Skuld Stealer is an open-source Golang information stealer focused on harvesting browser data, Discord tokens, cryptocurrency wallet data, local files, and host reconnaissance from Windows systems. It has been referred to as TMPN Stealer in some reporting and appears in both commodity crimeware use and customized campaigns. Core collection functions include theft of browser logins, cookies, payment-card data, downloads, and history from Chromium- and Gecko-based browsers; extraction and validation of Discord tokens; collection of system information; theft of wallet files and wallet-related browser extension data; and targeting of game-session data. Some variants also include a clipboard hijacking component for cryptocurrency theft.
The malware is notable for strong Discord-centric tradecraft. It tampers with Discord-related protections, modifies BetterDiscord and DiscordTokenProtector settings, and deploys malicious Discord injection code designed to intercept authentication and account-change workflows, including login, registration, two-factor authentication, and payment-related data. Customized deployments have also targeted cryptocurrency wallet applications such as Exodus and Atomic by injecting malicious code to capture wallet secrets, including seed phrases.
Skuld Stealer incorporates multiple post-compromise and evasion features. Reported samples use a mutex to avoid duplicate execution, attempt privilege escalation through a fodhelper UAC bypass, establish persistence via autorun configuration, hide files and console windows, perform anti-debugging checks, and apply anti-virtualization logic based on host artifacts. Some samples also attempt to weaken Microsoft Defender protections and interfere with access to security-vendor resources. Exfiltration has been observed through Discord webhooks, and some variants archive stolen files before upload.
Observed delivery has included social-engineering chains tied to malicious Discord invite hijacking and ClickFix-style lures that trick victims into executing PowerShell, as well as post-exploitation deployment following exploitation of internet-facing infrastructure. The malware is primarily associated with credential and wallet theft for financially motivated activity, with emphasis on Discord users, cryptocurrency holders, and Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
it opens a " AppData\Roaming\DiscordTokenProtector\config.json " file and changes the next values...
This function sets the malware path to the fodhelper.exe utility registry key: HKCU\\Software\\Classes\\ms-settings\\shell\\open\\command\\DelegateExecute
The old process then will clear the Fodhelper registry key and terminate.
"%s\\Windows Defender\\MpCmdRun.exe", os.Getenv("ProgramFiles")), "-RemoveDefinitions", "-All
Skuld checks if the sample is running on a Virtual Machine. To do this it checks the hostname, username, MAC address, IP address and HWID... If any string matches, it will terminate execution.
This script will set up hooks and intercept such data as login, register and 2FA requests, PayPal credits and email / password changes.
Functions that extract data, such as logins, cookies, credit cards, downloads and history, are the same for all browsers.
Functions that extract data, such as logins, cookies, credit cards, downloads and history, are the same for all browsers.
The stealer collects various sensitive data stored by Chromium and Gecko-based browsers, such as cookies, saved credit card information, downloads, browsing history, and login credentials.
Skuld starts obtaining system information... CPU, disks, GPU, Network, OS, Windows license keys, RAM and others.
Common files This function will search for files with particular keywords in their names and extensions... the file will be copied to the new folder... archived with a password... uploaded to the server
This script will set up hooks and intercept such data as login, register and 2FA requests, PayPal credits and email / password changes.
It uses multiple regex values to filter clipboard data... if there is a match, it will replace this data with its own cryptocurrency wallet address.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source Golang information stealer capable of stealing crypto wallets, files, system information, browser data and tokens; includes anti-debugging/anti-VM logic and a UAC bypass.
An open-source Golang information stealer capable of stealing crypto wallets, files, system information, browser data, and tokens; includes anti-debug/anti-VM features and a UAC bypass.
Information-stealing malware delivered via hijacked Discord invite links/verification lures; steals Discord credentials and browser tokens and targets cryptocurrency wallet seeds/passwords, exfiltrating via Discord webhooks.
Credential/asset stealer customized to target cryptocurrency wallets; includes wallet-application code injection to capture seed phrases when wallets are unlocked.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.