Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection
ID: 7f9511cc-831d-509d-801c-34608298beb4
STIX ID: report--7f9511cc-831d-509d-801c-34608298beb4
Feed Name: cybersecurityNews.com
LofyStealer is an actively deployed infostealer masquerading as a Minecraft cheat named “Slinky”; it uses a Node.js loader and a native C++ payload that is mapped into live browser processes via low-level syscalls to evade EDR, targeting eight major browsers to harvest cookies, saved credentials, payment cards and IBANs, and exfiltrates data to a Brazilian-hosted C2 (24.152.36.241). The operation is run as a Malware-as-a-Service with free and premium tiers, and the report includes attribution to the LofyGang crime group, technical TTPs, IOCs, and mitigation recommendations such as blocking the C2 IP and monitoring hidden PowerShell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
