In May 2023, the Trellix Advanced Research Center discovered a new Golang stealer, known as Skuld, that compromised systems worldwide.
Skuld
Skuld is a Golang-based Windows infostealer focused on Discord theft but equipped with broader credential and data-harvesting functionality.
Skuld
Family profile
Skuld is a Golang-based Windows infostealer focused on Discord theft but equipped with broader credential and data-harvesting functionality. First observed in 2023 and later reused in other criminal operations, it has been distributed both as an open-source proof-of-concept and as an operational payload in live malware campaigns, including deployment alongside AsyncRAT and use by HexaLocker V2 prior to ransomware encryption.
Skuld targets Discord tokens, Discord two-factor backup codes, browser-stored credentials, cookies, browsing history, download records, payment-card data, cryptocurrency wallets and wallet extensions, gaming-session data, saved Wi-Fi information, screenshots, host profiling data, and files from predefined sensitive locations. Reported variants also include Discord injection features that intercept authentication and account-change workflows, mechanisms to bypass protections such as BetterDiscord and Discord Token Protector, and wallet-focused theft including mnemonic phrases and passwords from selected wallets. Some builds include clipboard hijacking for cryptocurrency theft.
The malware incorporates multiple anti-analysis and defense-evasion features, including anti-debugging, anti-VM checks, fake error dialogs, process-based security-tool interference, and attempts to disable or weaken Windows Defender. It has also been described as using a UAC-bypass technique via fodhelper.exe to gain elevated access and steal data across user contexts. Persistence at system startup is supported in some versions.
Skuld is best classified as an infostealer. It has been associated with an actor using the alias Deathined, and code and behavioral overlaps have been noted with other open-source stealers and grabbers such as Creal Stealer, Luna Grabber, and BlackCap Grabber. Its availability as source code and modular theft capabilities have made it attractive for reuse by other threat actors targeting Windows users, especially Discord users and victims with browser-stored credentials or cryptocurrency assets.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Persistence
- Privilege Escalation
- Reconnaissance
- Session Hijacking
- Spoofing
Samples
Recent samples
14 sandbox samples in the Derp library, newest 14 shown
2bd897b80ce468ce264144f8d0939b32fede1bc70de26271dd0a0e67df5de50f 20e9fba9c6435cb94f1414ac3178428b69b725b4ed551361f8a0d5d7e440dce4 a44fc448d91fb9c8b7cb58b5ad371344ef3e5b8f068594a4a4e323f908489471 71ad3dda3461cd3dfb86add04d615a45de83eb386e5d9086696e69bdc46da7d4 a2d652cf1a082119664fbe344d843108aaaac5134c145b60a7532f40ba79f438 a460ddb047911912a3d320e815ead2476f08c02e05c1f3cb3958101d0114ec0b c9ab13bf00752d28cbb20523a99ab764485f3a8601765f09abef86c758cc01ce 6815e5f8cb5606c0e7dfc31dae7b8aa4178f2b93711e755299adf11f3d15f492 b7afa3570f6da7bdbef5414236161d11c33ccde38e79f9a4c32ac10745cd783b 07e0ec3b789925cb92d1faad9a0bd436202d8a9f92102715741e013279a83ff1 07bb84a36b310e414df590d9d0a37a5f4aa22226d17a6e8e80872e66f8f607bd 2dbbec71fd27cb7cfbc87d07380ecf59ced53eafbe6cabd7343c02b1aa84627d 34768aaa3c21ffa855ffea07b76256cfa4308abdaea453badbdeaafbaf369a90 f42a049263036a569bf9c942f77bc887f6fb0f2b9378fc30b83bb388496fcc43 Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Skuld in ATT&CK
36 distinct techniquesTechniques
36 techniquesReporting
Research mentioning Skuld
Skuld: The Infostealer that Speaks Golang
Trellix disclosed technical details on Skuld, a Golang-based infostealer linked to an actor using the alias Deathined, after observing infections affecting systems globally. The malware targets Discord, Chromium- and Gecko-based browsers, and the local host, harvesting tokens, browser data, system and network information, screenshots, backup codes, and in some variants local files. Researchers said Skuld also injects JavaScript into Discord and can bypass protections from BetterDiscord and Discord Token Protector. The report said Skuld uses anti-analysis and anti-VM checks to hinder investigation and evade security tooling, while exfiltrating stolen data primarily through Discord webhooks and in some cases Gofile. Trellix assessed the malware remains under active development, noting that some capabilities, including a clipper and parts of its Discord injection logic, appear only partially implemented. The analysis also found strong code and behavioral overlap with open-source stealers and grabbers including Creal Stealer, Luna Grabber, and BlackCap Grabber, indicating the author likely ported existing functionality into Golang.