
A new build of Lucid Stealer, a Malware-as-a-Service (MaaS) promoted through underground Telegram channels.
Instead of using a generic packed executable, attackers packaged this credential stealer and remote-access trojan (RAT) inside a legitimate Node.js Single Executable Application (SEA) wrapper.
The malware targets numerous browsers, cryptocurrency wallets, and Discord tokens while providing operators with full post-infection control.
Lucid Stealer Targets Wallets
The infection begins when a victim opens a password-protected WinZip-AES archive containing a 100 MB Windows executable.
This large file acts as a delivery and concealment layer, leveraging a legitimate Node.js runtime to hide an 8.5 MB JavaScript loader.
Once executed, the loader extracts helper binaries to disk and decrypts the core second-stage payload using an RC4-style algorithm.
Lucid Stealer operates as a highly capable hybrid threat rather than just a basic credential scraper. The recovered JavaScript payload reveals discrete modules designed for extensive data theft and remote system administration.
Threat actors can launch hidden virtual network computing (HVNC) sessions, automate synthetic screen inputs, capture desktop screenshots, and execute distributed denial-of-service (DDoS) commands.
The malware exhibits several distinct offensive capabilities. The targets include 18 web browsers, 21 clipper coin formats, 7 desktop wallets, and 4 Discord client variants.
Staged native modules handle hidden virtual desktop control, screen-capture automation, and privilege-escalation attempts. Post-infection tools provide operators with live remote shell access and file manager functions.
According to Foresiet research, the threat actors actively maintain this toolkit and recently announced plans to migrate the malware from Node.js to Java to improve evasion.
| Artifact | Detail | SHA-256 Hashes |
|---|---|---|
| Outer archive | WinZip-AES password-protected ZIP | a380e66f381c9f88f4f221906f12b73e1f43517c8e5f6affcaca71fad3340d5f |
| Inner payload | 100 MB Windows x64 Node.js SEA executable | 101351cff5f971cd39bd6280be02a5e0e8f08d9874cae78b971e3a421a7050f6 |
Because the underlying code base may shift, security teams should prioritize behavioral hunting over static hash detection.
A complete compromise involves extensive data exposure, meaning defenders must treat any execution of Lucid Stealer as a severe breach requiring immediate password rotation and session revocation.
| Indicator | Type | Context |
|---|---|---|
45[.]138[.]16[.]107:3001 | C2 | Primary command-and-control base endpoint (hard-coded) |
/upload | URI | Stolen-data archive upload endpoint |
/internal/log | URI | Metadata and keylog telemetry endpoint |
/dc-injector | URI | Discord injection payload retrieval |
/ws | URI | WebSocket C2 path |
lucidstealer[.]one | Domain | User-supplied panel domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post New Lucid Stealer Targets Browsers, Crypto Wallets, and Discord Tokens appeared first on Cyber Security News.
Discover more from RSS Feeds Cloud
Subscribe to get the latest posts sent to your email.
