Abaddon RAT is the malware that uses the Discord app as a command & control server

Abaddon RAT is the intruder with a ransomware feature and gets instructions from creators via the Discord application. Threat actors are known for abusing the Discord platform because its popularity helps to distribute malware around. This RAT[1] relies on a remote host that is a method to receive commands for execution on the infected machine. Once processes start on the targeted computer, trojan automatically steals information from the PC: cookies from Google Chrome browser, saved credit card credentials, other information, steam logins, and a list of games installed, Discord tokens, MFA information, file listings, information about the system. Additional commands can be received via the same Discord C&C server.
| Name | Abaddon RAT |
|---|---|
| Type | Remote access trojan |
| Issues | The trojan can steal data from the machine, access files, programs, control processes, and install other malware on the system |
| Distribution | The threat can be distributed via infected email attachments, malicious sites online, and even during social-engineering campaigns or with the help of other viruses |
| Features | The threat can steal credentials, files, directories. It also manages to execute commands that trigger additional infections. The feature that allows attackers to deploy ransomware is in development also |
| Elimination | Abaddon RAT removal process can be difficult because of the shady infiltration methods and persistence, so anti-malware tools are required |
| Repair | You should consider virus damage and run a tool like FortectIntego for the PC repair |
After analyzing, researchers revealed that Abaddon RAT virus could get commands to steal files or directories, add an open reverse shell that allows attackers to execute commands, launch ransomware, send collected information to threat actors. Such collected details can be used in later attacks.[2]
This connection with the command and control server happens every 10 seconds, so the Abaddon RAT is active and executing new tasks all the time. It might trigger issues with the machine's speed or performance, but generally, victims can't notice the intruder or spot that there are any issues with the computer.
Abaddon RAT has many tasks, and one of them is to run a basic ransomware virus. This threat encrypts computer with the help of a basic algorithm and claims to decrypt files after the ransom is paid. The feature is in development, according to experts. However, ransomware is extremely dangerous, so this feature will most definitely be completed and executed, so malicious actors can make a profit easily.
Abaddon RAT is used to collect sensitive information and trigger other malware infiltrations, so ransom gets paid for encrypted file recovery, or stolen credentials get used in later attacks against users. It is possible to suffer huge losses of money after credit card credential usage for direct transfers.
You need to remove Abaddon RAT as soon as possible, so you can ensure that additional commands cannot get executed and your machine is safe. Various issues can be caused by this malware piece and other intruders that trojan injects into the system behind your back.

Abaddon RAT removal success depends strongly on the detection rate and the anti-malware tool that you use for the procedure. Detection names that appear on the screen when you indicate the threat can be very different because AV tools use various malware databases. These are some of the possible names for this trojan:
- Spyware.DiscordStealer;
- Trojan.Malware.73593052.susgen;
- BackDoor.CmdShellNET.2;
- TScope.Trojan.MSIL;
- W32.Trojan.Gen;
- HEUR:Trojan.MSIL.Agent.gen;
- Win32.Trojan.Ransom.Ebqg;
- BackDoor.CmdShellNET.2;
- Trojan.Ransom.REntS.Gen.1.[3]
Rely on proper tools that can find this threat and additional intruders that Abaddon RAT malware installed once received such a command. The manager of this threat can steal various data and trigger damage to your computer. Do not hesitate when it comes to eliminating such threats, and do not forget to fix virus damage with tools like FortectIntego.
Malicious files hide serious malware payload
The payload of such threats mainly gets distributed with the help of email campaigns and even social engineering because people get tricked into opening a link to a hacked page or downloading executable, another type of file that triggers the C&C server connection and the drop of RAT, malware, worm. You can catch such intruder from:
- torrent sites;
- hacked pages;
- pirated software packages;
- email attachments.
The main issue with such infiltration methods is the fact that users cannot control the installations or notice the drop in the first place, so all the activities can run without users' knowledge. You can avoid these infections if you pay close attention to details, avoid getting anything suspicious from the internet.
Get rid of the Abaddon RAT virus and clear the system properly after the virus termination procedure
Since Abaddon RAT is silent and shady, you cannot find the file that triggers all the functions yourself. The best option for the proper system clearing procedure is a proper scan of the infected device, so tools designed to fight viruses can detect and eliminate all threats related or not associated with this trojan.
To remove Abaddon RAT, you need tools like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, so the machine is checked for any suspicious or malicious pieces. Once the system scan is triggered, you can see the list with intruders and get rid of the infection or any possible threats. Tools like anti-malware or PC security programs can indicate active infections and clear any viruses for you.
However, Abaddon RAT removal is not the process that can ensure that your system is safe and works as it is supposed to. You need to repair the damage that trojan triggers on your machine, and the best way to do so – with system tools like FortectIntego. You might benefit from features that the Windows OS devices have, so follow the guide below.
Did this guide help?
Be the first to comment