Luca Stealer is a Rust-based information stealer that has appeared in the wild and was also released publicly as open-source malware. The provided content indicates it as an example of the broader trend of threat actors adopting modern languages such as Rust, Golang, and Nim instead of C/C++ for malware development. Because Rust malware can be compiled for both Linux and Windows with minimal changes, Luca Stealer is associated with cross-platform development potential. Analysis of Rust binaries is noted as challenging due to Rust-specific string handling and binary structure, including non-null-terminated strings that can complicate reverse engineering in tools such as Ghidra. High-confidence artifacts and indicators mentioned for Rust malware analysis include the runtime entry point string "std::rt::lang_start_internal", Cargo-related strings such as "cargo\registry", statically linked crate artifacts, and debug data that may leak author usernames or system paths. The content also notes that artifacts from the Rust build process can aid attribution and dependency analysis. No specific infection vector, victimology, threat actor attribution, or Luca-Stealer-specific IOCs beyond these Rust-analysis artifacts are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Luca Stealer is a Rust-based information stealer that targets both Linux and Windows systems. It is notable for being released as open-source, allowing threat actors to easily adopt and modify it. The malware is designed to steal sensitive information from infected systems.
Ransomware-like malware referenced as a family resemblance among samples; described as encrypting files and demanding cryptocurrency payments.
Named family referenced in the report in the context of ransomware-like behavior (file encryption and crypto payment demands), though the text is internally inconsistent about whether it is a stealer vs ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.