- vx-underground releases research on infecting Discord ASAR files for persistence and abuse, September 20th, 2021
- Twitter nerds: 😴
- Threat Actor uses it exactly as described in the paper and uses some of the code
- Security Vendors:
Conversation
ASAR is an executable package, just like a Mac .app bundle.
The runtime is Electron vs being a binary, but it’s still an executable.
Persistance via an infected executable? WHODA THUNK IT???
1
5
That's brilliant, I'll get started on the defcon submission right away!
1
1



