Stargazers Ghost Network is a distribution-as-a-service malware operation centered on large numbers of coordinated GitHub accounts used to spread trojanized repositories, phishing lures, and malicious links. The activity has been publicly associated with Russian-speaking malware developers and has been active on GitHub since at least 2023. The operation is characterized by artificial reputation-building on GitHub through fake stars, forks, commits, subscriptions, and frequent updates intended to boost repository credibility and search visibility. The network has been used to distribute information stealers and remote-access malware through repositories themed around gaming cheats, cryptocurrency tools, attack utilities, and other high-interest software. Reported lures have included Minecraft mods and cheats, cryptocurrency trading or price-tracking tools, multiplier-prediction tools for betting-related applications, and repositories aimed at inexperienced cybercriminals seeking offensive tooling. The actor has also been linked to malicious npm-package campaigns that used fake GitHub repositories as part of the infection chain. Observed operations include large-scale GitHub abuse involving thousands of accounts and hundreds of malicious repositories. One documented campaign targeted Minecraft users with multi-stage Java- and .NET-based malware delivered through trojanized mods and cheats. That intrusion chain used anti-analysis and anti-virtualization checks, stole Minecraft and Microsoft account data, messaging-platform tokens, browser credentials, VPN data, cryptocurrency-wallet data, and other host information, and exfiltrated stolen data to attacker-controlled infrastructure. The broader ecosystem linked to this actor has also delivered infostealers and RATs such as AsyncRAT, Remcos RAT, and Lumma Stealer through backdoored repositories. Stargazers Ghost Network functions primarily as a malware distribution and amplification service rather than a traditional espionage intrusion set. Its tradecraft emphasizes social engineering, software supply-chain abuse, reputation manipulation on developer platforms, credential and token theft, payload staging, and defense evasion through anti-analysis measures. The actor has been tied to campaigns affecting gamers, developers, cryptocurrency users, and individuals seeking hacking or cheating tools.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stargazers Ghost Network is a DaaS cluster distributing malware via malicious npm packages and fake GitHub repositories, targeting developers and crypto enthusiasts.
A distribution network of GitHub accounts used to propagate malware and malicious links through phishing repositories, particularly against Minecraft users, while artificially boosting repository legitimacy and visibility.
A Russian-speaking malware distribution operation leveraging large numbers of GitHub accounts/repositories to host trojanized Minecraft cheat tools that install multi-stage stealers and exfiltrate stolen data via Discord webhooks/servers.
A Russian-speaking malware distribution operation leveraging large numbers of GitHub accounts/repositories to host trojanized Minecraft cheat tools that install multi-stage stealers and exfiltrate stolen data via Discord webhooks/servers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.