A user downloads the .rar file. When they try to run the .exe inside, their Windows Defender or antivirus immediately screams.

It scrapes "Tokens," allowing the attacker to take over the user's Discord account without needing a password or 2FA.

The title sounds like a goldmine for a budding script kiddie, but in the world of cybersecurity, it’s a classic "Trojan Horse" tale.