SYMBOLCOMMON_NAMEaka. SYNONYMS
win.luca_stealer (Back to overview)

Luca Stealer

VTCollection    

According to PCRisk, The Luca stealer can extract a variety of information from compromised machines. It targets data related to the following: operating system, device name, CPUs, desktop environment, network interface, user account name, preferred system language, running processes, etc.

This malicious program can steal information from over thirty Chromium-based browsers. From these applications, Luca can obtain Internet cookies, account log-in credentials (usernames/passwords), and credit card numbers. Additionally, the stealer can extract data from password manager and cryptowallet browser extensions compatible with over twenty browsers.

This malware also targets various messaging applications like Telegram, Discord, ICQ, Skype, Element, etc. It likewise aims to acquire information from gaming-related software such as Steam and Uplay (Ubisoft Connect). Furthermore, some versions of Luca can take screenshots and download the files stored on victims' devices.

References
2022-08-18 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
Luca Stealer
Yara Rules
[TLP:WHITE] win_luca_stealer_auto (20260917 | Detects win.luca_stealer.)
rule win_luca_stealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.luca_stealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.luca_stealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { eb12 4898 48c1e005 4a8b0410 48894110 44894908 4885c0 }
            // n = 7, score = 100
            //   eb12                 | dec                 eax
            //   4898                 | mov                 dword ptr [esp + 0x20], eax
            //   48c1e005             | mov                 edx, 0x100
            //   4a8b0410             | dec                 eax
            //   48894110             | lea                 ecx, [esp + 0x30]
            //   44894908             | mov                 esi, dword ptr [eax + 4]
            //   4885c0               | dec                 ecx

        $sequence_1 = { eb4c 4c8d059a962a00 eb40 4c8d05a9962a00 eb3a 4c8d0578972a00 eb8a }
            // n = 7, score = 100
            //   eb4c                 | dec                 ecx
            //   4c8d059a962a00       | mov                 ebp, dword ptr [ebx + 0x20]
            //   eb40                 | dec                 ecx
            //   4c8d05a9962a00       | mov                 esi, dword ptr [ebx + 0x28]
            //   eb3a                 | mov                 eax, ebx
            //   4c8d0578972a00       | jmp                 0x1334
            //   eb8a                 | mov                 eax, 0x3d

        $sequence_2 = { eb03 49891a 41891b 488b9c2488000000 418bc7 4883c440 415f }
            // n = 7, score = 100
            //   eb03                 | mov                 eax, dword ptr [edi + esi + 0x3c]
            //   49891a               | mov                 dword ptr [ecx + 8], eax
            //   41891b               | mov                 eax, dword ptr [edi + esi + 0x4c]
            //   488b9c2488000000     | mov                 dword ptr [ecx + 0xc], eax
            //   418bc7               | movzx               eax, word ptr [ebx + 2]
            //   4883c440             | mov                 word ptr [ecx + 0x10], ax
            //   415f                 | xor                 edi, edi

        $sequence_3 = { ba09000000 488d0d3a473b00 e9???????? ba07000000 488d0dba463b00 e9???????? ba05000000 }
            // n = 7, score = 100
            //   ba09000000           | dec                 eax
            //   488d0d3a473b00       | mov                 ecx, ebx
            //   e9????????           |                     
            //   ba07000000           | mov                 edi, eax
            //   488d0dba463b00       | test                eax, eax
            //   e9????????           |                     
            //   ba05000000           | jne                 0x46d

        $sequence_4 = { e9???????? b8a9000000 3bd8 0f8759040000 0f841c040000 b8a4000000 3bd8 }
            // n = 7, score = 100
            //   e9????????           |                     
            //   b8a9000000           | mov                 eax, dword ptr [ebx + ecx*4]
            //   3bd8                 | inc                 ecx
            //   0f8759040000         | sub                 eax, ebp
            //   0f841c040000         | mov                 dword ptr [ebx + ecx*4], eax
            //   b8a4000000           | dec                 eax
            //   3bd8                 | cwde                

        $sequence_5 = { e9???????? c6430109 b001 8803 4889d1 4881c488010000 5b }
            // n = 7, score = 100
            //   e9????????           |                     
            //   c6430109             | je                  0x13ca
            //   b001                 | mov                 dword ptr [esi], eax
            //   8803                 | dec                 eax
            //   4889d1               | lea                 edx, [0x25470b]
            //   4881c488010000       | inc                 esp
            //   5b                   | cmp                 byte ptr [ebx + 0x68], bh

        $sequence_6 = { ebd0 488d542430 44884a08 44884209 890a 894204 488d4c2427 }
            // n = 7, score = 100
            //   ebd0                 | mov                 edx, ebx
            //   488d542430           | mov                 ecx, dword ptr [esp + 0x64]
            //   44884a08             | dec                 eax
            //   44884209             | lea                 edx, [esp + 0x64]
            //   890a                 | dec                 eax
            //   894204               | mov                 ebx, eax
            //   488d4c2427           | mov                 dword ptr [eax + 0x20], ecx

        $sequence_7 = { ebc2 488d05dcc02500 48894567 ba00001000 488d4def e8???????? 488d8bf80c0000 }
            // n = 7, score = 100
            //   ebc2                 | cmovne              ecx, ebx
            //   488d05dcc02500       | xor                 eax, eax
            //   48894567             | inc                 esp
            //   ba00001000           | sub                 eax, ecx
            //   488d4def             | inc                 esp
            //   e8????????           |                     
            //   488d8bf80c0000       | mov                 esi, eax

        $sequence_8 = { e8???????? 4084ed 740e 488b8be00a0000 e8???????? eb05 e8???????? }
            // n = 7, score = 100
            //   e8????????           |                     
            //   4084ed               | mov                 al, byte ptr [esp + 0x42]
            //   740e                 | cmp                 al, 0x2c
            //   488b8be00a0000       | je                  0x464
            //   e8????????           |                     
            //   eb05                 | cmp                 al, 0x7d
            //   e8????????           |                     

        $sequence_9 = { e8???????? 4585ed 741f 448b4f20 4585c9 7507 448b8e98000000 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   4585ed               | cmp                 bl, 2
            //   741f                 | je                  0xd7d
            //   448b4f20             | mov                 eax, ebx
            //   4585c9               | and                 al, 1
            //   7507                 | jne                 0xebf
            //   448b8e98000000       | dec                 eax

    condition:
        7 of them and filesize < 9285632
}
Download all Yara Rules