Skuld is an information-stealing malware targeting Windows systems. Reported activity shows it is used to steal Discord-related data from infected PCs, including Discord tokens and user data. It has been observed in active distribution campaigns, including reporting that campaigns delivered Skuld alongside AsyncRAT, and it has also been referenced among open-source infostealers distributed in ClickFix-related activity. Public reporting notes overlaps between Skuld, ThunderKitty, and Kematian Stealer. Detection content indicates static YARA coverage exists for Skuld, with rules described as matching byte patterns associated with its data-theft functions. High-confidence indicators and characteristics directly mentioned in the source include its focus on Windows hosts, Discord data theft, exfiltration of Discord tokens and user information, and the existence of YARA detections for its theft functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer delivered via Discord invite link hijacking; targets cryptocurrency wallet-related data per the title/context.
Windows infostealer; discussed in the context of YARA signatures matching byte patterns associated with data theft functionality.
Skuld is a stealer malware that targets Windows PCs to steal Discord data.
Skuld is an infostealer malware that shares code or operational similarities with ThunderKitty and Kematian Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.