Skuld is a Golang-based Windows infostealer focused on Discord theft but equipped with broader credential and data-harvesting functionality. First observed in 2023 and later reused in other criminal operations, it has been distributed both as an open-source proof-of-concept and as an operational payload in live malware campaigns, including deployment alongside AsyncRAT and use by HexaLocker V2 prior to ransomware encryption.
Skuld targets Discord tokens, Discord two-factor backup codes, browser-stored credentials, cookies, browsing history, download records, payment-card data, cryptocurrency wallets and wallet extensions, gaming-session data, saved Wi-Fi information, screenshots, host profiling data, and files from predefined sensitive locations. Reported variants also include Discord injection features that intercept authentication and account-change workflows, mechanisms to bypass protections such as BetterDiscord and Discord Token Protector, and wallet-focused theft including mnemonic phrases and passwords from selected wallets. Some builds include clipboard hijacking for cryptocurrency theft.
The malware incorporates multiple anti-analysis and defense-evasion features, including anti-debugging, anti-VM checks, fake error dialogs, process-based security-tool interference, and attempts to disable or weaken Windows Defender. It has also been described as using a UAC-bypass technique via fodhelper.exe to gain elevated access and steal data across user contexts. Persistence at system startup is supported in some versions.
Skuld is best classified as an infostealer. It has been associated with an actor using the alias Deathined, and code and behavioral overlaps have been noted with other open-source stealers and grabbers such as Creal Stealer, Luna Grabber, and BlackCap Grabber. Its availability as source code and modular theft capabilities have made it attractive for reuse by other threat actors targeting Windows users, especially Discord users and victims with browser-stored credentials or cryptocurrency assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In May 2023, the Trellix Advanced Research Center discovered a new Golang stealer, known as Skuld, that compromised systems worldwide.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
discordinjection: Intercepts login, register, and 2FA login requests. Captures backup codes requests. Monitors email/password change requests. Intercepts credit card/PayPal addition requests.
discordinjection: Intercepts login, register, and 2FA login requests. Captures backup codes requests. Monitors email/password change requests. Intercepts credit card/PayPal addition requests.
tokens: Extracts tokens from 4 Discord applications, Chromium-based browsers, and Gecko browsers.
browsers: Steals logins, cookies, credit cards, history, and download lists from 37 Chromium-based browsers.
browsers: Steals logins, cookies, credit cards, history, and download lists from 37 Chromium-based browsers. Steals logins, cookies, history, and download lists from 10 Gecko browsers.
The third and final block of checks performed by Skuld is getting the running processes of the system and comparing them to a blocklist.
system: Gathers CPU, GPU, RAM, IP, location, saved Wi-Fi networks, and more.
The sample includes a file stealer module that targets files stored in a predefined list of paths, which is set up in the initialization part.
The next target of the Skuld stealer malware is the information stored by Chromium and Gecko-based browsers.
discordinjection: Intercepts login, register, and 2FA login requests. Captures backup codes requests. Monitors email/password change requests. Intercepts credit card/PayPal addition requests.
discordinjection: Intercepts login, register, and 2FA login requests. Captures backup codes requests. Monitors email/password change requests. Intercepts credit card/PayPal addition requests.
241 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based infostealer that targets Discord, Chromium- and Gecko-based browsers, system information, screenshots, and files from predefined paths. Some samples also include an in-development cryptocurrency clipper and file-stealing/Gofile exfiltration modules, plus anti-analysis and VM-detection checks.
Information stealer delivered via Discord invite link hijacking; targets cryptocurrency wallet-related data per the title/context.
Windows infostealer; discussed in the context of YARA signatures matching byte patterns associated with data theft functionality.
Skuld is a stealer malware that targets Windows PCs to steal Discord data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.