Emojis Control the Malware in Discord Spy Campaign
ID: 9e048905-bfb2-5075-8748-ec132aaf310f
STIX ID: report--9e048905-bfb2-5075-8748-ec132aaf310f
Feed Name: Dark Reading
Threat Score
UTA0137, a Pakistan-linked APT, is using the Dirty Pipe Linux vulnerability (CVE-2022-0847) to gain root on targets and deploying Disgomoji — a Discord-based malware controlled with emojis — to persist (via cron), steal files (including from USB devices), capture screenshots, and exfiltrate data; organizations should patch affected Linux systems, audit Discord connectivity, and consider blocking unnecessary Discord access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
