Skip to main content
AVOID.NET

Lucifer DaaS

avoid.net/lucifer-daas0/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·55KRkj…97hm

Summary

Lucifer DaaS is a drainer-as-a-service criminal platform active from at least January 2025 through early 2026, analyzed by Flare threat intelligence researchers across approximately 700 posts collected from underground forums and Telegram channels. The operation employs an affiliate commission model — taking 20% of stolen funds per theft event — and has progressively professionalized its tooling with multichain wallet-draining capabilities, Permit2 signature abuse, automated phishing deployment, and operational resilience measures including migration to decentralized hosting after platform takedowns. No operator identities, attributable wallet addresses, or law enforcement actions have been publicly confirmed as of mid-2026.

Connected Entities

6 entities · 60 linked investigations
Organizations
Lucifer Drainer0Ethereum64Inferno Drainerwallet drainersLucifer DaaS
Protocols
Uniswap
Relationships
  • wallet drainersmentioned withEthereum(70%)
  • Uniswapmentioned withEthereum(80%)
  • Inferno Drainermentioned withEthereum(70%)
  • Lucifer DaaSmentioned withwallet drainers(80%)
  • Lucifer Drainermentioned withInferno Drainer(80%)
  • Lucifer Drainermentioned withLucifer DaaS(80%)
  • Lucifer DaaSmentioned withLucifer Drainer(80%)
  • Lucifer DaaSmentioned withInferno Drainer(80%)
  • wallet drainersmentioned withInferno Drainer(80%)
  • Lucifer DaaSmentioned withEthereum(80%)
  • + 2 more
Have evidence about Lucifer DaaS?

Timeline(6 events)

2025

Earliest posts in Flare's analyzed dataset: Lucifer DaaS Telegram channel and underground forum activity begins the period analyzed by researchers. Approximate start date based on the January 2025 to early 2026 collection window.

BleepingComputer / Flare research

March 2025

Lucifer operators announce version 6.6.6, introducing ERC20 support, Permit2 abuse, off-chain signatures, Telegram notifications, wallet-security bypasses, and multichain functionality. Announcement reiterates the software is not for sale and confirms 20% operator commission.

BleepingComputer / Flare research

May 2025

Lucifer channel posts confirm the operation does not sell or lease the software, only splitting '20% per hit.' Platform continues recruiting affiliates through underground communities.

BleepingComputer / Flare research

August 2025

Telegram bans Lucifer DaaS bots. Operators instruct affiliates to create new bots and grant them administrative privileges, restoring operational capability without extended downtime.

BleepingComputer / Flare research

November 2025

Lucifer DaaS documentation domain hosted on Google Firebase is suspended, reportedly following security research disclosures. Operators migrate documentation to IPFS, citing decentralization as a resilience measure against future takedowns.

BleepingComputer / Flare research

21 May 2026

BleepingComputer publishes Flare threat intelligence analysis of Lucifer DaaS based on approximately 700 underground posts collected between January 2025 and early 2026, providing the first detailed public research into the platform's internal structure, business model, and technical evolution.

BleepingComputer
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 14 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/4/2026, 11:36:21 PM

last updated: 8/26/2026, 9:04:25 AM

7 views

avoid.net — verified advice for a post-truth world