typetechniquecreated2026-08-21updated2026-08-21defense-evasionpersistencec2mitre-attck

Discord Desktop Core Injection

Malware modifies the Discord desktop client's discord_desktop_core/index.js to inject arbitrary JavaScript that runs with full access to the Discord process. This enables token theft, persistent surveillance of Discord activity, and secondary payload execution every time Discord launches.

Detection / Fingerprint

  • File writes to %APPDATA%/Discord*/discord_desktop_core/index.js
  • Creation of a ThiefCat or similarly named subdirectory under discord_desktop_core
  • Relaunch of Discord.exe after index.js modification
  • Network requests to Discord API v9/v10 from processes not matching known Discord paths

Implementation Patterns Observed

In novashadow the malware:

  1. Fetches a JavaScript template from a remote URL (DSCINJ_URL)
  2. Patches placeholders (%TRANSFER_URL%, %DISABLE_2FA%)
  3. Writes the patched script to discord_desktop_core/index.js
  4. Creates a ThiefCat marker directory to avoid re-injection
  5. Relaunches Discord via Start-Process in PowerShell

Reproduce on Your Own VMs

  1. Locate %APPDATA%/Discord/discord_desktop_core/index.js
  2. Append a benign console.log statement
  3. Relaunch Discord and observe the injected code executing in DevTools

Defensive Countermeasures

  • Monitor file integrity of discord_desktop_core/index.js
  • Alert on Discord.exe child processes spawned by node.exe or wscript.exe
  • Detect Discord API token queries (/api/v9/users/@me) from non-browser processes