BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malware Campaign Targets Minecraft Users With Fake Mod Downloads

  • New Malware campaign targets Minecraft players through fake mods distributed on GitHub.
  • Attackers use the Stargazers Ghost Network to spread Java-based malware that delivers an information-stealing tool.
  • The malware collects data such as game tokens, credentials, and files from browsers and other applications.
  • Researchers from Check Point found the attacks began in March 2025 and involve more than 1,500 compromised devices.
  • Separately, new versions of the KimJongRAT stealer linked to North Korean actors have also been observed using innovative delivery methods.

A new wave of cyberattacks is targeting Minecraft players by tricking them into downloading malicious game modifications distributed through GitHub. The campaign began in March 2025 and specifically targets users who seek out cracked software or cheats for the popular game, according to Check Point researchers.

- Advertisement -

The attackers use a service known as Stargazers Ghost Network, which leverages thousands of GitHub accounts to host fake repositories disguised as legitimate mods or Hacking tools. Victims download Java Archive (JAR) files, which only execute if the Minecraft runtime is present on the device. Once run, these files deploy a multi-stage attack that ends with the installation of a .NET-based information stealer capable of extracting sensitive user data.

"The campaigns resulted in a multi-stage attack chain targeting Minecraft users specifically," wrote Check Point researchers Jaromír Hořejší and Antonis Terefos in their report. The initial malware stages focus on evading antiviruses by using anti-virtual machine and anti-analysis code. After activation, the loader fetches a second-stage stealer from an IP address posted on Pastebin, which then downloads the .NET stealer.

The final payload gathers a broad range of information. This includes Discord and Minecraft tokens, data from Telegram, browser credentials, cryptocurrency wallets, Steam accounts, FileZilla transfers, and clipboard content. Collected data is then sent to the attacker via a Discord webhook. The signs point to a Russian-speaking group, based on language evidence and time zone data.

Researchers estimate the malware has infected over 1,500 devices. "This case highlights how popular gaming communities can be exploited as effective vectors for malware distribution," the report states, urging caution when downloading third-party add-ons.

- Advertisement -

In a related development, Palo Alto Networks Unit 42 has identified two new variants of the KimJongRAT malware, likely tied to a North Korean group also implicated in the BabyShark campaign. One variant uses a Portable Executable (PE) file, while the other relies on PowerShell. Both are delivered by getting users to activate Windows shortcut files that download packers from attacker-controlled servers. These new KimJongRAT variants are capable of capturing files, browser data, and credentials.

Unit 42 explained that the KimJongRAT stealer’s evolution, such as using legitimate content delivery networks for payload drop, reflects ongoing threats and increasing technical sophistication. The PE variant also has features to steal file transfer and email client information.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Panel: Bitcoin Could Crash to $30K or Soar to $130K

Patrick Bet-David suggested Bitcoin's price could swing dramatically, falling to $30,000 or surging to...

Bitcoin Plunges Amid Selloff; All Eyes on Saylor’s Next Move

Bitcoin plunged over 50% from its October 2025 peak of $126,000, wiping $2 trillion...

Broadcom Earnings Spark Semiconductor Stock Plunge

Broadcom's Q2 earnings, which beat expectations, triggered a 12.6% crash in its own stock...

Microsoft Found Vulnerability in Anthropic’s Claude Code

Microsoft researchers discovered a Claude Code vulnerability where attack instructions in GitHub comments could...

OpenAI Launches ChatGPT ‘Lockdown Mode’ to Block Data Leaks

OpenAI has launched a new optional Lockdown Mode for ChatGPT personal accounts to mitigate...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading