Criminals target Discord to spread malware
Cyber criminals are abusing Discord to host, spread, and control malware which targets the users of this chat service, according to new research.
According to security researchers at Sophos, the abuse of Discord has increased in popularity since last year, as 140 times more URLs hosting malware were blocked in the past two months, compared with the same period in 2020. Researchers said Discord hosts 4% of all TLS-protected malware downloads they have detected.
In the second quarter, researchers detected 17,000 unique URLs in Discord’s CDN pointing to malware. This excludes malware not hosted within Discord that leverages Discord’s application interfaces in various ways. More than 4,700 of those URLs, which point to a malicious Windows .exe file, remained active. Researchers said the malware is often disguised as gaming-related tools and cheats. Common “cheats” seen by researchers included modifications that allowed players to disable an opponent or to access premium features for free – usually for a popular online game, such as Minecraft, Fortnite, Roblox, or Grand Theft Auto. The researchers also found a lure that offered gamers the chance to test a game in development.