Minecraft cheaters never win ... but they may get malware
ID: 887f0719-2844-5387-8388-713e3a4ea1c8
STIX ID: report--887f0719-2844-5387-8388-713e3a4ea1c8
Feed Name: The Register (Security)
Check Point Research uncovered a campaign in which trojanized Minecraft cheat mods hosted on ~500 GitHub repositories delivered a multi-stage malware chain (Java loader + .NET stealer) that evades sandboxes, steals game and platform tokens, browser credentials, VPN and crypto wallet data, captures screenshots, and exfiltrates victims' data to attackers via Discord webhooks; the activity, attributed to a Russian-speaking cluster called the Stargazers Ghost Network, has been active since March and may have impacted up to ~1,500 devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
