New Discord malware targets NFT and crypto fans

An abstract image of digital security.
(Image credit: Shutterstock)

Researchers have shed light on an ongoing malware campaign that targets cryptocurrency enthusiasts on gaming-centric messaging platform Discord.

Discovered by cybersecurity researchers at Morphisec, the “sophisticated” campaign aims to distribute a malware strain named Babadeda.

“We know that this malware installer [Babadeda] has been used in a variety of recent campaigns to deliver information stealers, RATs [remote access trojans], and even LockBit ransomware,” share the researchers.

TechRadar needs yo...

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> <a href="" data-link-merchant=""" target="_blank">Click here to start the survey in a new window <<

Worse still, the researchers observe that Babadeda uses complex obfuscation to bypass most traditional signature-based antivirus solutions.

Elaborate deception

In their breakdown of the malware, the researchers note that the infection chain begins with the threat actors phishing users interested in crypto and NFTs by sending misleading private messages, asking them to download an app in order to access new features and additional benefits. 

What makes the campaign worth paying attention to is the lengths the threat actors go to in an effort to trick victims into installing Babadeda.  

“Because the actor created a Discord bot account on the official company discord channel, they were able to successfully impersonate the channel’s official account,” note the researchers.

Furthermore, the attackers use several other measures to ensure that the delivery chain looks legitimate even to technical users. For instance, they use cybersquatting to make the URLs of the decoy websites resemble that of genuine ones, and in addition to mimic the user interface, also use SSL certificates dished out by Let’s Encrypt to lend an air of legitimacy to the deception.

Shield yourself online with the best firewall apps and services, and ensure your computers are protected with the best endpoint protection tools

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.