The malware typically combines several malicious modules into a single payload:
Records every keystroke made by the user, capturing private conversations and typed credentials in real-time.
Enable MFA on all critical accounts to block access even if your password is stolen.
Harvests and validates Discord account tokens to allow attackers to take over user accounts.
Organizations should monitor or block unauthorized Discord webhook traffic, as this is the primary exfiltration method.
