logo

LofyStealer Uses Node.js Loader Against Minecraft Gamers

ID: 2b94f74e-6559-5410-a672-306368cbf7e7

STIX ID: report--2b94f74e-6559-5410-a672-306368cbf7e7

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Varshini

...
...

LofyGang is running an active LofyStealer/GrabBot campaign targeting Minecraft users by distributing a fake "Slinky" hack. Attackers use a massive Node.js-packaged loader (load.exe) that drops and injects a native C++ payload (chromelevator.exe) into memory, employs direct Windows syscalls to evade EDR, steals browser credentials/tokens/financial data, compresses and encrypts exfiltrated data, and operates a MaaS-style C2 panel ("LofyStealer V2.0") hosted in a Brazilian data center on port 8080; defenders should monitor unexpected Node.js and hidden PowerShell executions and network traffic to the described infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.