/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers say cybercriminals are leveraging the automation features, like bots, inside Discord and Telegram to host, distribute, and execute malware schemes

Wednesday, July 27, 2022 // (IG): BB //Buy Me: The Hawk Enigma Ravie Lakshmanan / The Hacker News : New Ducktail Infostealer Malware Targeting Facebook Business and Ad Accounts Steve Zurier / SC Media : Bad actors leverage popular cloud-based messaging apps to launch malware schemes Tweets: Catalin Cimpanu / @campuscodi : Malware families observed using Discord CDN to host malicious payloads -PrivateLoader -Discoloader -Colibri -Warzone RAT -Modi stealer -Raccoon stealer -Smokeloader -Amadey -Agent Tesla -GuLoader -Autohotkey -njRAT Via: https://intel471.com/... Greg Otto / @gregotto : NEW BLOG: Messaging platforms like Telegram and Discord have automation features that users love. Cybercriminals are among those users. Read how cybercriminals are using messaging automation for malware: https://intel471.com/...

Intel471

Context & Ripple Effects

This report extends a documented arc: researchers flagged collaboration tools as malware channels back in April 2021, and Sophos later traced the abuse to Discord's own CDN hosting malicious payloads. What Intel471 adds is the next stage — attackers no longer just borrowing storage, they are exploiting Discord and Telegram's automation features and bots to host, distribute, and execute malware operations end to end.

First-order effects

  • A dozen malware families — PrivateLoader, Discoloader, Colibri, Warzone RAT, Raccoon stealer, Agent Tesla, njRAT among them — are using Discord's CDN to host payloads, making Discord and Telegram de facto malware infrastructure and forcing both platforms' trust-and-safety teams to police abuse inside features built for legitimate users.

Second-order effects

  • The same playbook spills onto adjacent consumer platforms: Guardio Labs later documented fake and compromised Facebook accounts pushing Messenger phishing at business accounts (100K+ messages weekly), and Meta warned that malware actors deliberately spread infrastructure across multiple platforms to survive takedowns on any single one.

Third-order effects

  • If the pattern holds, messaging platforms will be pushed toward treating bot ecosystems and CDNs as attack surface requiring the same controls as web hosting — while attackers institutionalize multi-platform redundancy so that blocking one service no longer disrupts a campaign.

The trend: Malware operations are migrating from self-hosted infrastructure into the free CDNs, APIs, and bot frameworks of mainstream messaging platforms, forcing consumer apps into an adversarial security role they were never designed for.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Malware families observed using Discord CDN to host malicious payloads -PrivateLoader -Discoloader -Colibri -Warzone RAT -Modi stealer -Raccoon stealer -Smokeloader -Amadey -Agent Tesla -GuLoader -Autohotkey -njRAT Via: https://intel471.com/...
  • @gregotto Greg Otto on x
    NEW BLOG: Messaging platforms like Telegram and Discord have automation features that users love. Cybercriminals are among those users. Read how cybercriminals are using messaging automation for malware: https://intel471.com/...