Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Old Discord Links Now Lead To Malware

June 13, 2025
Reading Time: 2 mins read
in Alerts
VexTrio TDS Uses Adtech To Spread Malware

A sophisticated new attack vector exploits a critical flaw in Discord’s invitation system, allowing attackers to hijack expired invite links. This emerging threat leverages the trusted nature of Discord to silently compromise victims through previously legitimate invitation links. The attack chain begins when threat actors exploit Discord’s custom vanity invite link system, which is available to premium servers. When legitimate servers lose their boost status or links expire, the invitation codes become available for reuse by malicious actors. This creates a dangerous scenario where users clicking trusted links are unknowingly redirected to attacker-controlled Discord servers designed to appear legitimate.

Check Point researchers identified this active malware campaign in June 2025, uncovering how attackers weaponized the Discord vulnerability.

The campaign demonstrates remarkable technical sophistication, combining the ClickFix phishing technique with multi-stage loaders and time-based evasions. This combination is used to stealthily deliver AsyncRAT, a powerful remote access trojan, alongside a customized variant of Skuld Stealer. What makes this operation particularly insidious is that payload delivery and data exfiltration occur exclusively via trusted cloud services. This allows malicious traffic to blend seamlessly with normal network activity and avoid raising security alarms, making it very hard to detect.

The infection mechanism employed in this campaign represents a masterclass in social engineering, utilizing a refined technique known as ClickFix.

Once users join the hijacked Discord server, they encounter what appears to be a legitimate verification process managed by a bot. When victims click the verification button, they are redirected to an external phishing website that presents a sophisticated replica of Discord’s interface. The site displays a fake Google CAPTCHA that appears to fail, prompting users to perform manual “verification” steps to proceed. The JavaScript on this malicious page silently copies a PowerShell command to the user’s clipboard without their knowledge or any direct interaction.

The social engineering aspect is particularly effective because it presents users with familiar Windows instructions to follow to complete the process. This includes opening the Run dialog with Win+R, pasting the clipboard content, and then pressing Enter to finally execute the command. This command employs string reversal and Base64 decoding to obfuscate a Pastebin URL, which initiates the final malware infection chain. This approach cleverly eliminates the need for users to download or run files manually, removing common red flags that might alert security-conscious individuals. The campaign’s scale is significant, with potential victims exceeding 1,300 across multiple countries, including the United States, Vietnam, and Germany.

Reference:

  • New Discord Scam Hijacks Old Invite Links To Push RATs Via Fake CAPTCHAs
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityFIN6June 2025More Eggs
ADVERTISEMENT

Related Posts

OneClik Malware Attacks Energy Sector Firms

Hackers Abuse Trezor Support For Phishing

June 25, 2025
OneClik Malware Attacks Energy Sector Firms

FileFix Attack Turns Explorer Into Weapon

June 25, 2025
OneClik Malware Attacks Energy Sector Firms

OneClik Malware Attacks Energy Sector Firms

June 25, 2025
BEARDSHELL and COVENANT Malware Uncovered

BEARDSHELL and COVENANT Malware Uncovered

June 24, 2025
New Malware Skims WordPress E-commerce Sites

New Malware Skims WordPress E-commerce Sites

June 24, 2025
Chinese Hackers Build Router Spy Network

Chinese Hackers Build Router Spy Network

June 24, 2025

Latest Alerts

Hackers Abuse Trezor Support For Phishing

FileFix Attack Turns Explorer Into Weapon

OneClik Malware Attacks Energy Sector Firms

Chinese Hackers Build Router Spy Network

New Malware Skims WordPress E-commerce Sites

BEARDSHELL and COVENANT Malware Uncovered

Subscribe to our newsletter

    Latest Incidents

    Columbia University Probes Major IT Outage

    Mainline Health Breach Hits 101,000 Patients

    Porto Nacional City Hall Hit by Ransomware

    Hacken Token Crashes 99 Percent After Hack

    Paraguayan Government Hit By Cyberattack

    Hackers Leak Saudi Games Athlete Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial