Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Skuld is an information-stealing malware targeting Windows systems.
Profile source: Mallory opens in a new tabSkuld
Skuld is an information-stealing malware targeting Windows systems. Reported activity shows it is used to steal Discord-related data from infected PCs, including Discord tokens and user data. It has been observed in active distribution campaigns, including reporting that campaigns delivered Skuld alongside AsyncRAT, and it has also been referenced among open-source infostealers distributed in ClickFix-related activity. Public reporting notes overlaps between Skuld, ThunderKitty, and Kematian Stealer. Detection content indicates static YARA coverage exists for Skuld, with rules described as matching byte patterns associated with its data-theft functions. High-confidence indicators and characteristics directly mentioned in the source include its focus on Windows hosts, Discord data theft, exfiltration of Discord tokens and user information, and the existence of YARA detections for its theft functionality.
C2 tracking
Derp observations, rolling seven-day window
Samples
02994a804f39c8f5d73cdec837ae731f7e6c0dd7f9a6a73be0c1ec057d81aaee 2de562fafcc37cae182d78ac490f01f38f78f57b845dd7b34641733d616bd0f8 54981838588030121270c471c523ae39b47d0f4528683036721e04681588ddb2 9ab4ffc82c376061eab5df7088241b28f424b5f8ca8162e0783c78238eaf7512 a48d13c8760ba533fef095ce3c303b81662f684809138fbaa4310edea6d4c260 Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.