logo

UNC5174 Group’s Discord Bot Backdoor Malware

ID: 09341e63-72f8-5639-9859-752852c666be

STIX ID: report--09341e63-72f8-5639-9859-752852c666be

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-11-25

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC analyzed a campaign attributed to UNC5174 that deployed a Discord bot backdoor built with the open-source discordgo Golang library to use Discord as a covert C2 channel. The malware supports remote command execution, file upload/download, and system information collection; the report documents persistence tactics (sequential backdoors), runtime-decrypted tokens/server IDs, an MD5 hash, and example indicators, and warns that using Discord greatly increases detection difficulty because malicious traffic blends with legitimate platform usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.