New Lucid Stealer Targets Browsers, Crypto Wallets, and Discord Tokens

New Lucid Stealer Targets Browsers, Crypto Wallets, and Discord Tokens

A new build of Lucid Stealer, a Malware-as-a-Service (MaaS) promoted through underground Telegram channels.

Instead of using a generic packed executable, attackers packaged this credential stealer and remote-access trojan (RAT) inside a legitimate Node.js Single Executable Application (SEA) wrapper.

The malware targets numerous browsers, cryptocurrency wallets, and Discord tokens while providing operators with full post-infection control.

Lucid Stealer Targets Wallets

The infection begins when a victim opens a password-protected WinZip-AES archive containing a 100 MB Windows executable.

This large file acts as a delivery and concealment layer, leveraging a legitimate Node.js runtime to hide an 8.5 MB JavaScript loader.

Lucid Stealer web authentication panel. The operation uses separate user/admin login paths, a license-key field and AES-256 branding. The address bar URL is redacted (Source: foresiet)
Lucid Stealer web authentication panel. The operation uses separate user/admin login paths, a license-key field and AES-256 branding. The address bar URL is redacted (Source: foresiet)

Once executed, the loader extracts helper binaries to disk and decrypts the core second-stage payload using an RC4-style algorithm.

Lucid Stealer operates as a highly capable hybrid threat rather than just a basic credential scraper. The recovered JavaScript payload reveals discrete modules designed for extensive data theft and remote system administration.

elegram announcement channel with closure and relaunch narrative. The operator handle is redacted in both visible occurrences (Source: foresiet)
elegram announcement channel with closure and relaunch narrative. The operator handle is redacted in both visible occurrences (Source: foresiet)

Threat actors can launch hidden virtual network computing (HVNC) sessions, automate synthetic screen inputs, capture desktop screenshots, and execute distributed denial-of-service (DDoS) commands.

Telegram profile and distribution/vouch links. Actionable links are redacted while the channel identity, subscriber count and structure remain visible (Source: foresiet)
Telegram profile and distribution/vouch links. Actionable links are redacted while the channel identity, subscriber count and structure remain visible (Source: foresiet)

The malware exhibits several distinct offensive capabilities. The targets include 18 web browsers, 21 clipper coin formats, 7 desktop wallets, and 4 Discord client variants.

Staged native modules handle hidden virtual desktop control, screen-capture automation, and privilege-escalation attempts. Post-infection tools provide operators with live remote shell access and file manager functions.

According to Foresiet research, the threat actors actively maintain this toolkit and recently announced plans to migrate the malware from Node.js to Java to improve evasion.

ArtifactDetailSHA-256 Hashes
Outer archiveWinZip-AES password-protected ZIPa380e66f381c9f88f4f221906f12b73e
1f43517c8e5f6affcaca71fad3340d5f
Inner payload100 MB Windows x64 Node.js SEA executable101351cff5f971cd39bd6280be02a5e0
e8f08d9874cae78b971e3a421a7050f6

Because the underlying code base may shift, security teams should prioritize behavioral hunting over static hash detection.

A complete compromise involves extensive data exposure, meaning defenders must treat any execution of Lucid Stealer as a severe breach requiring immediate password rotation and session revocation.

IndicatorTypeContext
45[.]138[.]16[.]107:3001C2Primary command-and-control base endpoint (hard-coded)
/uploadURIStolen-data archive upload endpoint
/internal/logURIMetadata and keylog telemetry endpoint
/dc-injectorURIDiscord injection payload retrieval
/wsURIWebSocket C2 path
lucidstealer[.]oneDomainUser-supplied panel domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post New Lucid Stealer Targets Browsers, Crypto Wallets, and Discord Tokens appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading