Discord Invite Links Hijacked for Crypto Malware Attacks
Cybercriminals are exploiting Discord''s invite system to deliver malware targeting cryptocurrency wallets. Check Point Research reveals attackers hijack vanity URLs, redirecting users from legitimate sources to malicious servers. The campaign combines phishing techniques with multi-stage loaders to deploy AsyncRAT and a customized Skuld Stealer.
Expired or deleted invite links pose particular risks. Previously shared legitimate links can be repurposed to funnel victims to attacker-controlled servers. This follows a similar phishing campaign uncovered last month where hijacked Discord links led to wallet-draining schemes.
The attack chain demonstrates growing sophistication in crypto-focused cybercrime. Threat actors leverage trusted platforms like Discord to bypass security precautions, capitalizing on users'' familiarity with invite-based community access.