{"id":271763,"date":"2024-01-24T06:04:59","date_gmt":"2024-01-24T11:04:59","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=325264"},"modified":"2025-07-01T17:10:16","modified_gmt":"2025-07-02T00:10:16","slug":"be-careful-using-discord-they-are-stealing-key-information-from-users-and-servers","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/be-careful-using-discord-they-are-stealing-key-information-from-users-and-servers\/","title":{"rendered":"Be careful using Discord: they are stealing key information from users and servers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Trellix cybersecurity researcher Gurumoorthi Ramanathan details the malware and data extraction techniques used by hackers to attack Discord, the most used application by gamers to communicate.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Discord\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/f4c4dac6-c830-11e6-bd9d-599bf3caf9c2\/3298232087\/discord-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Discord<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.trellix.com\/about\/newsroom\/stories\/research\/java-based-sophisticated-stealer-using-discord-bot-as-eventlistener\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"According to the report\">According to the report<\/a>, threat actors have built a sophisticated infostealer called NS-STEALER. <strong>They distribute it through ZIP files disguised as cracked software<\/strong> (pirated Windows 11 or unlicensed Photoshop).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a victim extracts the compressed file, they will find a Windows shortcut titled &#8220;Loader GAYve&#8221; that, if executed, will deploy a malicious Java program.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This program will do two things:<\/strong> first, it will create a folder called &#8220;NS-&lt;11-digit_random_number&gt;&#8221;, where it will store all the collected information. Then, it will start capturing the data.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"985\" height=\"720\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/01\/java-based-sophisticated-stealer-1.jpg\" alt=\"\" class=\"wp-image-271766\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/01\/java-based-sophisticated-stealer-1.jpg 985w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/01\/java-based-sophisticated-stealer-1-300x219.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/01\/java-based-sophisticated-stealer-1-768x561.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/01\/java-based-sophisticated-stealer-1-150x110.jpg 150w\" sizes=\"auto, (max-width: 985px) 100vw, 985px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Looking for sensitive data to steal money<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>NS-STEALER will search for information stored in over two dozen browsers: <\/strong>cookies, credentials, and autofill data. It will then start taking screenshots of the infected device, collecting system information and the list of programs installed on the device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Then it will extract Discord tokens, as well as Steam and Telegram session data<\/strong>. Finally, it will filter all of the above to a Discord Bot channel. That&#8217;s where all the information ends up to monetize the hacking.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Alert! New Java <a href=\"https:\/\/twitter.com\/hashtag\/malware?src=hash&amp;ref_src=twsrc%5Etfw\">#malware<\/a> &quot;NS-STEALER&quot; uses bots to steal your logins and wallet data from popular browsers and exfiltrates secrets via Discord.<br><br>Learn more: <a href=\"https:\/\/t.co\/vAdo3RQt3A\">https:\/\/t.co\/vAdo3RQt3A<\/a><a href=\"https:\/\/twitter.com\/hashtag\/cybersecurity?src=hash&amp;ref_src=twsrc%5Etfw\">#cybersecurity<\/a><\/p>&mdash; The Hacker News (@TheHackersNews) <a href=\"https:\/\/twitter.com\/TheHackersNews\/status\/1749395492310847542?ref_src=twsrc%5Etfw\">January 22, 2024<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Taking into account the highly sophisticated function of collecting sensitive information and the use of X509Certificate to support authentication, this malware can quickly steal information from the victim&#8217;s systems with [Java Runtime Environment]&#8221;, explains Ramanathan.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Discord\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/f4c4dac6-c830-11e6-bd9d-599bf3caf9c2\/3298232087\/discord-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Discord<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This is not the first time that hackers find a way to abuse Discord for their nefarious purposes<\/strong>. In fact, Discord has been targeted by hacks for years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Be careful and do not download anything suspicious through Discord or unreliable websites.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When a victim extracts the compressed file, they will find a Windows shortcut titled &#8220;Loader GAYve,&#8221; and if executed, you are in trouble.<\/p>\n","protected":false},"author":9265,"featured_media":271765,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[2324],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-271763","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiondiscord"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/271763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9265"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=271763"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/271763\/revisions"}],"predecessor-version":[{"id":315093,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/271763\/revisions\/315093"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/271765"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=271763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=271763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=271763"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=271763"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=271763"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=271763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}