Discord Webhook C2 Exfiltration
Using Discord webhooks as a covert data-exfiltration channel. Webhooks are HTTP endpoints that accept JSON payloads and file attachments without authentication beyond the URL token, making them attractive to low-sophistication threat actors.
Mechanism
- Malware embeds a hardcoded
https://discord.com/api/webhooks/<id>/<token>URL - Stolen data is formatted as Discord embed objects (title, fields, inline images) or uploaded as file attachments
- The webhook posts into a private Discord server/channel controlled by the operator
- File attachments bypass size limits via Discord's CDN, giving the actor a free file-hosting backend
Detection / fingerprint
- Network telemetry: HTTPS POST to
discord.com/api/webhooks/*from non-browser processes - Strings:
discord_webhook,DiscordEmbed,DiscordWebhook, webhook URL patterns - Endpoint: browser processes (Chrome, Edge) are expected to hit Discord APIs;
python.exeor PyInstaller temp binaries doing so are anomalous
Defensive countermeasures
- Proxy/SIGMA: alert on
*.discord.com/api/webhooks*from processes not matching browser signatures - Discord TOS violation reporting can disable webhooks, but operators regenerate them cheaply
- Monitor
%TEMP%\_MEI*directories for processes contacting Discord immediately after execution
Pages where observed
- /intel/analyses/24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a.html — XLABB Grabber