Empyrean
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
MITRE ATT&CK
Empyrean in ATT&CK
1 distinct techniquesReporting
Research mentioning Empyrean
Skuld: The Infostealer that Speaks Golang
Trellix disclosed technical details on Skuld, a Golang-based infostealer linked to an actor using the alias Deathined, after observing infections affecting systems globally. The malware targets Discord, Chromium- and Gecko-based browsers, and the local host, harvesting tokens, browser data, system and network information, screenshots, backup codes, and in some variants local files. Researchers said Skuld also injects JavaScript into Discord and can bypass protections from BetterDiscord and Discord Token Protector. The report said Skuld uses anti-analysis and anti-VM checks to hinder investigation and evade security tooling, while exfiltrating stolen data primarily through Discord webhooks and in some cases Gofile. Trellix assessed the malware remains under active development, noting that some capabilities, including a clipper and parts of its Discord injection logic, appear only partially implemented. The analysis also found strong code and behavioral overlap with open-source stealers and grabbers including Creal Stealer, Luna Grabber, and BlackCap Grabber, indicating the author likely ported existing functionality into Golang.