The new ‘Abaddon’ remote access trojan may be the first to use Discord as a full-fledged command and control server that instructs the malware on what tasks to perform on an infected PC. Even worse, a ransomware feature is being developed for the malware. When started, Abaddon will automatically steal the following data from an infected PC:
Abaddon will then connect to the Discord command and control server to check for new commands to execute, as shown by the image below.
These commands will tell the malware to perform one of the following tasks:
The malware will connect to the C2 every ten seconds for new tasks to execute. Using a Discord C2 server, the threat actor can continually monitor their collection of infected PCs for new data and execute further commands or malware on the computer.