logo

Emojis Control the Malware in Discord Spy Campaign

ID: 9e048905-bfb2-5075-8748-ec132aaf310f

STIX ID: report--9e048905-bfb2-5075-8748-ec132aaf310f

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2024-06-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

UTA0137, a Pakistan-linked APT, is using the Dirty Pipe Linux vulnerability (CVE-2022-0847) to gain root on targets and deploying Disgomoji — a Discord-based malware controlled with emojis — to persist (via cron), steal files (including from USB devices), capture screenshots, and exfiltrate data; organizations should patch affected Linux systems, audit Discord connectivity, and consider blocking unnecessary Discord access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.