Hackers steal Discord accounts with RedTiger-based infostealer


Attackers are utilizing the open-source red-team software RedTiger to construct an infostealer that collects Discord account knowledge and cost info.

The malware may steal credentials saved within the browser, cryptocurrency pockets knowledge, and recreation accounts.

RedTiger is a Python-based penetration testing suite for Home windows and Linux that bundles choices for scanning networks and cracking passwords, OSINT-related utilities, Discord-focused instruments, and a malware builder.

Discord-related tools in RedTiger
Discord-related instruments in RedTiger
Supply: GitHub

RedTiger’s info-stealer part gives the usual capabilities of snatching system information, browser cookies and passwords, crypto pockets recordsdata, recreation recordsdata, and Roblox and Discord knowledge. It might additionally seize webcam snapshots and screenshots of the sufferer’s display screen.

Though the venture marks its harmful features as “authorized use solely” on GitHub, its free and unconditional distribution and the dearth of any safeguards permit simple abuse.

RedTiger's malware builder
RedTiger’s malware builder
Supply: GitHub

In keeping with a report from Netskope, risk actors at the moment are abusing RedTiger’s info-stealer part, primarily for concentrating on French Discord account holders.

The attackers compiled RedTiger’s code utilizing PyInstaller to type standalone binaries and gave these gaming or Discord-related names.

As soon as the info-stealer is put in on the sufferer’s machine, it scans for Discord and browser database recordsdata. It then extracts plain and encrypted tokens by way of regex, validates the tokens, and pulls the profile, e mail, multi-factor authentication, and subscription info.

Subsequent, it injects customized JavaScript into Discord’s index.js to intercept API calls and seize occasions reminiscent of login makes an attempt, purchases, and even password adjustments. It additionally extracts cost info (PayPal, bank cards) saved on Discord.

Discord data targeted by the malware
Discord knowledge focused by the malware
Supply: Netskope

From the sufferer’s internet browsers, RedTiger harvests saved passwords, cookies, historical past, bank cards, and browser extensions. The malware additionally captures desktop screenshots and scans for .TXT, .SQL, and .ZIP recordsdata on the filesystem.

After amassing the info, the malware archives the recordsdata and uploads them to GoFile, a cloud storage service that enables nameless uploads. The obtain hyperlink is then despatched to the attacker by way of a Discord webhook, together with the sufferer metadata.

Relating to evasion, RedTiger is well-equipped, that includes anti-sandbox mechanisms and terminating when debuggers are detected. The malware additionally spawns 400 processes and creates 100 random recordsdata to overload forensic evaluation.

Spamming deceptive processes
Spamming misleading recordsdata and processes on the host
Supply: Netskope

Whereas Netskope has not shared specific distribution vectors for the weaponized RedTiger binaries, some frequent strategies embody Discord channels, malicious software program obtain websites, discussion board posts, malvertising, and YouTube movies.

Customers ought to keep away from downloading executables or recreation instruments like mods, “trainers,” or “boosters” from unverified sources.

If you happen to suspect compromise, revoke Discord tokens, change passwords, and reinstall your Discord desktop consumer from the official web site. Additionally, clear saved knowledge from browsers and allow MFA all over the place.

46% of environments had passwords cracked, almost doubling from 25% final 12 months.

Get the Picus Blue Report 2025 now for a complete have a look at extra findings on prevention, detection, and knowledge exfiltration tendencies.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles