Friday, September 11, 2026

Hackers Compromise Discord Invite to Inject Malicious Links Delivering AsyncRAT

Threat actors have exploited Discord’s invite system to distribute malicious links, ultimately delivering AsyncRAT and other harmful payloads.

Discord, a widely trusted platform for gamers, developers, and communities, has become a target for cybercriminals who abuse its infrastructure particularly the invite link and content delivery features to orchestrate phishing schemes and malware infections.

This campaign, detailed in a recent cybersecurity report, reveals how attackers leverage fake Discord invites, social engineering, and hijacked vanity URLs to compromise user accounts and steal sensitive data, with a primary focus on cryptocurrency and gaming ecosystems.

Exploiting Discord’s Invite System

The attack begins with the manipulation of Discord invite links, which are unique URLs used to access servers or group chats.

AsyncRAT
Permanent Discord invite links

Legitimate links typically follow formats like https://discord.gg/<code>, but attackers craft deceptive lookalike domains such as discord-giveaway[.]net or discordnitro[.]gift to trick users.

A critical vulnerability lies in the reuse of expired or deleted invite codes, especially vanity URLs tied to boosted servers.

AsyncRAT
Misleading Behavior in Invite Code Settings

Once a temporary invite expires, attackers with Level 3 Boost status can reclaim the code, redirecting unsuspecting users to malicious servers.

According to Dark Atlas Report, this hijacking exploits residual trust in previously shared links on platforms like Twitter or Reddit, leading victims to join fake servers designed to mimic legitimate communities.

Multi-Stage Infection Chain

Once users join these attacker-controlled servers, they are often funneled into a single channel, such as #verify, where a fake bot commonly named “Safeguard” or “TrustBot” prompts them to click a “Verify” button.

This interaction redirects users to phishing sites like captchaguard[.]me, which abuse Discord’s OAuth2 authorization flow to harvest data before presenting a spoofed UI mimicking the Discord desktop app.

Clicking “Verify” on these pages triggers JavaScript that copies a malicious PowerShell command to the clipboard, initiating the download of AsyncRAT (a Remote Access Trojan) and Skuld Stealer.

AsyncRAT, identified by hashes like 53b65b7c38e3d3fca465c547a8c1acc53c8723877c6884f8c3495ff8ccc94fbe, enables full remote control, keylogging, and file manipulation, while Skuld targets browser credentials, Discord tokens, and cryptocurrency wallets like Exodus through .asar file injections.

The malware also uses Discord webhooks for data exfiltration and leverages platforms like GitHub and Bitbucket to host encrypted payloads, ensuring stealth and persistence.

This campaign’s impact is notable, with download counts from hosting repositories exceeding 1,300, indicating a potentially large victim pool across regions like the United States, Vietnam, and the UK.

Despite Discord’s efforts to remove malicious bots, the underlying techniques relying on invite abuse and modular delivery chains remain viable for future attacks. Users are urged to scrutinize invite links and avoid unverified verification prompts to mitigate risks.

Indicators of Compromise (IOCs)

TypeIndicator
SHA256 (AsyncRAT)53b65b7c38e3d3fca465c547a8c1acc53c8723877c6884f8c3495ff8ccc94fbe
SHA256 (Skuld Stealer)8135f126764592be3df17200f49140bfb546ec1b2c34a153aa509465406cb46c
Phishing URLcaptchaguard[.]me
C2 Address101.99.76.120
Webhook URLhttps://discord[.]com/api/webhooks/1355186248578502736/_RDywh_K6…

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News