Topic: Discord Stealer
github.com
github.com
> Over the past year, we've worked together to build and improve this project. It has been an incredible journey, and I'm immensely grateful for all the contributions, feedback, and support from each one of you.
It has been an incredible journey doing crime together with y’all. Huggles and fuzzies! ^_^
I simply don't understand that vibe. I guess I’m just old cause back in my days, the crime geeks openly did was warez and that seems substantially less evil to me. This software is explicitly intended to victimize individual users. I simply don’t get how someone can get so “incredible journey” about that sort of stuff, you active worked to make the world worse.
Seeing this happy-OSS-community praise from someone providing a turn-key malware solution for even the most technologically incompetent jerks is just harrowing.
He's not wrong.
Even then, if you download a .js file and try to execute it you will get the MotW warning. https://www.bleepstatic.com/images/news/Microsoft/vulnerabil...
> A lay person should not be operating a computer.
This isn't the 60s. Computere are made and marketed for regular lay persons/general public.
"Disclaimer: This program is provided for educational and research purposes only. The creator of this program does not condone or support any illegal or malicious activity"
I guess it is a gang like mindset. Exploiting others and preying on the weak. And I am not that old, but I actually also do remember other and more dark hack activity from the past, than just warez.
Afaik razor didn't advertise “steal innocent people’s account” services in cutesy cracktros.
I think it still falls into the "malware implementations" category.
It is more about what happens if your data is stolen and how a hacker could exploit that stolen data to gain access to your account.
It's pretty clear when an account or computer is hacked and yet neither razz or hubby were charged with theft ... Hubby essentially got convicted of tax evasion like a '30s gangster.
That's one of the perks of free/open source.
Presuming there exists something like a provider/customer relationship for users of Discord, it's now Discord's job to step up and fix it; unfortunately years of Microsoft getting away with horrible security has cemented in our collective heads that "malware" is some abstract thing that, you know, just happens.
Even before considering the deleterious effects of censorship, it would simply be more work for everyone and unlikely to benefit anyone. Not to mention you'd lose valuable telemetry that could be used in investigations after the fact (e.g. if someone is accused of stealing photos from an ex on discord, and GitHub can positively identify them as having downloaded a malicious tool to steal Discord tokens, then investigators could subpoena GitHub for those download records).
If there is a problem here, then hiding the code that exploits the problem does not eliminate it. It's Discord's responsibility to mitigate the scale of risk associated with a stolen token. A program that grabs a token on your machine probably shouldn't be able to use it to exfiltrate all the data from your Discord account. And similarly, it probably shouldn't be so easy for any program running on the machine (as a non-root user) to retrieve such a token in the first place.
Source: I’m old and used to source this stuff for research purposes (genuinely) long before GitHub, and social media in general, was a thing.
"Harmful software" is a much blurrier line. Is a GitHub URL being used as a dropper in an active malware campaign? That will probably get a repository removed. Is the source code for malware published on GitHub? That's not harming anyone in its current form, just like the source code of Popcorn Time isn't pirating movies.
Do you want to ban any content with a readme claiming it can be used maliciously? What if I want to publish a basic keylogger implementation for an open source cybersecurity class? Where's the line between educational content and cyberweapons? And even if it's a weapon, how do you know I don't have permission to install the keylogger on a system, like one belonging to a company paying me to pentest them?
I can assure you, script kiddy code on GitHub isn’t going to lead to people uploading kiddy porn on GitHub as well. The two are not in any way related, let alone one being a slippery slope for another.
> The code will continue to exist regardless of whether you see it on GitHub
You can extrapolate this to literally anything - "we should allow hosting CSAM on GitHub, since it's on the Internet anyways and we can't do anything about that"
> If there is a problem here, then hiding the code that exploits the problem does not eliminate it.
There's no problem here. This code only exploits the naivety of whoever was social engineered into running it. A session token gives access to the account, by design - it's the way the internet works. The only way to steal a token is by having full access to the machine, and at that point there's no possible mitigation. Even if you completely eliminate persistent sessions, which is a major UX regression, malware can still hook into a running process and steal the active session.
> And similarly, it probably shouldn't be so easy for any program running on the machine (as a non-root user) to retrieve such a token in the first place
What are you even saying? How does Discord/Chrome then read their own session data/cookies? Should we run them as root?
Maybe I'm misunderstanding NTFS permissions and this is expected, I don't do a lot of Windows, but worst case for the malware is that it has to show a UAC prompt, and if you made someone click "free-discord-nitro.exe" they'll probably click through that too.
Permissions are fake, especially Windows ones. If someone is running code on your machine, they can access any data on it.
And yes, a user could click through that. The primary responsibility is always on the user, within the bounds of what the OS allows them to do (as an extreme, a mobile app certainly cannot access data from another app's keychain or configuration directory - but this requires a highly restrictive OS). But the point is that an application should still make an effort to use best practices provided by the operating system for protecting sensitive data. And in the case of Discord, at least on Mac, it should probably be storing tokens in the Keychain, not the filesystem (maybe it does, idk). Yes, malware can hook the process but not without compromising various OS sandboxing mechanisms, which usually requires the assistance of the user clicking past scary warnings (and even going outside the flow of alerts to explicitly disable protections).
ytdl is a great example of that. For Google, it’s “stealing” people from their platform by allowing individuals to download content in a way that doesn’t increase engagement and ad views. I don’t personally agree that ytdl is malicious but I do understand how some could make that claim.
Then what about tools that are legitimately intended for research purposes but could still be abused?
The problem with freedoms is they have to work both ways: if you aren’t prepared to allow abuse of that freedom then you certainly aren’t going to allow legitimate but unpopular uses either.
If you want to go ahead and make the free speech argument, feel free, but I don't buy it.
"This repository is for ethical purposes and to use the scripts to learn and improve in python :)"
# Features
• GUI Builder.
• UAC Bypass.
• Custom Icon.
• Runs On Startup.
• Disables Windows Defender.
• Anti-VM.
• Blocks AV-Related Sites.
• Melt Stub.
• Fake Error.
• EXE Binder.
• File Pumper.
• Obfuscated Code.
• Discord Injection.
• Steals Discord Tokens.
• Steals Steam Session.
• Steals Epic Session.
• Steals Uplay Session.
• Steals Passwords From Many Browsers.
• Steals Cookies From Many Browsers.
• Steals History From Many Browsers.
• Steals Autofills From Many Browsers.
• Steals Minecraft Session Files.
• Steals Telegram Session Files.
• Steals Crypto Wallets.
• Steals Roblox Cookies.
• Steals Growtopia Session.
• Steals IP Information.
• Steals System Info.
• Steals Saved Wifi Passwords.
• Steals Common Files.
• Captures Screenshot.
• Captures Webcam Image.
• Sends All Data Through Discord Webhooks/Telegram Bot.
(...more)
Others like: https://github.com/venaxyt/Token-Grabber-Advanced are intended for stealing discord information.> Steals Roblox Cookies.
Is there any value in cookies for a children game?
"For educational purposes" is the new "It's just a joke, man."
I get the argument that non-disclosure isn't working ("isn't perfect" would be a better phrasing) and that once the source code is out there, you can't contain its spread. But I'm not making a political argument here on how to prevent this from happening, but a moral argument (pretty obvious in my post). Basically if you spread this "for educational purposes" *wink*wink* you are part of the problem and most of your justifications are worthless and disengenuine. And if you're really a free speech advocate you allow me my moral judgement.
https://support.discord.com/hc/en-us/community/posts/3600300...
It should just follow what the system is doing like other apps.
> Why aren‘t physically-local attacks in Chrome’s threat model?
> We consider these attacks outside Chrome's threat model, because there is no way for Chrome (or any application) to defend against a malicious user who has managed to log into your device as you, or who can run software with the privileges of your operating system user account. Such an attacker can modify executables and DLLs, change environment variables like PATH, change configuration files, read any data your user account owns, email it to themselves, and so on. Such an attacker has total control over your device, and nothing Chrome can do would provide a serious guarantee of defense. This problem is not special to Chrome — all applications must trust the physically-local user.
https://chromium.googlesource.com/chromium/src/+/master/docs...
Additionally, It's the only platform I've been hacked on. Someone compromised a friend's account and said they had made a game they wanted me to try (I'm an indie game dev so it seemed legit)
I’ve been a discord user since July 2015 and it was nice until people began to use it as an everything app and the hordes of children joined. I really really despise the discord userbase because they’re the new generation of the eternal September that ruins the internet.
only have to be right once and there is a huge and gullible audience there
Discord support has been completely unhelpful, because he didn't have 2FA enabled before and the hacker added it.
At least it was just discord. I'd treat this as a valuable lesson on the virtue of 2FA especially if they have a habit of running untrusted executables (especially with admin permissions...)
My main takeaway from looking at some of the repositories is that they are deathly afraid of being run in a VM, because they think that means someone is trying to reverse engineer them. (Which I suppose makes sense; test untrusted software in a VM, if it doesn't do anything evil, then run it outside of the VM.)
These are open source but the popular ones are paid malware (as cheap as a few dollars though) you get on those same forums/chats that have more features, evasiveness and nice control panels. But arguably, discord is a nice enough control panel lol.