Discord Under Siege: New Cmimai Stealer Malware Exploits Webhooks to Target Windows Users

Listen to this Post

Featured Image

A Dangerous Shift in Cybercrime Tactics

Cybersecurity researchers at K7 Labs have sounded the alarm over a new malware strain that turns a popular chat platform into a covert data theft pipeline. Dubbed Cmimai Stealer, this Visual Basic Script (VBS)-powered infostealer emerged in June 2025 and marks a worrying evolution in how cybercriminals weaponize legitimate tools for malicious purposes. By abusing Discord webhooks, the malware bypasses traditional security barriers to exfiltrate sensitive information straight from infected Windows systems.

How the Attack Works

The Cmimai Stealer deploys through a straightforward yet highly effective VBS execution method, using Windows’ native scripting to operate without raising red flags. Once active, it creates a vbs_reporter_log.txt file in the victim’s temporary folder, logging operations while collecting essential system data via Windows Management Instrumentation (WMI). The malware focuses on Win32_OperatingSystem details such as OS versions, device names, usernames, and timestamps.

But it doesn’t stop there — Cmimai Stealer infiltrates browsers like Chrome and Edge, deploying PowerShell scripts (vbs_ps_browser.ps1) to extract stored metadata, including profile names and email addresses from Local State JSON files. In addition, another script (vbs_ps_diag.ps1) takes full-screen screenshots, compresses them to 70% JPEG quality to fit Discord’s 8MB upload limit, and prepares them for transmission to attackers.

Evasion and Persistence Mechanisms

To avoid detection, the malware uses -ExecutionPolicy Bypass to sidestep PowerShell restrictions and runs in hidden window mode. It executes in a loop every 60 minutes, ensuring uninterrupted surveillance. Communications occur over HTTPS directly to Discord webhook URLs, using a custom User-Agent string — “Cmimai Stealer VBS UI Rev” — which ironically acts as a detection signature.

Even if network conditions block one method, Cmimai Stealer falls back to alternative HTTP objects (WinHttpRequest.5.1 and MSXML2.XMLHTTP) for reliable data delivery.

Detection & Defense

Security experts warn organizations to watch for suspicious wscript.exe and powershell.exe parent-child process activity, the presence of Cmimai-related PowerShell scripts in temporary directories, and unexpected Discord API traffic from corporate networks.

While the current version doesn’t attempt credential theft or startup persistence, its lightweight reconnaissance capabilities suggest it may be a precursor to larger, more dangerous attacks.

What Undercode Say:

The Cmimai Stealer is a textbook example of cybercriminal innovation — not in terms of complex payloads, but in weaponizing trusted platforms that blend seamlessly into normal network activity. Discord, originally designed as a gamer-friendly chat app, has evolved into a multi-purpose communication hub, making it an attractive target for exploitation.

From a threat actor’s perspective, using Discord webhooks is a low-cost, high-reward tactic. It doesn’t require creating a dedicated command-and-control (C2) server, reduces infrastructure risks, and leverages an encrypted communication channel provided by a third party. This tactic also makes attribution difficult since the platform’s legitimate traffic masks malicious transmissions.

The Cmimai Stealer’s architecture is particularly dangerous because it modularizes its functions — system data collection, browser metadata theft, and screenshot capture — allowing future versions to expand capabilities easily. Adding credential theft, keylogging, or persistence features could transform it into a full-fledged espionage tool.

One of the most notable aspects of this malware is its persistence through timing loops rather than startup registry hooks. This method avoids leaving obvious traces in system autostart entries, making it harder for automated endpoint detection systems to catch.

Another key point is the compression of screenshots to fit Discord’s size limits. This small yet significant detail shows that the malware’s creators understand platform restrictions and adapt accordingly, ensuring successful data exfiltration without disruption.

From a defensive standpoint, organizations must go beyond traditional antivirus scanning. Behavioral analysis, outbound traffic monitoring, and custom detection rules targeting Discord webhook misuse are essential. Enterprises should also implement PowerShell logging and restrict script execution policies unless explicitly required.

The Cmimai Stealer is not an isolated incident — it’s part of a growing trend of legitimate service exploitation. Cybercriminals are increasingly abusing cloud storage, messaging platforms, and collaboration tools. This means that security teams must start treating trusted services as potential threat vectors rather than inherently safe.

Given its current design, Cmimai Stealer’s primary goal appears to be reconnaissance, potentially mapping out infected systems for a second-stage payload. This might include ransomware deployment, credential theft, or lateral movement inside corporate networks. If that happens, the initial breach could act as the first domino in a devastating cyberattack chain.

In short, the malware’s strength lies not in brute force, but in stealth, adaptability, and creative abuse of trust. This should serve as a wake-up call for defenders to rethink their detection models.

🔍 Fact Checker Results

✅ K7 Labs did confirm the discovery of Cmimai Stealer in June 2025

✅ Malware uses Discord webhooks for encrypted data exfiltration

✅ VBS scripting and PowerShell are core elements of its operation

📊 Prediction

Given the speed at which malware evolves, it’s likely that future variants of Cmimai Stealer will integrate credential theft, persistence across reboots, and encrypted C2 fallback servers. Attackers may also start disguising exfiltrated data as harmless media or documents to evade deep packet inspection. Organizations that do not monitor legitimate platform misuse could see this threat becoming significantly harder to detect within the next 12 months.

If you want, I can also enhance this with SEO keyword mapping and meta description optimization so it’s primed for maximum search visibility. Would you like me to prepare that version?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon