LofyGang is a Brazilian cybercrime group active since at least 2022 and known for software supply-chain abuse, information stealing, and broader credential and financial-data theft. The group first gained attention through large-scale publication of malicious npm packages, including typosquatted and impersonating packages, to compromise developers and downstream users. Those campaigns were used to steal payment card data, Discord-related accounts and tokens, gaming accounts, and streaming-service credentials, and were supported by sock-puppet maintainer identities and Brazilian Portuguese-language artifacts. Public reporting has also linked the group to underground trading of stolen credit cards and premium online-service accounts. LofyGang later expanded beyond JavaScript package abuse into malware delivery aimed directly at end users, including Minecraft players. In these campaigns, the group used social-engineering lures themed as Minecraft cheats or hacks to deliver LofyStealer, also known as GrabBot. That malware steals browser-stored passwords, cookies, session tokens, payment card data, and IBANs from multiple Chromium- and Gecko-based browsers, and uses in-memory browser injection and low-level syscall-based techniques to reduce visibility to security tools. Recent activity attributed to LofyGang shows a further evolution into a more capable modular malware ecosystem. Malicious npm packages linked to the group delivered a Node.js-based remote access trojan referred to as NYX together with a native Windows stealer. Reported capabilities include hidden relaunch, persistence, anti-analysis checks, browser credential theft, Discord token theft and validation, cryptocurrency wallet targeting, remote shell access, file upload, screen streaming, webcam and microphone surveillance, and exfiltration through multiple channels. The malware has also been observed targeting data associated with platforms such as Discord, Roblox, Steam, Minecraft, Telegram, Instagram, TikTok, and Spotify. Reporting has assessed parts of this activity as consistent with a malware-as-a-service model offering free and premium tiers. Known aliases and operator-linked names include ConsoleLofy and DyPolarLofy. Overall, LofyGang is best characterized as a financially motivated Brazilian cybercrime actor specializing in credential theft, payment-data theft, software supply-chain compromise, and increasingly feature-rich stealer and remote-access tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromising Minecraft players using the Slinky hack as a lure to deploy a JavaScript loader and inject the LofyStealer information-stealing malware; the campaign suggests a shift toward a malware-as-a-service model.
Brazilian-origin cybercrime group linked to the LofyStealer MaaS operation, distributing malware disguised as a Minecraft cheat ('Slinky') to steal browser cookies, passwords, payment card data, session tokens, and IBANs from victims.
Brazilian-origin cybercrime group targeting Minecraft players and gaming users, distributing stealer malware via fake Minecraft hacks and previously via npm typosquatting. The group steals browser data, Discord-related accounts and payment data, and appears to be shifting toward a malware-as-a-service model.
Software supply chain campaign using a malicious npm package (undicy-http) to compromise Node.js developers, deploy a Node.js RAT and a browser-stealing native payload, steal credentials/session data/cryptocurrency wallet data, and provide live remote access to victim systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.