PULSE NAME
Discord Invite Hijacking: How Fake Links Are Delivering Infostealers
WHITE AlienVault 2025-06-20 Modified: 2025-07-20
36
IOCs
MEDIUM VOLUME
Cybercriminals are exploiting Discord's invite system and content delivery features to distribute malware and steal sensitive data. They use fake invite links, expired codes, and vanity URLs to redirect users to malicious servers. The attack chain involves a sophisticated combination of social engineering, multi-stage loaders, and time-based evasion tactics. Victims are tricked into authorizing a fake bot, which leads to the deployment of AsyncRAT and a customized Skuld Stealer. These malware variants target browser credentials, Discord tokens, and cryptocurrency wallets. The campaign uses trusted platforms like GitHub and Bitbucket to host encrypted payloads, and employs advanced techniques to bypass security measures and maintain persistence.
Indicators of Compromise (9 / 36 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 363a97ec2f5b63c9d5e8f0f2daf487c9db423a58 2025-06-20
FileHash-SHA1 4501e8029fedadab2cbaa9e504301200c4cd2bfe 2025-06-20
FileHash-SHA1 4e9ba566d5f0d8ab7f600e5b12f0b1edecff5f3d 2025-06-20
FileHash-SHA1 8dca55b5485aa1d9fa8716f15ee3802d8e8f43e5 2025-06-20
FileHash-SHA1 94b3250879e3600b24318e47620ae5aab15d8640 2025-06-20
FileHash-SHA1 96d660016368f406560631d9c142e7946cb49c46 2025-06-20
FileHash-SHA1 9af70bbe2eb389a76dafeb7bdab890799f14620b 2025-06-20
FileHash-SHA1 d383b44cb3c7e5a2e460300182d89932869a7281 2025-06-20
FileHash-SHA1 e6b9aca260498ed928e580fb920e78135a5a5150 2025-06-20