Researchers discovered a simple malware builder designed to steal credentials, then pinging them to Discord webhooks.
On April 23rd, 2022, a Discord user with the handle “Portu” began advertising a new password-stealing malware builder.
Malware builders are programs which so-called script kiddie hackers can craft their own executables on top of. Script kiddie is cybersecurity parlance for a novice hacker who uses a preexisting code to slightly modify it for their own nefarious purposes.
Four days later, threat analysts from Uptycs discovered the first sample of a Portu-inspired malware sample in the wild researchers dubbed “KurayStealer.” According to researchers, the malware has been used to target Discord users.
How KurayStealer Works
The author behind KurayStealer has clearly taken inspiration – and code – from those other attacks. “We have seen several other similar versions floating around in public repositories like github,” the researchers noted, concluding that “the KurayStelaer builder has several components of different password stealers.”
When it’s first executed, KurayStealer runs a check to determine if the malicious user is running the free or “VIP” (paid) version.
Next, it attempts to replace the string “api/webhooks” with “Kisses” in BetterDiscord – an extended version of the