The Scariest Fake Discord Login Phishing Scam!

preview_player
Показать описание

However, what happens when you get a popup that has the normal discord URL and looks legit?

Well surprisingly there are some fake discord login pages that can disguise their URL by using some HTML trickery. Thankfully, there is one very easy way to tell if we are about to be phished.

Use promo code: ISubscribedToNTTS for 0% off your Walmart order.

SOCIALS
-----------------------------------------------------------------------------
Discord Server

TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - Introduction
00:36 - The scam
02:04 - Explaining the popup
05:42 - Conk clue shun
07:00 - How to recover your account
08:03 - Outro

MUSIC
-----------------------------------------------------------------------------
C418 - Minecraft - Volume Alpha (Minecraft music)
Рекомендации по теме
Комментарии
Автор

The funny thing is that they used a backslash "\" in the fake URL instead of a forward slash "/" which gives away the entire scam easily if you pay a little bit of attention.

Parsa
Автор

Scammers are getting really good these days but I think that takes the cake. Very impressive. Its a shame skilled devs are doing stuff like that, what a waste of skills

ethanrushbrook
Автор

Also love how he doesn't mention the backslashes in the URL of the fake popup. But on a serious note, this dude is doing God's work 🙏

dummmonke
Автор

the fact that he didn't even realize the backslash instead of forward slash speaks levels about how dangerous these scams can be

WanderingShogun
Автор

Great job at describing how you can tell it's a fake pop-up, but you forgot one thing, a pop-up of the actual Discord website takes time to load, instead of this pop-up instantly appearing.

ThatCarrotGuy
Автор

"Just take a look at the URL and you will see a few odd things..."
That HUGE danger sign looks convenient

yellowtapes
Автор

Thank you, NTTS. Thank you for making us aware of the phishy (I'll see myself out) Discord scams.

SpeedstersUnited
Автор

Glad to see a honest to god legitimate explanation of a fairly sophisticated phish, instead of the usual fear mongering and outright lies usually spread on social media about Discord phishing. Need more of this!

zephyfoxy
Автор

Another way to tell if the Popup is real is to check your programs bar on the bottom of the screen in Windows. If it is a real popup you should see chrome or whatever browser you are using showing two windows, the main browser, then the popup. Or just look for the popup in general if you already have more than one browser window open.

IWickDev
Автор

I love how this guy explains so good and doesnt use music that bleeds our ears

LeslieCosmik
Автор

One of the oldest Steam Account scams finally moves to discord, love to see it

charuseTV
Автор

You can also tell it’s a phishing attempt because the whole authorisation is made on the official discord website and not on a third-party-site.

maximats
Автор

As a web developer, I can say the iframe explanation was pretty accurate here (and yeah "src" does refer to the source URL) - this particular tactic isn't limited to just Discord either; I believe other phishing scams have started to adopt the "fake browser window" strategy as well, so that's definitely something to watch out for.

In addition, it seems the developer of the login page _might've_ goofed up the loading icon for the QR code login method.

FairPlay
Автор

Not gonna lie, this would've caught me off guard. I was pretty lost until you pointed out the whole window not leaving the window bit and I went from "Wtf" to "OH SHIT YOU RIGHT!" moment. Thankyou for this!!

xipherzen
Автор

I just noticed on the 'scam' discord login page, they somehow failed to spell "Mobile" correct on the QR code area lmao
you'd think that given how accurate they wanted their scam to look they made a spelling error

Ommoo
Автор

Also, one thing that I noticed that is also odd is that, where it says "Log in with QR Code" below that it says "Scan this with the Discord *MOBILY* app to log in instantly". In the original it goes "Scan this with the Discord *MOBILE* app to log in instantly". Its a grammar mistake that is bearly noticeable, but still can give off if the website is a scam or no.

lxbilol
Автор

This is so scary, because i always login on google and literally everyday
Thanks for the info:))

AryX
Автор

A subtle anti-phishing protection of password managers: The password manager will not autofill your Discord password on phishing websites. This lack of auto-fill can give users a few seconds to remind them which website they are ACTUALLY on.

ProjSHiNKiROU
Автор

Its absurd how many scams there are on discord and yet discord wont dont anything

ApolloSnips
Автор

This is actually a somewhat new phishing technique. Its called BiTB attack (Browser in the Browser attack) in cybersecurity terms. One can modify that embed depending on the target's browser and easily social engineer someone into thinking its legitimate, as it is very deceiving.

sneharghya
welcome to shbcf.ru