Threat Advisory

Discord Invite Hijacking Delivers Info-Stealing Malware

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers are exploiting Discord’s invite system by hijacking expired or reused vanity links to lure users into fake servers. These links, often shared months ago on social platforms or forums, appear legitimate but now point to attacker-controlled servers. Once inside, users are met with a “verification” prompt from a fake bot like “Safeguard#0786.” This prompt encourages users to perform actions that ultimately lead to malware infection. The trick relies on users not realizing that “never expire” invites can still be replaced once they lapse. By taking over old links, attackers mimic trusted communities, making the deception hard to spot. This tactic weaponizes trust and Discord’s open invite features to create convincing traps that lead users straight into malware delivery setups—all disguised as routine community onboarding.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers are exploiting Discord’s invite system by hijacking expired or reused vanity links to lure users into fake servers. These links, often shared months ago on social platforms or forums, appear legitimate but now point to attacker-controlled servers. Once inside, users are met with a “verification” prompt from a fake bot like “Safeguard#0786.” This prompt encourages users to perform actions that ultimately lead to malware infection. The trick relies on users not realizing that “never expire” invites can still be replaced once they lapse. By taking over old links, attackers mimic trusted communities, making the deception hard to spot. This tactic weaponizes trust and Discord’s open invite features to create convincing traps that lead users straight into malware delivery setups—all disguised as routine community onboarding.[emaillocker id="1283"]

After joining the fake server, users are sent to a phishing site posing as a verification or CAPTCHA page. It tells them to paste a PowerShell command into their system, claiming it fixes a failed CAPTCHA. This command silently downloads a loader that installs info-stealing malware like AsyncRAT, Skuld Stealer, and ChromeKatz. These tools steal passwords, cookies, Discord tokens, and crypto wallet data. The attack hides its activity using trusted sites like GitHub and Pastebin, avoids antivirus detection with delayed execution, and stays persistent via scheduled tasks. Data is exfiltrated using Discord webhooks, blending malicious activity into normal app traffic. The attackers rely on user confusion, clipboard tricks, and minimal visible actions to avoid raising suspicion during the infection process.

This campaign shows how attackers can turn basic Discord features into powerful tools for spreading malware. By reusing expired invite links and setting up realistic-looking servers, they trick users into downloading malware under the guise of verification. Over 1,300 infections have been recorded worldwide. To stay safe, users should avoid clicking old invite links and never run unexpected PowerShell commands. Server admins should stop using vanity URLs, and organizations should block unnecessary scripting tools and educate users on these phishing tricks. Discord has removed the fake bot, but as long as invite reuse remains unchecked, similar attacks can continue.

THREAT PROFILE:

Tactic Technique ID Technique Sub-Technique
Initial Access T1566.002 Phishing Spearphishing via Service
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1053.005 Scheduled Task/Job Scheduled Task
Defense Evasion T1027 Obfuscated Files or Information
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1113 Screen Capture
T1056.001 Input Capture Keylogging
Command & Control T1071.001 Application Layer Protocol Web Protocols (via Discord webhooks)
Exfiltration T1041 Exfiltration Over C2 Channel

 

MBC MAPPING:

Objective Behaviour ID Behaviour
Initial Access E1204 User Execution
Execution B0011 Remote Commands - Execute
Defense Evasion F0001 Software Packing
Collection E1056 Input Capture
E1113 Screen Capture
Credential Access F0002 Keylogging
Exfiltration B0030 C2 Communication
Persistence F0012 Registry Run Keys

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu