PULSE NAME
Discord Invite Hijacking: How Fake Links Are Delivering Infostealers
WHITE AlienVault 2025-06-20 Modified: 2025-07-20
36
IOCs
MEDIUM VOLUME
Cybercriminals are exploiting Discord's invite system and content delivery features to distribute malware and steal sensitive data. They use fake invite links, expired codes, and vanity URLs to redirect users to malicious servers. The attack chain involves a sophisticated combination of social engineering, multi-stage loaders, and time-based evasion tactics. Victims are tricked into authorizing a fake bot, which leads to the deployment of AsyncRAT and a customized Skuld Stealer. These malware variants target browser credentials, Discord tokens, and cryptocurrency wallets. The campaign uses trusted platforms like GitHub and Bitbucket to host encrypted payloads, and employs advanced techniques to bypass security measures and maintain persistence.
Indicators of Compromise (9 / 36 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3d32539314f681bc250ee749e1dc4538 2025-06-20
FileHash-MD5 4ef039f4fdd0df3a9d20feb34b1cfd62 2025-06-20
FileHash-MD5 6e397edeb705cdd9de4cb2f16dbed271 2025-06-20
FileHash-MD5 7834b9b4574b68ba85eabd79b9770b08 2025-06-20
FileHash-MD5 8a5449c0ed6d73f0dc1be74156413d02 2025-06-20
FileHash-MD5 b5d26bf46c4732be2a28ba4fc88d4241 2025-06-20
FileHash-MD5 c6b5034526b90943b8c478494068a08d 2025-06-20
FileHash-MD5 f9db8601d94df9c026331066a2ba9ae1 2025-06-20
FileHash-MD5 fc13b02d22f6fe582e2948259660e3d5 2025-06-20