Skip to main content
Mallory
Back to malware
Malware

Lucid Stealer

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.003Windows Command ShellEvidence1

Combined with a remote shell, a file manager, keylogging, and screenshot capture, the attacker has essentially the same access as if they were sitting in front of the machine themselves.

Persistence

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence1

Once opened, it runs through a layered setup process that drops helper files, sets up persistence in the Windows registry, and optionally tries to gain elevated privileges.

Privilege Escalation

2 techniques
T1547.001Registry Run Keys / Startup FolderEvidence1

Once opened, it runs through a layered setup process that drops helper files, sets up persistence in the Windows registry, and optionally tries to gain elevated privileges.

T1548Abuse Elevation Control MechanismEvidence1

Once opened, it runs through a layered setup process that drops helper files, sets up persistence in the Windows registry, and optionally tries to gain elevated privileges.

Stealth

1 technique
T1036MasqueradingEvidence1

The entire malicious package is wrapped inside a legitimate Node.js runtime, making it look like a normal software application to most standard security tools.

Credential Access

3 techniques
T1056.001KeyloggingEvidence1

Combined with a remote shell, a file manager, keylogging, and screenshot capture, the attacker has essentially the same access as if they were sitting in front of the machine themselves.

T1539Steal Web Session CookieEvidence1

Credentials, browser cookies, Discord sessions, crypto wallet keys, and Roblox session data are all at risk the moment the malware runs.

T1555Credentials from Password StoresEvidence1

It goes after saved credentials, session cookies, autofill data, and browser history using a bundled SQLite tool to query copied browser databases directly.

Collection

4 techniques
T1056.001KeyloggingEvidence1

Combined with a remote shell, a file manager, keylogging, and screenshot capture, the attacker has essentially the same access as if they were sitting in front of the machine themselves.

T1113Screen CaptureEvidence1

Combined with a remote shell, a file manager, keylogging, and screenshot capture, the attacker has essentially the same access as if they were sitting in front of the machine themselves.

T1115Clipboard DataEvidence1

It also monitors clipboard activity, so any crypto wallet address a victim copies can be silently swapped with one controlled by the attacker.

T1560Archive Collected DataEvidence1

The malware arrives in a password-protected ZIP archive.

Command and Control

1 technique
T1219Remote Access ToolsEvidence1

The malware includes a hidden desktop control feature, called HVNC, that lets operators take over a machine visually without opening any visible window on the victim’s screen.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Network defenders should block all traffic to the known C2 address and watch for repeated POST requests to internal log and upload endpoints as additional confirmation.

INDICATORS OF COMPROMISE

IOCs tracked for this family

17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
7 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
10 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
hash.md5●●●●●●●●●●●●View more in apptoday
hash.md5●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching17

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.