Skip to content
Data Breach

New Lucid Stealer Targets 18 Browsers, Crypto Wallets, and Discord Tokens With Hidden Remote Access

A newly identified piece of Windows malware is raising serious concerns among cybersecurity professionals for its wide reach and unusually deep set of capabilities. Discovered through underground channels linked to Telegram, the threat known as Lucid Stealer goes far beyond stealing a few stored pas...

· Jun 08, 2026 · 6 min read · 👁 0 views

A newly identified piece of Windows malware is raising serious concerns among cybersecurity professionals for its wide reach and unusually deep set of capabilities.

Discovered through underground channels linked to Telegram, the threat known as Lucid Stealer goes far beyond stealing a few stored passwords. It can take full control of an infected machine without the victim ever noticing anything is wrong.

What makes this malware particularly dangerous is how it disguises itself. The entire malicious package is wrapped inside a legitimate Node.js runtime, making it look like a normal software application to most standard security tools.

This clever packaging allows it to slip past basic defenses while quietly carrying out a wide range of harmful activities in the background.

Researchers at Foresiet identified and statically analyzed this Lucid Stealer build after noticing renewed activity tied to a dedicated Telegram channel promoting the tool as a paid, subscription-based product. 

Foresiet said in a report shared with Cyber Security News (CSN) that the sample is far more capable than a typical credential stealer, combining data theft with live remote access in a single build.

The malware is sold as a commercial service, complete with a hosted web panel, license keys, and an active support channel.

The operators briefly shut down the project in late May 2026 before relaunching it days later, announcing a full rebuild of the site and even a planned move away from Node.js toward Java for better evasion. This shows that the people behind it are actively investing in improving and expanding the threat.

The situation is especially serious because infections should be treated as full compromises. Credentials, browser cookies, Discord sessions, crypto wallet keys, and Roblox session data are all at risk the moment the malware runs.

Defenders are urged to act fast and assume everything stored on the infected machine has already been seen by the attacker.

New Lucid Stealer Targets 18 Browsers, Crypto Wallets, and Discord Tokens

Lucid Stealer is built to steal from nearly every corner of a user’s digital life. The analyzed build targets 18 browsers, 21 cryptocurrency clipper formats, seven desktop wallets, seven wallet browser extensions, and four Discord client variants.

Lucid Stealer web authentication panel (Source - Foresiet)
Lucid Stealer web authentication panel (Source – Foresiet)

It goes after saved credentials, session cookies, autofill data, and browser history using a bundled SQLite tool to query copied browser databases directly.

The malware injects itself into Discord clients to steal tokens and modify the app to send stolen data back continuously. It also monitors clipboard activity, so any crypto wallet address a victim copies can be silently swapped with one controlled by the attacker.

These capabilities work together to drain both financial accounts and communication platforms at the same time.

What truly sets this threat apart is its remote access module. The malware includes a hidden desktop control feature, called HVNC, that lets operators take over a machine visually without opening any visible window on the victim’s screen.

Combined with a remote shell, a file manager, keylogging, and screenshot capture, the attacker has essentially the same access as if they were sitting in front of the machine themselves.

Infection Chain and Detection Guidance for Defenders

The malware arrives in a password-protected ZIP archive. Once opened, it runs through a layered setup process that drops helper files, sets up persistence in the Windows registry, and optionally tries to gain elevated privileges.

Infection flow (Source - Foresiet)
Infection flow (Source – Foresiet)

By the time the main payload decrypts and runs, the attacker already has a stable foothold.

Security teams should focus on behavior-based detection rather than relying only on file hashes, since the operators have already announced plans to rebuild the malware on a new platform.

Hunting for temporary self-copies in the Windows TEMP folder disguised as “winupd” files, suspicious HKCU Run registry entries named WindowsUpdate, and unexpected .node module files appearing in user profiles are among the strongest signals of an active infection.

Network defenders should block all traffic to the known C2 address and watch for repeated POST requests to internal log and upload endpoints as additional confirmation.

Indicators of Compromise (IoCs)

TypeIndicatorDescription
SHA-256a380e66f381c9f88f4f221906f12b73e1f43517c8e5f6affcaca71fad3340d5fOuter WinZip-AES password-protected ZIP archive
SHA-256101351cff5f971cd39bd6280be02a5e0e8f08d9874cae78b971e3a421a7050f6Inner 100 MB Windows x64 Node.js SEA executable (primary payload)
SHA-2568422c48d6301426a39bf9b3d7f11bdbe e7708e8a4e58171f38a5b5e51a8a53b8Embedded ~8.5 MB NODE_SEA_BLOB JavaScript loader
SHA-256cad3f0dde70a5d37c996abee75f39aff8e7603862f071a8c85cb48ee5482750fDecrypted JavaScript stealer/RAT core payload
SHA-2565e33fe030fb7c3bbe2bca1f70f21a406716961aefdfb1bc030d7c65b7db055e9Bundled SQLite helper binary
SHA-256fc52b15848191ad97213d49c7f3c21760e1cc9507d5fb0d77fa75b7620c0deacUAC/elevation native N-API addon
SHA-2566fb83f431f43d7b13e411676cdaa98d8ce005ffd61eed9d1d117698476acfb44HVNC hidden desktop control native module
SHA-25618e61b06068a8dd71e19ed3b117e4b0800f6dfbf252f381961dbb15b44ecc481RobotJS screen capture and synthetic input addon
SHA-256f85e5b19198cc4800be76346bb2868abdd45acbb314968cf2fe41cb18b502bfaCanvas addon for screenshots and streaming
IP Address45[.]138[.]16[.]107:3001Primary C2 command-and-control endpoint (hard-coded in sample, AS210558)
IP Address85[.]239[.]155[.]68Resolving infrastructure for lucidstealer[.]one at analysis time
Domainlucidstealer[.]oneUser-supplied panel domain
Domainiloveyoulucid[.]spaceUser-supplied panel domain; resolved in DNS at analysis time
Domainghdfhfjhfg[.]webhop[.]meUser-supplied panel domain; no DNS resolution at analysis time
Domain0kt[.]oneUser-supplied panel domain; resolved in DNS at analysis time
Domainstoredonutsmp[.]netUser-supplied panel domain; resolved in DNS at analysis time
URI/uploadStolen-data archive upload endpoint
URI/internal/logMetadata and keylog telemetry endpoint
URI/dc-injectorDiscord injection payload retrieval endpoint
URI/wsWebSocket C2 communication path
File%TEMP%\winupd_<random>.exeHidden self-copy of the loader
File%TEMP%_sq3e_<pid>.exeDropped SQLite helper binary
File%LOCALAPPDATA%\Common\<id>*.nodeDropped native addons (UAC, HVNC, RobotJS, Canvas)
File%TEMP%\Data_<hwid>.zipStaged exfiltration archive
File%TEMP%\uac.log.txtLoader and elevation activity log
File%TEMP%\lucid_err.logLoader error log
Registry KeyHKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdateAutorun persistence value pointing to loader self-copy
Crypto Addressbc1qj0uraqhgquwcwdlhazy7ahzypz7r987z89dhweBTC clipper replacement address (disabled in this build)
Crypto Address0x239df70C0d328dEb4187A8B50a70ead8cbb1f48DETH clipper replacement address (disabled in this build)
Crypto AddressLYUQyhrqHS9VXzRkQWRHvVEtr5aCCSoVigLTC clipper replacement address (disabled in this build)
License KeyLUCID-M8NJ-SLBQ-ROI2Embedded license key found in sample configuration

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you