunately, in those cases, the sites had already locked or taken down the payload script, so the stealer failed to complete its task. Register herefor the Wed., April 21 LIVE event.