Malware Distribution Uses Discord CDN
ID: 2ca127a8-e28a-5194-91f7-c55cdd8063b5
STIX ID: report--2ca127a8-e28a-5194-91f7-c55cdd8063b5
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report documents active Discord-based malware campaigns that lure gamers with pirated/replicated game software hosted on cdn.discordapp.com; analyzed payloads include Epsilon ransomware (file encryption and shadow-copy deletion), Redline stealer (credential and wallet theft), XMRig miner (cryptomining and game/process killing), and multiple Discord token stealers (TroubleGrabber). The report provides technical behavior, persistence and C2 details, MITRE ATT&CK mappings, and a table of IOCs (file hashes and malicious Discord CDN URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
