A new type of malware known as 'Vare' has been found to be spread through the widely-used chat platform, Discord, which has over 300 million active users. Researchers from CyberArk Labs, a US-based identity security company, discovered the malware and observed that it utilises Discord to carry out its activities.
Written in Python, Vare is a type of malware that serves as an information stealer. It employs Discord as both a target for theft and an infrastructure for data exfiltration - the unauthorised removal or transfer of data from a device.
Discord Nitro has been identified as the root cause of the malware's presence on the platform. Nitro provides users with various enhanced features, such as the ability to send larger files and longer messages, and higher-quality video streaming, among others, in exchange for a monthly fee.
Security researchers have connected this malware to a nascent group called 'Kurdistan 4455,' located in southern Turkey. The group is still in its early stages of formation.
Rather than targeting users directly, the 'Kurdistan 4455' malware group has employed previous tactics to target other malware groups, resulting in their success with minimal exertion.
Upon discovering the malware, the researchers informed Discord's support team about the various ways in which attackers exploit the platform's features, including the new malware group.
"However, despite our numerous attempts we did not get a definitive response from Discord," they said in a blog post.
Security researchers examined 2,390 public repositories on GitHub linked to Discord malware and found that 44.5% consisted of standalone malware, mostly written in Python. 20.5% were written in JavaScript and primarily used the injection technique to target Discord.
"Vare is a perfect case of how publicly available repositories are being used to help arm cybercrime groups and how attackers can leverage Discord's infrastructure maliciously," said researchers.
Follow Gadgets Now on Facebook and Twitter. For the latest news, tech news, breaking news headlines and live updates checkout Gadgetsnow.com