This fake Discord software could infect your PC


A new variant of the AnarchyGrabber malware has been discovered by MalwareHunterTeam which modifies Discord client files in order to evade detection and steal user accounts every time someone logs into the popular chat service.
The malware is distributed on hacking forums and in YouTube videos to allow cybercriminals to steal user tokens for a logged-in Discord user once it is executed. These user tokens are then uploaded back to a Discord channel under the attacker’s control where they can be collected and used to log in as their victims.
The original version of AnarchyGrabber comes in the form of an executable that can easily be detected by security software and only has the ability to steal tokens while it is running.
However, a newer version of the malware has been altered to avoid detection and establish persistence on a user’s machine.
AnarchyGrabber2
In an effort to make it more difficult for antivirus software to detect the malware and to offer persistence, a hacker has updated AnarchyGrabber to modify the JavaScript files used by the Discord client to inject its code every time it runs.
The new version of the malware has been dubbed AnarchyGrabber2 and when executed, it will modify Discord’s index.js file to inject JavaScript created by its developer.
The new changes to the malware allow it to run additional malicious JavaScript files every time a user opens Discord. Once a user who has the AnarchyGrabber2 running on their system logs into Discord, the scripts will use a webhook to post the victim’s user token to the attacker’s Discord channel along with the message “Brought to you by The Anarchy Token Grabber”.
Unfortunately, even if the original malware executable is deleted, the client files will already be modified. Security software has a hard time detecting these client modifications which allows the code to remain on a user’s machine without them even knowing their accounts are being stolen.
Until Discord decides to add client integrity into its software, Discord accounts will continue to be at risk from AnarchyGrabber2 and other malware that modifies client files.
Via BleepingComputer
A new variant of the AnarchyGrabber malware has been discovered by MalwareHunterTeam which modifies Discord client files in order to evade detection and steal user accounts every time someone logs into the popular chat service. The malware is distributed on hacking forums and in YouTube videos to allow cybercriminals to…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010