This Roblox Discord was Hijacked
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A popular Roblox game developer's Discord server was compromised and used to distribute malware disguised as a new game called SlumpCute. The malware is a Java-based info stealer called Micro Stealer that kills browsers to relaunch them in debug mode, steals credentials using Windows DPAPI, and maintains persistence through scheduled tasks. The analysis covers detection evasion techniques, decompilation of obfuscated Java code, and exfiltration methods including backup uploads to GoFile. Key indicators include zero antivirus detections initially, NSIS packaging, and the use of legitimate signed Java binaries renamed as Microsoft.exe.
Sort: