LUCA STEALER: OPEN-SOURCE WEB3 MALWARE

Ohm Shah
Co-Founder at Wallet Guard

Luca Stealer: Open-Source Web3 Malware

⚠️ New Open-Source Malware ⚠️  
🎯 Targeting Web3 🧡  
Code Named:  Luca Stealer  πŸ₯·

πŸ”  High Level:  
- Primarily an info stealer  
- Targets cold/hot wallets  
- Steals discord tokens  
- Steals from over 17 different extensions πŸ‘‡

Why should you care?

β€œThe malware, which the author claims to have developed in just six hours, is quite stealthy, with VirusTotal returning a detection rate of around 22%.” β€” Bleeping Computer

The entire code-base for this malware was released for free. πŸ‘‡

What makes this malware interesting?

πŸ” Uses Discord web-hooks OR Telegram bots to communicate back to attacker  
πŸ” Written in Rust which allows for easy porting to macOS or Linux  
πŸ” Can modify clipboard to attempt to steal crypto by replacing the copied address with theirs.

‍

Why should Web3 Care?‍

πŸ”² This malware targets your hot/cold wallets.  
πŸ”² Could replace copied addresses on clipboard  
πŸ”² Easy to impact Windows, macOS and Linux  
πŸ”² Low Detection Rate

What can I do to protect myself?

πŸ”² Download  [@Malwarebytes](https://twitter.com/Malwarebytes) and get premium  
πŸ”² Never download random files  
πŸ”² Always open documents via Google Docs or something similar  
πŸ”² Check the copied address every-time before sending any transactions.

Sources //

Source code for Rust-based info-stealer released on hacker forums A malware author released the source code of their info-stealer for free on hacking forums earlier this month, and security analysts already report observing several samples being deployed in the wild…

β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€” β€”

Thanks for reading all the way to the end!

If you liked the content consider checking out our chrome extension designed to help you combat scams in Web3!

Wallet Guard logo

‍

Published on
September 5, 2023

Related Articles

All articles