typetechniquecreated2026-07-25updated2026-07-25c2exfiltrationdiscordwebhookinfostealermitre-attck

Discord Webhook C2 Exfiltration

Using Discord webhooks as a covert data-exfiltration channel. Webhooks are HTTP endpoints that accept JSON payloads and file attachments without authentication beyond the URL token, making them attractive to low-sophistication threat actors.

Mechanism

  • Malware embeds a hardcoded https://discord.com/api/webhooks/<id>/<token> URL
  • Stolen data is formatted as Discord embed objects (title, fields, inline images) or uploaded as file attachments
  • The webhook posts into a private Discord server/channel controlled by the operator
  • File attachments bypass size limits via Discord's CDN, giving the actor a free file-hosting backend

Detection / fingerprint

  • Network telemetry: HTTPS POST to discord.com/api/webhooks/* from non-browser processes
  • Strings: discord_webhook, DiscordEmbed, DiscordWebhook, webhook URL patterns
  • Endpoint: browser processes (Chrome, Edge) are expected to hit Discord APIs; python.exe or PyInstaller temp binaries doing so are anomalous

Defensive countermeasures

  • Proxy/SIGMA: alert on *.discord.com/api/webhooks* from processes not matching browser signatures
  • Discord TOS violation reporting can disable webhooks, but operators regenerate them cheaply
  • Monitor %TEMP%\_MEI* directories for processes contacting Discord immediately after execution

Pages where observed

  • /intel/analyses/24c7c6cc3124b20c717ac485e263193e351f0ab2e672b353b38688ba218bda9a.html — XLABB Grabber