Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
This malware targets over 20 applications with the express purpose of stealing Discord tokens
MITRE ATT&CK® Techniques ... Discovery T1007 System Service Discovery
The malware configuration also contains Flag variables and a list of programs to terminate during execution
The malware uses the API hxxps[:]//discord.com/api/v9/users/@me and appends a Discord authorization token to identify Account information, such as email, mobile, and billing-related details.
MITRE ATT&CK® Techniques ... Discovery T1124 System Time Discovery
The malware also checks for the disk size of the victim’s system. If it’s below 50GB, it terminates itself. It then reads the following registry keys for identifying the Virtual environment.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.