Oringo is the lure name used in a malware campaign that distributed trojanized Minecraft cheat tools through GitHub repositories. The malicious packages impersonated popular Minecraft cheats including Oringo and Taunahi and were used to infect players with a multi-stage information-stealing malware chain. According to the provided reporting, the operation involved roughly 500 GitHub repositories, was amplified by about 70 GitHub accounts that starred the repositories around 700 times, and may have infected more than 1,500 devices. The campaign was reported as active since March and attributed to Russian-speaking developers linked to the Stargazers Ghost Network.
The infection chain begins with a malicious Java JAR mod that executes when Minecraft launches and requires Minecraft to be installed on the victim system. The loader performs anti-VM and anti-analysis checks and aborts in sandboxed environments. If those checks pass, it deploys a second-stage stealer that targets Minecraft tokens, Microsoft account information, Discord tokens, and Telegram data. That stage then downloads and executes a final stealer written in .NET.
The final stealer harvests credentials from Firefox and Chromium-based browsers, targets cryptocurrency wallets including Armory, AtomicWallet, BitcoinCore, Bytecoin, DashCore, Electrum, Ethereum, LitecoinCore, Monero, Exodus, Zcash, and Jaxx, and collects VPN-related data from ProtonVPN, OpenVPN, and NordVPN. It also steals data from applications including Steam, Discord, FileZilla, and Telegram, gathers host information, captures screenshots, and exfiltrates the stolen data via Discord webhooks to an attacker-controlled Discord server. High-confidence indicators and traits mentioned in the content include the use of trojanized GitHub-hosted Minecraft cheat repositories, malicious Java JAR mods, anti-VM/anti-analysis behavior, Discord webhook-based exfiltration, and targeting of Minecraft, browser, wallet, VPN, and messaging application data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware purports to be popular cheat tools like Oringo and Taunahi, and once executed, kicks off a multi-stage attack...
The malware purports to be popular cheat tools like Oringo and Taunahi, and once executed, kicks off a multi-stage attack...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate Minecraft cheat tool name abused as a trojanized lure on GitHub; the trojanized build acts as a loader that leads to multi-stage credential/crypto-wallet stealing.
A legitimate Minecraft cheat tool name abused as a trojanized lure on GitHub; the trojanized build acts as a loader that leads to multi-stage credential/crypto-wallet stealing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.