logo

Discord Spy: SolyxImmortal Malware Uses Webhooks for Stealthy Theft

ID: d102b7e5-1ff9-509f-bb02-e7f3e3e0eb5e

STIX ID: report--d102b7e5-1ff9-509f-bb02-e7f3e3e0eb5e

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ddos

...
...

SolyxImmortal is a Python-based Windows infostealer that bundles credential theft (DPAPI-decrypted browser data), keylogging, screenshot capture, document harvesting, and persistence into a single long-running implant; it uses hardcoded Discord webhooks for C2 and was distributed via underground Telegram channels, likely by mid-tier criminals (medium confidence for a Turkish-speaking origin), posing a stealthy surveillance and data-exfiltration risk to individuals and small organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.