logo

RAT Malware Operating via Discord Bot

ID: 9e23dea9-7cad-5642-8e06-c8ffb282ccc5

STIX ID: report--9e23dea9-7cad-5642-8e06-c8ffb282ccc5

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-10-22

Date Updated: 2026-04-26

Author: ATCP

...
...

This report analyzes PySilon, an openly available Discord-based RAT builder that converts customized Python bot code into executables using PyInstaller. The malware creates a per-host Discord channel for command-and-control, persists via self-replication and registry run keys, evades virtual machines, exfiltrates credentials and browser data (including Discord tokens), performs keylogging, screen/audio recording, arbitrary file upload/download, process and command execution, and can encrypt files using Fernet (producing .pysilon files) without leaving a ransom note; because it leverages legitimate Discord infrastructure, detection and attribution are more difficult and threat actors can easily adopt the tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.