Luca Stealer

Malware type
credential-stealer, screen-capture, spyware
Family
Malware family
Last IoC activity
2026-07-21 02:40:06
Profile updated
2026-07-07 15:10:17

Targeted industries: technology-and-telecommunications media-and-entertainment retail-and-hospitality

Context

According to PCRisk, The Luca stealer can extract a variety of information from compromised machines. It targets data related to the following: operating system, device name, CPUs, desktop environment, network interface, user account name, preferred system language, running processes, etc. This malicious program can steal information from over thirty Chromium-based browsers. From these applications, Luca can obtain Internet cookies, account log-in credentials (usernames/passwords), and credit card numbers. Additionally, the stealer can extract data from password manager and cryptowallet browser extensions compatible with over twenty browsers. This malware also targets various messaging applications like Telegram, Discord, ICQ, Skype, Element, etc. It likewise aims to acquire information from gaming-related software such as Steam and Uplay (Ubisoft Connect). Furthermore, some versions of Luca can take screenshots and download the files stored on victims' devices.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Stealer_Win_Luca (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Luca Stealer (report)
  • blogs.blackberry.com — Luca Stealer Targets Password Managers And Cryptocurrency Wallets (report)

External references