Wednesday, September 16, 2026

Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens

A new, fully featured Lucid Stealer build that combines large-scale credential theft with hidden remote access.

The sample, distributed through Telegram-linked underground channels, is not a simple packed executable but a Lucid-branded information stealer and RAT wrapped inside a legitimate Node.js Single Executable Application (SEA).

Static analysis recovered an embedded JavaScript loader and decrypted core payload without executing the sample, giving high confidence in the findings and a clear view of operator capabilities and infrastructure.

The malware arrives in a password-protected WinZip-AES archive containing a roughly 100 MB Windows x64 Node.js SEA executable.

Inside that runtime sits an approximately 8.5 MB NODE_SEA_BLOB JavaScript loader which rebuilds and writes helper binaries to disk, then decrypts and executes a second-stage JavaScript payload.

The recovered core uses an RC4-style PRGA and an XOR pass to protect its code.

Analysts extracted modular components responsible for browser credential and cookie theft, Discord token harvesting and injection, multiple wallet-targeting routines, keylogging, screenshot capture, remote shell and file-manager functions, DDoS commands, and HVNC-style hidden desktop control.

A bundled SQLite CLI for querying copied browser databases, a native elevation addon invoked for privilege escalation attempts, an HVNC addon for hidden VNC and remote-screen control, RobotJS for synthetic input and screen capture, and a canvas image module for rendering screenshots and streams.

Foresiet Threat Intel Team identified and statically analyzed a newly observed Lucid Stealer build promoted through Telegram-linked underground channels.

The SEA wrapper’s role is concealment and delivery; the actual risk comes from the staged helpers, the decoded configuration, and the payload’s broad command surface.

Lucid Stealer Hits 18 Browsers

Operator activity and infrastructure evidence point to a small but organized commercial operation. Foresiet correlated Telegram announcements, a hosted multi-tenant web control panel, and a release timeline showing a brief pause and rapid relaunch in late May 2026.

Lucid Stealer web authentication panel (Source : Foresiet).
Lucid Stealer web authentication panel (Source : Foresiet).

The operator publicly signaled plans to re-platform from Node.js to Java to evade defenses and improve performance, indicating active maintenance and likely future variations.

Screenshots of the panel and channel were sanitized for public sharing; embedded strings and loader variables include Lucid branding (for example, LUCIDPay and _LUCID*), which the report treats as operator self-identification rather than a community-assigned family name.

From a defender’s perspective, Lucid Stealer should be treated as a full compromise event. This build targets a wide array of applications 18 browsers, multiple wallet formats and extensions, and four Discord client variants so stolen browser tokens, saved passwords, Discord sessions, game sessions, and wallet seed material must be assumed exposed if execution occurred.


Publication-safe infection-flow map for the recovered Lucid Stealer build (Source : Foresiet).
Publication-safe infection-flow map for the recovered Lucid Stealer build (Source : Foresiet).

Because the operator is actively developing the product, static hashes identify only this specific build; reliable detection requires hunting for behavioral staging and persistence patterns instead.

High-value signals include temporary self-copies named like winupd, HKCU Run persistence entries, user-profile .node addon staging, suspicious browser database access, and the specific upload/log URI sequences recovered from the decoded configuration.

Foresiet’s blog reframes the full technical report into a corporate-style deep dive covering executive summary, threat context, technical findings, capability analysis, infection-flow details and pragmatic detection and response guidance.

Enterprises should prioritize containment, assume credential and key compromise on suspected hosts, and hunt for the staging behaviors and native helper artifacts documented in the report.

For teams wanting the full technical indicators, sanitized screenshots, hashes, and network indicators, consult the Foresiet detailed report and use behavior-focused detection rules rather than relying solely on changing file hashes.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News