Guide · July 28, 2026 · 6 min read
Malicious files on Discord: token grabbers and fake betas
A file dropped in a channel stays downloadable by everyone until a human reports it. This guide explains what actually circulates, why the member's antivirus arrives too late, and how to analyse every attachment at the source.
Contents
What really circulates as an attachment
Four families cover most of what goes around on Discord servers:
- Token grabbers — steal the Discord session token. By far the most widespread, because they pay off immediately: a stolen account serves to steal the next ones.
- Infostealers — cast a wider net: passwords saved in the browser, session cookies, cryptocurrency wallets, game configuration files.
- Remote access tools (RATs) — install a persistent back door. These are what you find behind a machine that “does things on its own” months later.
- Ransomware — rarer on Discord, but present, often disguised as a cheat tool or a key generator.
The wrappings, though, are always the same: a private beta of a much-awaited game, a cheat tool, a Nitro generator, a “verification tool”, a mod for a popular game, or a plain renamed screenshot. What all these pretexts have in common is that they explain in advance why the antivirus is going to complain: “it's a false positive, turn it off”.
Any instruction asking you to disable the antivirus is, in itself, proof that the file must not be opened.
The token grabber, explained simply
When you are logged in to Discord, the application keeps an authentication token on your machine — a long string of characters proving your identity on every request. That token is what saves you retyping your password each time.
A token grabber is a small program whose only job is to find that token among the local files and send it to the attacker, usually through a Discord webhook (which makes the traffic look perfectly ordinary).
What makes the attack formidable: the token bypasses both the password and two-factor authentication. The attacker does not log in, they replay your session. Changing the password is not enough either: as long as the active sessions are not revoked, the stolen token stays valid.
What Discord filters, and what it does not
Discord blocks a few notoriously dangerous extensions on upload and removes content reported by users. That is useful, and that is all: no antivirus scan is performed on attachments posted in a server.
In practice, an executable dropped in a public channel remains downloadable by every member for as long as nobody reports it — which, overnight, means several hours. And a file removed on Discord's side often stays reachable through its direct CDN link.
Why the member's antivirus arrives too late
The antivirus installed on the member's machine is the last line of defence, not the first. Three reasons not to rely on it:
- It fires after the download, sometimes after execution. The file has already reached its target.
- Grabbers are often brand new: recompiled for each campaign, they have no known signature yet.
- The victim disables it themselves, because the accompanying message told them to and the alert seemed to confirm that “it really is a cheat”.
The right place to block is therefore the server, before the file is visible.
Analysing files at the source
That is the role of OriusGuard, OriusBot's file analysis module. Every attachment goes through a funnel: the fast checks first, the expensive ones only if doubt remains.
- Archives are opened. A ZIP is extracted and every file inside it is analysed individually. That closes the “I put the executable in a ZIP” loophole.
- Static analysis of executables. Packer detection, entropy measurement (an encrypted or compressed file gives itself away by its byte distribution), the presence of surplus data after the binary's logical end — three classic signatures of a program trying not to be read.
- Hash checking. The file's digest is compared with a database of known malware, fed by public threat-intelligence sources.
- Hashes shared between servers. A file recognised as malicious on one equipped server is blocked immediately on all the others. An attacker spreading the same payload across ten servers reaches only one.
- Optional signature-based antivirus engine. ClamAV can be plugged in for an extra pass.
As with OriusBot's other security modules, the analysis runs on Orius's infrastructure: your server's files are not sent to any third-party service.
Links get the same treatment: redirects followed to the real destination, checks against
public threat databases, and analysis of the landing page's content where necessary. The
/scan command also lets you have a file checked on demand, and
/analyser-lien an address.
The channel rules to set
Tooling does not remove the need for a few structural decisions, free and immediate:
- One channel allows attachments, if the server needs them. Everywhere else, remove the “Attach files” permission from the default role.
- Ban executables explicitly in the rules, and have the bot enforce it rather than relying on goodwill.
- No attachments for recent accounts. A member who arrived ten minutes ago has no reason to send an archive.
- Block private messages between members of the server: that is where the files moderation never sees get handed around.
- Log uploads so you can retrace things afterwards: who sent what, when, and who downloaded it.
After an infection
- Delete the message and ban the sender, without waiting for confirmation: the debate comes afterwards.
- Tell people publicly, with the exact file name, so that those who downloaded it come forward.
- Have affected members change their passwords, enable two-factor authentication, and above all revoke every Discord session — without which the stolen token stays valid.
- Full scan of the machines involved: a grabber frequently comes with persistent remote access.
- Check the server logs: a compromised account that held permissions may already have acted. The anti-nuke guide covers that scenario.
Frequently asked questions
Does Discord scan uploaded files?
Discord blocks certain file types and removes reported content, but performs no antivirus scan on attachments posted in a server.
What is a token grabber?
A program that looks for the Discord authentication token stored on the computer and sends it to the attacker. That token grants full access to the account without a password and without triggering two-factor authentication.
Is a ZIP file dangerous?
The archive is harmless, but it serves to hide its contents: most filters look at the extension of the uploaded file and stop there. You have to open the archive to analyse what it carries.
How do I know whether a file is a virus before opening it?
Without a tool, you cannot: the icon, the name and the size are all forgeable. The reliable clues are contextual — a stranger who insists, a beta that requires disabling the antivirus, an archive password-protected to prevent any analysis.
What should I do after running a token grabber?
Password changed, two-factor authentication enabled, log out of every session to invalidate the token, then a full scan of the machine.
Read next : Discord scams, Anti-nuke: protecting your server, Security checklist.
