Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
it opens a " AppData\Roaming\DiscordTokenProtector\config.json " file and changes the next values...
This function sets the malware path to the fodhelper.exe utility registry key: HKCU\\Software\\Classes\\ms-settings\\shell\\open\\command\\DelegateExecute
The old process then will clear the Fodhelper registry key and terminate.
"%s\\Windows Defender\\MpCmdRun.exe", os.Getenv("ProgramFiles")), "-RemoveDefinitions", "-All
Skuld checks if the sample is running on a Virtual Machine. To do this it checks the hostname, username, MAC address, IP address and HWID... If any string matches, it will terminate execution.
This script will set up hooks and intercept such data as login, register and 2FA requests, PayPal credits and email / password changes.
Functions that extract data, such as logins, cookies, credit cards, downloads and history, are the same for all browsers.
Functions that extract data, such as logins, cookies, credit cards, downloads and history, are the same for all browsers.
Skuld starts obtaining system information... CPU, disks, GPU, Network, OS, Windows license keys, RAM and others.
Common files This function will search for files with particular keywords in their names and extensions... the file will be copied to the new folder... archived with a password... uploaded to the server
This script will set up hooks and intercept such data as login, register and 2FA requests, PayPal credits and email / password changes.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.