PULSE NAME
From Trust to Threat: Hijacked Discord Invites Used for Multi-Stage Malware Delivery
WHITE AlienVault 2025-06-13 Modified: 2025-07-13
19
IOCs
MEDIUM VOLUME
Check Point Research uncovered a malware campaign exploiting expired Discord invite links to redirect users to malicious servers. The attackers use a combination of techniques including ClickFix phishing, multi-stage loaders, and time-based evasions to deliver AsyncRAT and a customized Skuld Stealer targeting crypto wallets. The campaign leverages trusted cloud services for payload delivery and data exfiltration to avoid detection. The operation continues to evolve, with threat actors now able to bypass Chrome's App Bound Encryption using adapted tools like ChromeKatz to steal cookies from new Chromium browser versions. The campaign highlights how subtle features in Discord's invite system can be exploited as attack vectors.
Indicators of Compromise (19)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7834b9b4574b68ba85eabd79b9770b08 2025-06-13
FileHash-MD5 fc13b02d22f6fe582e2948259660e3d5 2025-06-13
FileHash-SHA1 4501e8029fedadab2cbaa9e504301200c4cd2bfe 2025-06-13
FileHash-SHA1 d383b44cb3c7e5a2e460300182d89932869a7281 2025-06-13
FileHash-SHA256 160eda7ad14610d93f28b7dee20501028c1a9d4f5dc0437794ccfc2604807693 2025-06-13
FileHash-SHA256 375fa2e3e936d05131ee71c5a72d1b703e58ec00ae103bbea552c031d3bfbdbe 2025-06-13
FileHash-SHA256 53b65b7c38e3d3fca465c547a8c1acc53c8723877c6884f8c3495ff8ccc94fbe 2025-06-13
FileHash-SHA256 5d0509f68a9b7c415a726be75a078180e3f02e59866f193b0a99eee8e39c874f 2025-06-13
FileHash-SHA256 670be5b8c7fcd6e2920a4929fcaa380b1b0750bfa27336991a483c0c0221236a 2025-06-13
FileHash-SHA256 673090abada8ca47419a5dbc37c5443fe990973613981ce622f30e83683dc932 2025-06-13
FileHash-SHA256 8135f126764592be3df17200f49140bfb546ec1b2c34a153aa509465406cb46c 2025-06-13
FileHash-SHA256 d54fa589708546eca500fbeea44363443b86f2617c15c8f7603ff4fb05d494c1 2025-06-13
FileHash-SHA256 db1aa52842247fc3e726b339f7f4911491836b0931c322d1d2ab218ac5a4fb08 2025-06-13
FileHash-SHA256 ef8c2f3c36fff5fccad806af47ded1fd53ad3e7ae22673e28e541460ff0db49c 2025-06-13
FileHash-SHA256 f08676eeb489087bc0e47bd08a3f7c4b57ef5941698bc09d30857c650763859c 2025-06-13
URL https://captchaguard.me/?key= 2025-06-13
domain captchaguard.me 2025-06-13
domain microads.top 2025-06-13
domain request.open 2025-06-13