Discord flaw lets hackers reuse expired invites in malware campaign

Discord flaw lets hackers reuse expired invites in malware campaign

Hackers are exploiting flaws in Discordโ€™s invite system by hijacking expired or deleted invite links to redirect users to malicious sites hosting remote access trojans and info-stealing malware. This attack campaign has affected over 1,300 users across multiple countries by using fake communities and multi-stage infection chains. #DiscordInviteHijack #ClickFixMalware

Keypoints

  • Hackers reuse expired or deleted Discord invite codes to create malicious links.
  • The flaw involves Discordโ€™s handling of temporary and permanent invite codes, including vanity links.
  • Malicious servers appear legitimate but only show a single verification channel.
  • Users are tricked into executing PowerShell commands that download malware like AsyncRAT and info stealers.
  • Admins are advised to use permanent invites and remain cautious of outdated links and suspicious verification requests.

Read More: https://www.bleepingcomputer.com/news/security/discord-flaw-lets-hackers-reuse-expired-invites-in-malware-campaign/