What is discord doing to prevent malicious files from being distributed on its CDN?
I am gradually seeing more articles highlighting CDN abuse by malicious actors to deploy malware, such as password stealers, backdoors, spyware and Trojans. Here is a RiskIQ article that says 27 different types of malicious filetypes are being propagated through the discord CDN: https://www.riskiq.com/blog/external-threat-management/discord-cdn-abuse-malware/
This is even more alarming to read that these files can be distributed by bots as well as users. Obviously, the automated distribution of these files could amount to an overwhelming number to be manually verified by staff.
I have not read anything in the transparency report that reflects this situation. Is there anything being done by the discord team to ensure the CDN is not being abused and used to distribute malicious programs to end users?
This also comes after the fairly old malware injection incident propagating AnargyGrabber: https://www.bleepingcomputer.com/news/security/discord-client-turned-into-a-password-stealer-by-updated-malware/ which, as far as I'm aware, depended on word of mouth to notify users to check the index.js file in appdata, and the community did not hear anything from discord themselves addressing the issue.
In the next transparency report, it would be beneficial to address these concerns, both as a reminder for end users to stay vigilant against malicious files, and also to acknowledge any incidents that have happened with the CDN.
I would also like to know if there are any firewall/hashing going on with files being passed around the CDN, to ensure that files do not contain malicious software and to protect users' computers before it arrives on their endpoint.
Edit: formatting
請登入寫評論。
評論
0 條評論