{"id":44783,"date":"2021-08-04T10:35:49","date_gmt":"2021-08-04T02:35:49","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=44783"},"modified":"2021-08-04T11:22:57","modified_gmt":"2021-08-04T03:22:57","slug":"sophos-uncovers-malware-targeting-discord-chat-platform","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/08\/04\/sophos-uncovers-malware-targeting-discord-chat-platform\/","title":{"rendered":"Sophos uncovers malware targeting Discord chat platform"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos, a global player in next-generation cybersecurity, published new research on how malware is increasingly targeting the Discord chat platform. The cyberthreats uncovered by Sophos include information-stealing malware, spyware, backdoors, and ransomware resurrected as \u201cmischiefware.<em>\u201d<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The findings are based on Sophos researchers\u2019 analysis of more than 1,800 malicious files detected by Sophos telemetry on the Discord Content Management Network and are detailed in a new SophosLabs Uncut article, \u201c<a href=\"https:\/\/news.sophos.com\/en-us\/2021\/07\/22\/malware-increasingly-targets-discord-for-abuse\/\">Malware Increasingly Targets Discord For Abuse<\/a>.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among other things, the research reveals how the number of URLs hosting malware on Discord\u2019s Content Management Network during the second quarter of 2021 increased by 140% compared to the same period in 2020, according to Sophos telemetry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sean Gallagher, senior threat researcher at Sophos, said:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cDiscord provides a persistent, highly-available, global distribution network for malware operators, as well as a messaging system that these operators can adapt into command-and-control channels for their malware \u2013 in much the same way attackers have used Internet Relay Chat and Telegram. Discord\u2019s vast user base also provides an ideal environment for stealing personal information and credentials through social engineering.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThese scams are not harmless \u2013 we found one malware that can steal private images from the camera on an infected device, as well as ransomware from 2006 that the attackers have resurrected to use as \u2018mischiefware.\u2019 The mischiefware denies victims access to their data, but there\u2019s no ransom demand and no decryption key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cFurther, adversaries have caught on that companies increasingly use the Discord platform for internal or community chat in the same way they might use a channel like Slack. This provides attackers with a new and potentially lucrative target audience, especially when security teams can\u2019t always inspect the Transport Layer Security-encrypted traffic (TLS) to and from Discord to see what\u2019s going on and raise the alarm if needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cDiscord users, whoever they are and whatever they use the platform for, should remain vigilant to the threat of malicious content that\u2019s lurking within the service and not just leave it to the Discord platform to identify and remove suspicious files. In addition, IT security teams should never consider any traffic from an online cloud service as inherently \u2018safe\u2019 based on the trusted nature or legitimacy of the service itself. Adversaries could be hiding anywhere.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Sophos investigation into malicious content linked to Discord found the following:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>The malware is often disguised as gaming-related tools and cheats. Common \u201ccheats\u201d seen by Sophos researchers include modifications that allow players to disable an opponent or to access premium features for free \u2013 usually for a popular online game such as Minecraft, Fortnite, Roblox, and Grand Theft Auto. The researchers also found a lure that offered gamers the chance to test a game in development.<\/li><li>Information-stealers are the most prevalent threat, accounting for more than 35% of the malware seen. More than 10% of the malware Sophos detected on Discord belongs to the \u201cBladabindi\u201d family of information-stealing backdoors. Sophos researchers found several password-hijacking malware, including Discord security token \u201cloggers\u201d built specifically to steal Discord accounts. In another instance, the researchers found a modified version of a Minecraft installer that, in addition to delivering the game, installs a \u201cmod\u201d called \u201cSaint.\u201d Saint is, in fact, spyware, capable of capturing keystrokes and screenshots as well as images directly from the camera on an infected device.<\/li><li>Sophos researchers also found repurposed ransomware, backdoors, Android malware packages, and more. The analyzed files included several types of Windows ransomware being spread by attackers that block access to data without making a ransom demand or offering victims the chance to get a decryption key.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The Android malware comprised backdoors, droppers, and financial malware designed to steal access to online bank accounts and cryptocurrency. Sophos researchers also noticed that a file advertised as a \u201cmultitool for Fortnite\u201d loads a Meterpreter backdoor and found many copies of a widely used stealer malware known as Agent Tesla that, once in place, also offers remote access to a victim\u2019s computer and a platform to deliver other malware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At a technical level, the researchers found some malware using the Application Programming Interface (APIs) of Discord \u201cchatbots\u201d to covertly communicate with and receive instructions from their command server. They also uncovered files that claim to install cracked versions of popular commercial software, such as Adobe Photoshop, and tools that claim to give the user access to the paid features of Discord Nitro, the service&#8217;s premium edition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Staying safe on Discord<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos recommends that organizations using Discord for workplace chat and collaboration use multi-factor authentication (MFA) to protect employees\u2019 Discord accounts and ensure that all employees have up-to-date malware protection on any computer they use to access remote collaboration platforms for work-related projects.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos Intercept X protects business users by detecting the actions and behaviors of malware, while Sophos Firewall inspects encrypted Transport Layer Security (TLS) traffic \u2013 now used by half of all malware for communications, according to Sophos research.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos also advises consumers to install a security solution on the devices that they and their families use for online communications and gaming, such as Sophos Home, to protect everyone from malware and cyberthreats. It is also good security practice to avoid downloading and installing unlicensed software from any source, even if it seems to come from a known source.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The number of URLs hosting malware on Discord\u2019s Content Management Network during the second quarter of 2021 increased by 140% compared to the same period in 2020, according to Sophos telemetry.<\/p>\n","protected":false},"author":6,"featured_media":44788,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[54,2103,3914,53,4100,206],"class_list":["post-44783","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-security","tag-security-breach","tag-security-platform","tag-security-risk-management","tag-security-solutions","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=44783"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44783\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/44788"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=44783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=44783"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=44783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}