A new malware campaign uses the RedTiger infostealer to compromise Discord accounts, browser data, and crypto wallets. Cybercriminals distribute the malware through gaming channels, presenting it as cheats, mods, or performance boosters.
Researchers warn that the RedTiger infostealer Discord accounts campaign is spreading quickly across gaming and social communities. Because the malware disguises itself as a legitimate tool, users often install it without suspicion. As a result, their stored credentials, browser data, and tokens become exposed to attackers.
How the RedTiger infostealer operates
Attackers recompile open-source RedTiger code into malicious versions. Then, they upload these fake tools to Discord servers, YouTube videos, or third-party mod websites. Once a user downloads and runs one of them, the program immediately begins collecting data.
The malware searches browsers for saved passwords, cookies, and wallet information. At the same time, it scans local Discord folders to find authentication tokens. After extracting them, it injects malicious JavaScript code into Discord’s internal files to intercept future activity.
Furthermore, the stolen data is uploaded to attacker-controlled servers via Discord webhooks. Some variants even record screenshots or webcam footage, providing hackers with an extensive profile of their victims.
Why Discord users are at high risk
Gamers and community users remain easy targets. They often download unverified files or use cracked software, believing it harmless. However, once RedTiger gains access, it allows attackers to impersonate the victim, steal payment data, and send malicious links to friends.
Moreover, Discord’s token system makes matters worse. Because tokens function as session keys, attackers can access accounts without needing passwords or triggering alerts. Consequently, the stolen tokens give them unrestricted control.
How to stay protected
Users should download mods and utilities only from verified developers. Additionally, enabling multi-factor authentication (MFA) on both Discord and email accounts adds an extra layer of security. If an infection is suspected, users must immediately revoke active sessions, reset passwords, and reinstall Discord from official sources.
Security experts also advise running reputable antivirus software and avoiding suspicious links. Meanwhile, administrators should monitor for unusual webhook activity or file changes in Discord’s local data directories.
Conclusion
The RedTiger infostealer Discord accounts campaign demonstrates how quickly open-source tools can turn into powerful threats. Because the malware exploits trust within gaming communities, it spreads faster than typical phishing attacks. Therefore, regular updates, cautious downloads, and strong authentication practices are essential to keeping both Discord accounts and personal data secure.


0 responses to “RedTiger infostealer targets Discord accounts and gamers”