Taunahi is the name used by a malware campaign that impersonated the popular Minecraft cheat tool of the same name and distributed trojanized mods through GitHub repositories. According to the provided reporting, the operation involved roughly 500 GitHub repositories, amplified by about 70 GitHub accounts that starred the repos around 700 times, and may have infected more than 1,500 devices. The campaign was active since March and was attributed to Russian-speaking developers linked to the Stargazers Ghost Network.
The malware used a multi-stage infection chain. The initial stage was a malicious Java JAR mod that executed at Minecraft launch and required Minecraft to be installed on the victim device. It performed anti-VM and anti-analysis checks and aborted in sandbox environments. If those checks passed, it deployed a second-stage Java stealer that targeted Minecraft tokens, Microsoft account information, Discord tokens, and Telegram data. That stage then downloaded and executed a final stealer written in .NET.
The final stealer harvested credentials from Firefox and Chromium-based browsers, targeted cryptocurrency wallets including Armory, AtomicWallet, BitcoinCore, Bytecoin, DashCore, Electrum, Ethereum, LitecoinCore, Monero, Exodus, Zcash, and Jaxx, and collected VPN-related data from ProtonVPN, OpenVPN, and NordVPN. It also stole data from applications including Steam, Discord, FileZilla, and Telegram, gathered host information, captured screenshots, and exfiltrated the stolen data via a Discord webhook to an attacker-controlled Discord server. Infection vector and lures described in the content were trojanized Minecraft cheat tools masquerading as Taunahi and similar mods such as Oringo, hosted on GitHub.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware purports to be popular cheat tools like Oringo and Taunahi, and once executed, kicks off a multi-stage attack...
The malware purports to be popular cheat tools like Oringo and Taunahi, and once executed, kicks off a multi-stage attack...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate Minecraft cheat tool name abused as a trojanized lure on GitHub; the trojanized build initiates a multi-stage stealer chain targeting gaming, browser, and crypto credentials.
A legitimate Minecraft cheat tool name abused as a trojanized lure on GitHub; the trojanized build initiates a multi-stage stealer chain targeting gaming, browser, and crypto credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.