EXECUTIVE SUMMARY:
Attackers are exploiting Discord’s invite system by hijacking expired or reused vanity links to lure users into fake servers. These links, often shared months ago on social platforms or forums, appear legitimate but now point to attacker-controlled servers. Once inside, users are met with a “verification” prompt from a fake bot like “Safeguard#0786.” This prompt encourages users to perform actions that ultimately lead to malware infection. The trick relies on users not realizing that “never expire” invites can still be replaced once they lapse. By taking over old links, attackers mimic trusted communities, making the deception hard to spot. This tactic weaponizes trust and Discord’s open invite features to create convincing traps that lead users straight into malware delivery setups—all disguised as routine community onboarding.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Attackers are exploiting Discord’s invite system by hijacking expired or reused vanity links to lure users into fake servers. These links, often shared months ago on social platforms or forums, appear legitimate but now point to attacker-controlled servers. Once inside, users are met with a “verification” prompt from a fake bot like “Safeguard#0786.” This prompt encourages users to perform actions that ultimately lead to malware infection. The trick relies on users not realizing that “never expire” invites can still be replaced once they lapse. By taking over old links, attackers mimic trusted communities, making the deception hard to spot. This tactic weaponizes trust and Discord’s open invite features to create convincing traps that lead users straight into malware delivery setups—all disguised as routine community onboarding.[emaillocker id="1283"]
After joining the fake server, users are sent to a phishing site posing as a verification or CAPTCHA page. It tells them to paste a PowerShell command into their system, claiming it fixes a failed CAPTCHA. This command silently downloads a loader that installs info-stealing malware like AsyncRAT, Skuld Stealer, and ChromeKatz. These tools steal passwords, cookies, Discord tokens, and crypto wallet data. The attack hides its activity using trusted sites like GitHub and Pastebin, avoids antivirus detection with delayed execution, and stays persistent via scheduled tasks. Data is exfiltrated using Discord webhooks, blending malicious activity into normal app traffic. The attackers rely on user confusion, clipboard tricks, and minimal visible actions to avoid raising suspicion during the infection process.
This campaign shows how attackers can turn basic Discord features into powerful tools for spreading malware. By reusing expired invite links and setting up realistic-looking servers, they trick users into downloading malware under the guise of verification. Over 1,300 infections have been recorded worldwide. To stay safe, users should avoid clicking old invite links and never run unexpected PowerShell commands. Server admins should stop using vanity URLs, and organizations should block unnecessary scripting tools and educate users on these phishing tricks. Discord has removed the fake bot, but as long as invite reuse remains unchecked, similar attacks can continue.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Initial Access | T1566.002 | Phishing | Spearphishing via Service |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1053.005 | Scheduled Task/Job | Scheduled Task |
| Defense Evasion | T1027 | Obfuscated Files or Information | – |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1113 | Screen Capture | – |
| T1056.001 | Input Capture | Keylogging | |
| Command & Control | T1071.001 | Application Layer Protocol | Web Protocols (via Discord webhooks) |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | – |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Initial Access | E1204 | User Execution |
| Execution | B0011 | Remote Commands - Execute |
| Defense Evasion | F0001 | Software Packing |
| Collection | E1056 | Input Capture |
| E1113 | Screen Capture | |
| Credential Access | F0002 | Keylogging |
| Exfiltration | B0030 | C2 Communication |
| Persistence | F0012 | Registry Run Keys |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]