Skip to content

Skuld

Skuld is an information-stealing malware targeting Windows systems.

Profile source: Mallory opens in a new tab

Skuld

Family profile

Skuld is an information-stealing malware targeting Windows systems. Reported activity shows it is used to steal Discord-related data from infected PCs, including Discord tokens and user data. It has been observed in active distribution campaigns, including reporting that campaigns delivered Skuld alongside AsyncRAT, and it has also been referenced among open-source infostealers distributed in ClickFix-related activity. Public reporting notes overlaps between Skuld, ThunderKitty, and Kematian Stealer. Detection content indicates static YARA coverage exists for Skuld, with rules described as matching byte patterns associated with its data-theft functions. High-confidence indicators and characteristics directly mentioned in the source include its focus on Windows hosts, Discord data theft, exfiltration of Discord tokens and user information, and the existence of YARA detections for its theft functionality.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.