StarDev is a self-branded operator of a financially motivated rootkit-as-a-service and cheat-as-a-service platform focused on the Chinese gaming cheat market. The operation distributes malware that masquerades as anti-cheat software while providing subscribers with kernel-level game cheating functionality and simultaneously exposing those users to remote access and information theft. The platform combines user-mode and kernel-mode components, including kernel drivers, a process injector, input emulation modules, and a .NET remote access trojan/infostealer. Observed capabilities include rootkit-style hiding of processes and modules, low-level keyboard and mouse input emulation, encrypted command-and-control over web protocols, keylogging, screen capture, clipboard theft, file exfiltration, and persistence through Windows registry mechanisms. The malware also uses kernel-to-user interprocess communication and process injection to support post-compromise control and stealth. Operational characteristics indicate a mature service model rather than a one-off toolset. StarDev uses subscription or card-based authentication and hardware-bound licensing tied to motherboard serial information, suggesting commercialized access control for customers. The malware employs commercial packers and protectors, blends into the local gaming ecosystem through anti-cheat-themed branding, and shows evidence of long-term development across multiple years. Available evidence supports assessment of StarDev as a Simplified Chinese-speaking actor operating from China and primarily targeting users in China involved in the gaming cheat ecosystem. The actor’s dominant motivation is financial gain rather than espionage or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.