logo

Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens

ID: 3f86e58d-7c16-5050-8efb-19e6d726fe6b

STIX ID: report--3f86e58d-7c16-5050-8efb-19e6d726fe6b

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Foresiet analysts recovered and statically analyzed a Lucid Stealer build delivered inside a Node.js Single Executable Application distributed via Telegram-linked underground channels; the multi-stage payload includes modules for browser credential and cookie theft (18 browsers), Discord token harvesting, wallet-targeting routines, keylogging, screenshots, remote shell/file management, DDoS commands, and HVNC-style hidden desktop control. The report describes the SEA concealment, decrypted JavaScript payloads, embedded helpers (SQLite CLI, native elevation and HVNC addons), staging/persistence indicators, sanitized screenshots, and provides pragmatic detection and response guidance and behavioral hunting recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.