discord (3)

10154125073?profile=RESIZE_400xActivity Summary - Week Ending on 25 February 2022:

  • Red Sky Alliance identified 9,248 connections from new IP’s checking in with our Sinkholes
  • com[.]tr Hit 336 times last week.
  • Analysts identified 9,095 new IP addresses participating in various Botnets
  • DriveGuard
  • Magecart
  • Cloud Security
  • Impacket & APT10
  • CyberWar
  • Stealing Discord Tokens
  • Cyclops Blink
  • Russian Cyber-Attacks; Ukraine Attack

Link to full report: IR-22-056-001_weekly056.pdf

9861149277?profile=RESIZE_400xAn advanced malware operation on Discord utilizes the Babadeda crypter to hide malware that targets the crypto, NFT, and DeFi communities.  Babadeda is a crypter used to encrypt and obfuscate malicious payloads in what appear to be harmless application installers or programs.  Starting in May 2021, threat actors have been distributing remote access trojans obfuscated by Babadeda as a legitimate app on crypto-themed Discord channels.  Due to its complex obfuscation, it has a very low AV detection

8892667262?profile=RESIZE_400xThe malware seems like nothing special at first, but further exploration shows it can wreak serious damage in follow-on attacks.  The NitroRansomware malware strain is changing the ransomware norm by demanding Discord Nitro gift codes from victims instead of actual money.  Discord is a VoIP, instant messaging and digital-distribution platform designed for creating communities. Users communicate with voice calls, video calls, text messaging, media and files in private chats or as part of communit