This New Discord Virus is Only Targeting Scammers?

preview_player
Показать описание

Discord is filled with script kiddies, e-gangsters, scammers, and hackers. And that's the perfect target for this new Discord malware, people with zero morals and zero frontal lobe. But how does this malware infect Discord's e-gangsters? In what "Discord tools" does this malware hide? And what does this Discord malware do?

More importantly, why is it spreading to Discord and why is the malware problem getting worse?

SOCIALS
-----------------------------------------------------------------------------
Discord Server

Twitter

TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - I'm going to hack Discord... i think
05:18 - Cracking the Malware
07:57 - Malware Decoded?
12:07 - Malware DLC
17:05 - Why is it spreading to Discord and getting worse?
Рекомендации по теме
Комментарии
Автор

i do not understand how a channel can be dedicated to discord, a chatting app while being so amusing. This is beyond me but i love it when a video is uploaded

dienzer
Автор

I was almost surprised that list of browsers didn't include Tor, but then I realized Tor runs on the Firefox engine. Firefox isn't a Chromium browser.

UlyssesK
Автор

Hi NTTS, someone who does a bit of software engineering (and understands a smidge about protective measures); the likely reason every stage of the malware is encrypted via fernet is that it makes it difficult for things like Malwarebytes/etc to get a really easy detection via looking for some very specific key triggers; such as the ones you can see after decrypting it. (e.g searching for passwords, onedrives, etc - all of which tend to be either detected by their new nifty AI methods, or just heuristically detected due to the amount it accesses).

It isn't meant to stop someone from analysing it; the malware isn't obfuscated (in the way you'd typically associate with malware obfuscation), it's simply meant to hit the lowest bar, the dumbest of the dumb, so for now; this works as it helps prevent an immediate detection (and likely the reason they use webpages which they can change remotely; so if one variation gets detected, either by signature or by heuristic methods, they can modify the code with GPT or by hand to no longer be detected!)

toxicthereporter
Автор

Eric Parker has a malware analysis video on this exact piece of malware from August 2024 (his vid about discord raiding tools). It's a good video. According to his investigations, the stolen accounts also end up being used to raid servers, so in the end, innocent people are still affected by this.

cinderwolf
Автор

13:26 adding comments to your MALWARE is crazy 😭

cherrypluck
Автор

when hackers get hacked in the most obvious way

Me_devlogs
Автор

I love that due to how I configure my Windows, the code would genuinely do nothing.
Heck they are not even preventing anyone to check the website's stuff by 403.

ElFrod
Автор

0:22 as someone who doesn’t even know how to code but loves computer and has a passion to learn coding even i know not to download a malware builder 😂😂

xilliam
Автор

10:21 I''m so glad that I'm not the only one having a passionate hatred for OneDrive.

StarSpacewolf
Автор

5:31 this is called "invisible code", which is a technique which some malware written on python uses, if the case you didn't know.
Luckily, since you have the line warp enabled, that make finding some invisible code easier.

BloomDevelop
Автор

i believe tranium went on a similar escapade with trying to figure out how malware can be installed without triggering defender at all, all that obscuring (in this case via fernet) helps avoid defender triggering, it doesnt do a good job with malwarebytes for example because that registers it doing funky stuff, basically splitting the payload into multiple relatively (to defender) inconspicuous packages

_ms
Автор

1:56 rare footage of no text to speech being freaky😂

dprintingwithleon
Автор

The main reason my passwords aren’t saved under an obvious name and have a file called password that just says “lmao nice try nerd”

MapleSyrupKoala
Автор

YOU explaining the code would actually not make me put to sleep.

megadeth
Автор

Bro im a cybersecurity geek and am finally moving on from help desk after a year and a half into a further stepping stone. I try qatching maleare analysis videos and they are just so boring and intricate that its hard to follow along. I love how you explained this analysis because it actually seems like you are on my wavelength. If i want to learn specifics ill figure it out myself. Too complicated. Love this stuff. Hope to keep seeing more.

unknwn.
Автор

you are entirely correct about the encryption thing. It's called obfuscation, and it's main purpose is to make figuring out what's actually going on VERY annoying for automated tools. However, to do it properly you have to actually use variety, not just spam the same gimmick over and over.

kenbaird
Автор

1:42 Simple- a majority of devs are depressed, nothing better to do than to code. And an even bigger majority tries to act like a dev.

jderpyy
Автор

It's crazy that discord is an entire ecosystem. I remember being chronically online during covid and living that way for a while after the lockdown. But i just recently met people that still live like that. (Met playing a videogame obv.) And some people just live their entire existence out on discord...

loops
Автор

thanks for the tutorial on how to make malware with code examples! :D

kai_cenatRizzTehe
Автор

I use firefox 🗿 9:14
also when i tried analysing my self the discord server was gone and paylode websites were marked and suspicious by Kaspersky

EvoFireGaming
visit shbcf.ru