Severity scale:  

Remove Discord virus (Virus Removal Guide) - updated Jul 2019

removal by Jake Doevan - - | Type: Malware

Discord virus is a cyber infection that can use phishing tactics and direct malware to obtain personal information 

Discord virus
Discord virus is a combination of malware that is distributed via the VoIP application Discord

Discord virus is a set of malware distributed via the voice over internet protocol (VoIP) application Discord. The network is legitimate and often used by users to communicate while playing online video games, and is also popular among the security research community. Unfortunately, bad actors also create chat servers that are hosting malware.[1] Users who get tricked into infecting their machines with Discord virus in the form of trojans or worms are putting their sensitive information at risk, as well as have an increased chance of getting infected with other malware.

Questions about Discord virus

When it comes to any social media or applications, malicious actors always target users with scams and phishing attacks. Discord is no exception. For years, since the initial appearance of this social network, it was known that various messages surface the DMs. The more recent campaign is known to deliver DMs for users with a link that resembles a legitimate website, in the first place, but once clicked delivers the victim to a fake login page that asks to put your account information again. This is a phishing scheme that can lead to serious privacy issues.[2]

Name Discord virus
Type Malware
Most commonly distributed types RAT (Remote Access Trojan), phishing campaigns
Malware examples NanoCore, SpyRat, njRAT, OSX.Dummy
Distribution Malicious attachments, drive-by downloads, social engineering, phishing campaigns
Main dangers Recorded passwords, credit card details, and other sensitive data; other malware infections
Symptoms Trojans rarely emit any symptoms, but users might experience computer crashes or freezes, slow operation, error messages, etc. DMs coming from, what it seems. your friends, contain malicious links that record and collect personal users' information
Detection and elimination Download and install Reimage or Malwarebytes Malwarebytes to check the system and possibly remove Discord virus

Most of the malware that is delivered via Discord is Remote Access Trojans[3] (RATs). These malicious applications are installed with users' permission, although victims are not aware of it (typically phishing techniques are used to make the user click on malicious links or attachments). As soon as Discord malware is settled, it grants itself administrative rights, and the host system is used to distribute the RAT even further – that is how a botnet is established.

RATs that are common in Discord virus attacks include:

  • NanoCore (Trojan.Nancrat)
  • SpyRat (Backdoor.Ratenjay)
  • njRAT (W32.Spyrat)
  • OSX.Dummy

All the viruses mentioned above are capable of various malicious activities on the targeted PC, including monitoring the behavior of the victim, recording keystrokes, taking screenshots, using the webcam to record the video, formatting drives, starting or shutting down various system processes, as well as installing additional malicious files on the system. Before that happens, users are advised to regularly scan their machines using security software and take care of Discord virus removal if it was detected on the device.

Additionally, certain hacking tools are being advertised as legitimate. Malware authors claim that the hacking tool can allegedly steal passwords of other Discord users. However, as soon as victims agree to download the application, they become victims of a phishing attack itself and get scammed. The unfair users are then hit with malware that is capable of stealing personal information and distributing RATs even further.

Targets of Discord virus are usually gamers and video streamers. The latter ones often employ the program to stream gaming sessions for the entertainment purposes. The hackers often target personal information that is related to online gaming, such as:

  • Login credentials;
  • In-game currency;
  • Contacts;
  • Items, etc.

This data can be used for monetary benefit in the same way it is used by hackers when they steal private information like name and surname, address, email, social media credentials, etc. (which can also be harvested by cybercriminals in the process).

As evident, these actions pose serious personal safety concerns and can result in identity theft or money loss. To make sure you are not a victim of such consequence, better remove Discord virus as soon as possible. For that, you should install reputable security software such as Reimage or Malwarebytes Malwarebytes and perform a full system scan. Security researchers[4] warn that RATs can disable anti-virus programs in some situations, so starting the computer in Safe Mode with Networking is an option.

Discord network virus
Discord virus is the threat that delivers possibly malicious links in DMs and infects the system further if clicked or not terminated in time.

Discord phishing campaign

The campaign starts with a direct message from someone that includes a link to a website that seems to be connected to the Discord official site. Unfortunately, when looking closely you can see that this website is discord dd dot ga – a mockup of the official social network page. Once the victim clicks on that hyperlink the redirect makes the person visit a fake login page that requires to fill your email and password again.

Unfortunately, this way scammers obtain account information and can use these profiles to spread the campaign further. The embed of the Discord link gets forged and the redirect leads to a site that records information. This is why you got the message in the first place – because your friend or any person you know and content on the network has clicked on such link. 

Once you reveal your login and password the profile is taken by scammers and the system collects all those stolen credentials. Hackers then lock you out of the profile and can DM other server members, group chats with all the malicious links. You can make a new account and try to inform as many people in your circle to let them know about the phishing campaign.

You can attempt to log out these people from the account by changing the password and enabling the two-way-authentication. Don't fall for the scam when you receive a message from a friend or a person you know and inform that friend has a virus and a compromised account.

Although the particular got banned by the company itself, this campaign might repeat itself via other malicious sites. Keep the machine clean from such threats and eliminate possible damage by scanning the system with Reimage. You can use other tools, base the selection on the malware detection rate.[5]

Discord virus phishing campaign
Discord virus is the term used to describe various malicious campaigns spreading on this network including phishing campaigns and malware dropping.

Discord – a chat program that rapidly gained popularity

Many users used chatting programs since mIRC and ICQ times, later turning to Skype and Facebook messenger. Gamers used TeamSpeak, Mumble, and Ventrilo for their communications, but often required players to share various IP addresses and/or were not free to use and were resource-heavy, which is a huge disadvantage when playing games. 

Thus, Discord was created in 2015 as an alternative VoIP application which is lightweight, innovative and user-friendly. Additionally, it was supported on multiple platforms, including Windows, Android, macOS, iOS, Linux and web browsers. The simplicity of Discord is what added to its popularity, as any user can create a server or a group in just a few seconds. Thus, the popularity of the app grew, and by May 2018, it was used by 130 million users worldwide.

Unfortunately, bad actors reacted to the booming fame of the application and were well prepared to use Discord malware for their malicious deeds. While some criminals hosted viruses on the created servers, others use the platform as an alternative to the black marked on Dark Web and sell sensitive information or malware.

Ways Discord virus is distributed

Discord users can upload files like pictures, videos, and other attachments on Discord using the chat feature. Since the app allows anybody to upload almost all kinds of data, malware authors can use the feature to their advantage. While Discord team applied additional security measures over time, Discord malware is still prevalent and should be taken seriously.

Users are merely baited to open the malicious attachments in sophisticated phishing attacks via the chat function on the created servers. Some attackers don't even have to create their own servers, as they can manually post the virus on the server they have been invited to.

To avoid dangerous consequences of the data-harvesting malware, users should never click on suspicious links in chats, even if they are coming from people on their friend list. Users reported that certain instant invite messages were turned into malicious links without their knowledge.

Remove Discord virus from your computer

To remove Discord virus from your computer, you will have to employ reputable security software. Remote Access Trojans often use obfuscation techniques and show no symptoms of presence whatsoever. Therefore, detecting malware without using professional tools might be impossible. 

Download Reimage, SpyHunterCombo Cleaner or Malwarebytes Malwarebytes for the effective Discord virus removal. Make sure that the security software is up to date before performing the scan. In case the malicious software prevents you to start anti-virus correctly, enter Safe Mode with Networking as explained below.

do it now!
Reimage (remover) Happiness
Reimage (remover) Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with SpyHunter.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.

To remove Discord virus, follow these steps:

Remove Discord using Safe Mode with Networking

In case Discord malware is blocking security software from working properly, enter Safe Mode with Networking the following way:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Discord

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Discord removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Discord using System Restore

To stop the virus from operation, use System Restore function:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Discord. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that Discord removal is performed successfully.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Discord and other ransomwares, use a reputable anti-spyware, such as Reimage, SpyHunterCombo Cleaner or Malwarebytes Malwarebytes

About the author

Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions


Removal guides in other languages

Your opinion regarding Discord virus