New Rust Malware "ChaosBot" Leverages Discord for Stealthy Command and Control
ID: 695f5a1d-bdfb-5323-9486-1af838d089d3
STIX ID: report--695f5a1d-bdfb-5323-9486-1af838d089d3
Feed Name: Resources-2
Date Published: 2025-10-21
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
**Executive summary:** ChaosBot is a sophisticated Rust-based backdoor that leverages Discord API tokens and per-victim Discord channels for covert C2, enabling interactive PowerShell-based shell commands, file download/upload, and screenshot exfiltration; initial access observed includes compromised Cisco VPN and an over-privileged AD service account, DLL side-loading, and decoy .lnk phishing, while evasion employs ETW patching and VM MAC checks—recommendations include MFA, WMI restrictions, application whitelisting, and monitoring for Discord API traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
