National Cyber Warfare Foundation (NCWF) Forums


Is the Abaddon RAT the first malware using Discord as C&C?


0 user ratings
2020-10-25 16:00:31
milo
General News

Abaddon is the first RAT that uses the freeware instant messaging and VoIP app and digital distribution platform Discord as a command & control server. Researchers from MalwareHunterTeam have spotted a new piece of remote access trojan (RAT) dubbed ‘Abaddon’ that is likely the first malware using the Discord platform as command and control. The […]


The post Is the Abaddon RAT the first malware using Discord as C&C? appeared first on Security Affairs.




Abaddon is the first RAT that uses the freeware instant messaging and VoIP app and digital distribution platform Discord as a command & control server.





Researchers from MalwareHunterTeam have spotted a new piece of remote access trojan (RAT) dubbed ‘Abaddon’ that is likely the first malware using the Discord platform as command and control. The Abaddon malware connects to the Discord command and control server to check for new commands to execute.











Experts also warn that the author of the malware also developed a malware feature.





In the past, other threat actors already abused the Discord platform for different purposes, such as using it as a stolen data drop.





“In the past, we have reported on how threat actors use Discord as a stolen data drop or have created malware that modifies the Discord client to have it steal credentials and other information.” reported Bleeping Computer that first reported the news.





Abaddon implements data-stealing feature, it was designed to steal multiple data from the infected host, including Chrome cookies, saved credit cards, and credentials, Steam credentials, Discord tokens and MFA information.





The malware also collects system information such as country, IP address, and hardware information.





According to Bleeping Computer the malware supports the following commands:





  • Steal a file or entire directories from the computer
  • Get a list of drives
  • Open a reverse shell that allows the attacker to execute commands on the infected PC.
  • Launch in-development ransomware (more later on this).
  • Send back any collected information and clear the existing collection of data.




The malicious code connects to the Command & Control every ten seconds for new tasks to execute.





Experts pointed out that the malware also implements the commands to encrypt files of the infected system and decrypt them.





The ransomware feature appears to be under development.

















Pierluigi Paganini





(SecurityAffairs – hacking, Abaddon)























The post Is the Abaddon RAT the first malware using Discord as C&C? appeared first on Security Affairs.



Source: SecurityAffairs
Source Link: https://securityaffairs.co/wordpress/109971/malware/abaddon-rat-discord-cc.html?utm_source=rss&utm_medium=rss&utm_campaign=abaddon-rat-discord-cc


Comments
new comment
Nobody has commented yet. Will you be the first?
 
return to home



Copyright 2012 through 2020 - National Cyber Warfare Foundation - All rights reserved worldwide.