Skuld Malware Grabs Discord and Browser Data from PCs

Skuld, a recently discovered information-stealing malware written in Golang, has successfully compromised Windows systems in Europe, Southeast Asia, and the U.S.

According to Trellix researcher Ernesto Fernández Provecho, Skuld is designed to steal sensitive data from its victims. It searches for valuable information stored in applications like Discord and web browsers, as well as system data and files in the victim's folders.

Skuld shares similarities with other publicly available stealers such as Creal Stealer, Luna Grabber, and BlackCap Grabber. It is believed to be the creation of a developer known online as Deathined, who can be found on platforms like GitHub, Twitter, Reddit, and Tumblr.

Trellix also discovered a Telegram group named "deathinews," suggesting that these online channels may be used to promote Skuld as a service for other threat actors in the future.

To evade analysis, the malware checks if it is running in a virtual environment. It also terminates processes that match a predefined blocklist instead of terminating itself.

Skuld's Capabilities

In addition to gathering system metadata, Skuld has the ability to collect cookies, credentials, and files from various Windows user profile folders, including Desktop, Documents, Downloads, Pictures, Music, Videos, and OneDrive.

Trellix's analysis revealed that Skuld is designed to tamper with legitimate files associated with Better Discord and Discord Token Protector. It injects JavaScript code into the Discord app to extract backup codes, resembling techniques observed in another infostealer based on Rust, as reported by Trend Micro.

Certain versions of Skuld also incorporate a clipper module that alters clipboard content, allowing the theft of cryptocurrency assets by replacing wallet addresses. Trellix speculates that this feature is still in development.

Stolen data is exfiltrated using either an actor-controlled Discord webhook or the Gofile upload service. In the case of the latter, a reference URL to the uploaded ZIP file containing the stolen data is sent to the attacker via the same Discord webhook functionality.

This development highlights the increasing adoption of the Go programming language by threat actors. Go's simplicity, efficiency, and cross-platform compatibility make it an attractive choice for targeting multiple operating systems and expanding the potential victim pool.

June 14, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.