logo

Malware Distribution Uses Discord CDN

ID: 2ca127a8-e28a-5194-91f7-c55cdd8063b5

STIX ID: report--2ca127a8-e28a-5194-91f7-c55cdd8063b5

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report documents active Discord-based malware campaigns that lure gamers with pirated/replicated game software hosted on cdn.discordapp.com; analyzed payloads include Epsilon ransomware (file encryption and shadow-copy deletion), Redline stealer (credential and wallet theft), XMRig miner (cryptomining and game/process killing), and multiple Discord token stealers (TroubleGrabber). The report provides technical behavior, persistence and C2 details, MITRE ATT&CK mappings, and a table of IOCs (file hashes and malicious Discord CDN URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.