logo

Hackers steal Discord accounts with RedTiger-based infostealer

ID: b33e5c30-1c45-5dba-a3db-7ddba2f46b05

STIX ID: report--b33e5c30-1c45-5dba-a3db-7ddba2f46b05

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-26

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A report describes how threat actors are weaponizing the open-source RedTiger red-team framework to produce a Windows info-stealer that harvests Discord account tokens, profile and payment data, browser-stored credentials and wallets, and game files; it injects JavaScript into Discord to capture API activity, uses PyInstaller-built binaries disguised as gaming/Discord tools, employs anti-analysis techniques, and exfiltrates stolen data via GoFile with results sent over Discord webhooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.