Tag: Discord

New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code
News

New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code

VVS Stealer, also known as VVS $tealer, is a new Python-based information stealer that can grab Discord tokens and passwords, according to information released by cybersecurity researchers. A report from Palo Alto Networks Unit 42 claims that the stealer was for sale on Telegram as early as April 2025. According to researchers Pranay Kumar Chhaparwal and Lee Wei Yeong, Pyarmor obfuscates the code of VVS stealers. Python scripts can be obfuscated using this tool to prevent signature-based detection and static analysis. Both lawful uses and the creation of covert malware are possible using Pyarmor. Promoted on Telegram as the "ultimate stealer," a weekly subscription costs €10 ($11.69). It is also among the least expensive stealers available, costing €20 ($23) for a month, €40 ($47...
Hackers steal Discord accounts with RedTiger-based infostealer
News

Hackers steal Discord accounts with RedTiger-based infostealer

Attackers are creating an infostealer that gathers payment and Discord account information using the open-source red-team tool RedTiger. Additionally, the spyware can steal game accounts, bitcoin wallet information, and browser credentials. RedTiger is a Python-based penetration testing suite for Linux and Windows that includes tools for discord, OSINT-related utilities, malware generator, and options for network scanning and password cracking. System information, browser cookies and passwords, cryptocurrency wallet files, game files, even Roblox and Discord data can all be stolen using RedTiger's info-stealer component. Additionally, it has the ability to take screenshots of the victim's screen and camera. Despite identifying its risky features as "legal use only" on GitHub, ...
New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs
News

New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

Cybersecurity researchers have released details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on infected computers. According to a technical study released last week by eSentire, threat actors used compromised credentials that linked to both a Cisco VPN and an overprivileged Active Directory account called "serviceaccount." They used WMI to run remote commands across network systems using the hacked account, which made it easier to deploy and run ChaosBot. According to the Canadian cybersecurity firm, the virus was initially discovered in the environment of a financial services client in late September 2025. The misuse of Discord for command-and-control (C2) by ChaosBot is notable. The online person...
Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
News

Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord

An ongoing social engineering attack targets cryptocurrency users by using phony startup companies to lure users into downloading malware that can drain digital assets from Windows and macOS devices. In a study posted with The Hacker News, Darktrace researcher Tara Gould said that these malicious operations use fake social media identities and project documentation hosted on trustworthy platforms like Notion and GitHub to imitate AI, gaming, and Web3 companies. It is a sophisticated social media scam that has been going on for a while. In December 2024, it used fake videoconferencing platforms to trick victims into attending a conference that was supposed to be about an investment opportunity after contacting them on Telegram and other messaging applications. Stealer virus, like ...
Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets
News

Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets

A new malware operation is using a flaw in Discord's invitation mechanism to spread the AsyncRAT remote access trojan and the information-stealing program Skuld. Through vanity link registration, the attackers were able to take control of the links and covertly reroute users from reliable sources to malicious servers, according to a technical report from Check Point. To covertly distribute AsyncRAT and a customized Skuld Stealer that targets cryptocurrency wallets, the attackers used a combination of time-based evasions, multi-stage loaders, and the ClickFix phishing tactic. The problem with Discord's invite method is that it gives hackers the ability to steal invite links that have expired or been removed and covertly reroute unwary users to malicious servers that they control. ...
Discord Introduces DAVE Protocol for End-to-End Encryption in Audio and Video Calls
News

Discord Introduces DAVE Protocol for End-to-End Encryption in Audio and Video Calls

Discord, a well-known social messaging app, has announced that it will soon be introducing a new proprietary end-to-end encrypted (E2EE) protocol for safe audio and video conversations. DAVE, which stands for Discord's audio and video end-to-end encryption ("E2EE A/V"), is the acronym for the protocol. Voice and video in direct messages (DMs), group DMs, voice channels, and go live streaming are anticipated to be moved to use DAVE as part of the modification that was implemented last week. Having said that, it's important to remember that Discord's content moderation policy applies to all messages and that they will not be encrypted read more about Discord Introduces DAVE Protocol for End-to-End Encryption in Audio and Video Calls. Get up to date on the latest cybersecurity ne...
Discord reveals impact of ticket agent breach
News

Discord reveals impact of ticket agent breach

The platform for voice and video calls and instant messaging, Discord, contacted roughly 200 users whose data may have been affected by the data breach in May, disclosing user contact information. A data breach that happened as a result of unlawful access to an employee's account of a third-party service provider has been communicated with by Discord to those affected. The provider is used by the platform to address user requests and operational problems. The breach notification letter from Discord states, "On March 29, 2023, Discord learned that an unauthorized person gained access to the account of an agent of that service provider and accessed some of the agent's support tickets read more Discord reveals impact of ticket agent breach. Stay informed with the best cybersecurity ...
Russia blacklists Snapchat, WhatsApp, and more in latest propaganda move
News

Russia blacklists Snapchat, WhatsApp, and more in latest propaganda move

Snapchat, Telegram, and WhatsApp are among the latest Western-based social media platforms the Russian Federation has put to its notorious Registry of Banned Sites. A statement reportedly from the Russian federation announcing the most recent blacklist of largely Western-owned social media and online communication apps was released to VX-Underground, a well-known underground internet repository of malware, source code, and other hacker-related information. American-owned apps Discord, Microsoft Teams, Skype for Business, Snapchat, and WhatsApp are included on the list read more Russia blacklists Snapchat, WhatsApp, and more in latest propaganda move. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest...