A multi-stage information-stealing malware campaign distributed through trojanized Minecraft cheat tools hosted on GitHub. The malware was observed masquerading as popular Minecraft cheats such as Oringo and Taunahi and was attributed by researchers to Russian-speaking malware developers associated with the Stargazers Ghost Network, a cluster of GitHub accounts used to distribute malware and malicious links. Check Point Research reported the operation involved roughly 500 GitHub repositories, amplified by about 70 accounts that starred the repositories around 700 times, and estimated that more than 1,500 devices may have been infected.
The infection chain begins with a malicious Java JAR mod that executes at Minecraft launch and requires Minecraft to be installed on the victim system. The first-stage loader performs anti-VM and anti-analysis checks and aborts in sandboxed environments. If those checks pass, it deploys a second-stage Java stealer that targets Minecraft tokens, Microsoft account information, Discord tokens, and Telegram data. That stage then downloads and executes a final stealer written in .NET.
The final stealer harvests credentials from Firefox and Chromium-based browsers, targets cryptocurrency wallets including Armory, AtomicWallet, BitcoinCore, Bytecoin, DashCore, Electrum, Ethereum, LitecoinCore, Monero, Exodus, Zcash, and Jaxx, and collects VPN-related data from ProtonVPN, OpenVPN, and NordVPN. It also steals data from applications including Steam, Discord, FileZilla, and Telegram, gathers host information, captures screenshots, and exfiltrates the stolen data via Discord webhooks to attacker-controlled Discord infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage stealer malware distributed via trojanized Minecraft cheat mods on GitHub. The malware targets gamers, stealing credentials, crypto wallets, browser data, and information from various applications. It uses anti-analysis techniques and exfiltrates stolen data to Discord webhooks.
A multi-stage stealer malware distributed via trojanized Minecraft cheat mods on GitHub. The malware targets gamers, stealing credentials, crypto wallets, browser data, and information from various applications. It uses anti-analysis techniques and exfiltrates stolen data to Discord webhooks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.