ESentire Uncovers “ChaosBot”: A Rust-Based Backdoor Hiding In Plain Sight On Discord

eSentire’s Threat Response Unit discovered a Rust-based backdoor, ChaosBot, targeting Vietnamese speakers. The malware used Discord as a command center, spreading through stolen credentials and phishing lures. It evaded detection by patching Windows Event Tracing and checking for virtual machines, maintaining access through encrypted SOCKS5 tunnels.

Edward Kiledjian @ekiledjian