logo

A Look at a Novel Discord Phishing Attack

ID: b585d4ad-abb9-5d68-bee3-a0df14275e1b

STIX ID: report--b585d4ad-abb9-5d68-bee3-a0df14275e1b

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense ARC Labs documents MalenuStealer, a recently observed infostealer campaign in which attackers use compromised Discord accounts to distribute a faux “game” (encrypted RAR with password) that unpacks to a self-extracting installer; the installer runs an Electron-wrapped, obfuscated JavaScript stealer that kills browsers/messengers, harvests data, and exfiltrates it in a machine-named ZIP. Researchers performed dynamic analysis, identified behavioral TTPs (including Chromium remote-debugging usage and taskkill behavior), and published hunting queries and detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.