Go Back   Carder.life > [en] International Forum > Carding News



Reply
 
Thread Tools Display Modes
  #1  
Old 04-10-2025, 11:16 AM

Artifact Artifact is offline
Administrator
Join Date: Jan 2024
Posts: 0
Default


Researchers from https://twitter.com/malwrhunterteam/...36824070500353 have spotted a new piece of remote access trojan (RAT) dubbed ‘Abaddon’ that is likely the first malware using the Discord platform as command and control. The Abaddon malware connects to the Discord command and control server to check for new commands to execute.

Experts also warn that the author of the malware also developed a malware feature.
In the past, other threat actors already abused the Discord platform for different purposes, such as using it as a stolen data drop.
“In the past, we have reported on how threat actors use https://www.bleepingcomputer.com/new...t-stolen-data/ or have created malware thathttps://www.bleepingcomputer.com/new...y-new-malware/ to have ithttps://www.bleepingcomputer.com/new...ohack-malware/.” https://www.bleepingcomputer.com/new...mware-feature/Bleeping Computer that first reported the news.
Abaddon implements data-stealing feature, it was designed to steal multiple data from the infected host, including Chrome cookies, saved credit cards, and credentials, Steam credentials, Discord tokens and MFA information.
The malware also collects system information such as country, IP address, and hardware information.
According to Bleeping Computer the malware supports the following commands:
  • Steal a file or entire directories from the computer

  • Get a list of drives

  • Open a reverse shell that allows the attacker to execute commands on the infected PC.

  • Launch in-development ransomware (more later on this).

  • Send back any collected information and clear the existing collection of data.


The malicious code connects to the Command & Control every ten seconds for new tasks to execute.
Experts pointed out that the malware also implements the commands to encrypt files of the infected system and decrypt them.
The ransomware feature appears to be under development.
  #2  
Old 04-10-2025, 11:42 AM

lyfe100 lyfe100 is offline
Join Date: Dec 2023
Posts: 0
Default


Damn those hackforums kids at it again. My annoyance is those kids never make any real money with their great inventions cos they're simply a whole bunch of scared kids selling $15 monthly subscriptions for their numerous RATS and botnets, and then will tell you to use their virus for educational purposes only after you pay or get banned from using it smh
Reply

Tags
NULL


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT. The time now is 05:20 PM.