Stargazer Goblin is a malware distribution threat actor associated with the Stargazers Ghost Network, a large cluster of GitHub accounts and repositories used to spread malicious payloads through social-engineering lures. The actor is known for abusing code-hosting and social platforms to distribute malware disguised as gaming cheats, cracked software, cryptocurrency tools, exploits, and purported malware projects. Reported delivery chains have relied on GitHub repositories, URL shorteners, paste services, cloud-hosted archives, and multi-stage scripts or build-time backdoors that infect users who download, compile, or execute the lures. Activity linked or potentially linked to Stargazer Goblin has used password-protected archives and staged delivery chains that culminate in commodity malware including Lumma Stealer, AsyncRAT, and Remcos, as well as Electron-based loaders with host reconnaissance, Telegram-based operator notification, scheduled-task creation, registry modification, shadow-copy deletion, and Windows Defender tampering. Related campaigns have also used Visual Studio PreBuild abuse, obfuscated JavaScript, Python backdoors, and disguised screensaver files to trigger malware installation. Automation has been observed in repository maintenance, including workflows designed to make malicious repositories appear actively developed. The actor’s targeting pattern is opportunistic and heavily consumer-facing rather than focused on traditional enterprise intrusion. Victims include cheating gamers, users seeking pirated or cracked software, cryptocurrency-tool users, and inexperienced threat actors who compile or test public malware projects. Attribution of some 2024–2025 GitHub malware campaigns to Stargazer Goblin remains tentative because multiple operations share overlapping tradecraft consistent with a broader distribution-as-a-service ecosystem, and some observed delivery variations have not been conclusively tied to the actor. Known associated naming includes Stargazers Ghost Network.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distribution-as-a-Service operation using GitHub accounts and repositories themed around gaming cheats and malware to distribute infostealers, with overlap noted against the backdoored repository campaign discussed in the article.
Operates or is associated with the ‘Stargazers Ghost Network,’ a Distribution-as-a-Service operation using GitHub repositories themed as gaming cheats and malware to distribute infostealers. The article assesses the current ischhfd83-linked campaign may be a new customer of this operation, a closely linked variant, or a rival/standalone actor using similar methods.
Potentially linked by similarity to a LummaStealer distribution campaign that promotes cracked software via GitHub repositories, cracked forums, Facebook groups, Devpost, TikTok, and Chromium issues, using password-protected archives and MEGA-hosted payload delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.