Fake Minecraft mods distributed by the Stargazers Ghost Network to steal gamers’ data

June 23, 2025, 7:03 p.m.

Description

A multistage malware campaign targeting Minecraft users has been discovered, distributed through the Stargazers Ghost Network on GitHub. The malware impersonates popular Minecraft mods and cheats, using a Java-based downloader that evades detection. The infection chain includes multiple stages: a Java loader, a Java stealer, and a .NET stealer. The malware steals gaming credentials, browser data, cryptocurrency wallets, and other sensitive information. The campaign, likely of Russian origin, exploits the popularity of Minecraft mods to spread malware, highlighting the risks in gaming communities. Over 1500 potential infections have been recorded based on Pastebin hits.

Date

  • Created: June 18, 2025, 4:36 p.m.
  • Published: June 18, 2025, 4:36 p.m.
  • Modified: June 23, 2025, 7:03 p.m.

Indicators

  • f08086257c74b1de394bf150ad8aacc99ca5de57b4baa0974bc1b59bb973d355
  • c5936514e05e8b1327f0df393f4d311afd080e5467062151951e94bbd7519703
  • a427eeb8eed4585f2d51b62528b8b4920e72002ab62eb6fc19289ebc2fba5660
  • a1dc479898f0798e40f63b9c1a7ee4649357abdc757c53d4a81448a5eea9169f
  • 9ca41431df9445535b96a45529fce9f9a8b7f26c08ac8989a57787462da3342f
  • 9a678140ce41bdd8c02065908ee85935e8d01e2530069df42856a1d6c902bae1
  • 97df45c790994bbe7ac1a2cf83d42791c9d832fa21b99c867f5b329e0cc63f64
  • 886a694ee4be77242f501b20d37395e1a8a7a8f734f460cae269eb1309c5b196
  • 7aefd6442b09e37aa287400825f81b2ff896b9733328814fb7233978b104127f
  • 5d80105913e42efe58f4c325ac9b7c89857cc67e1dcab9d99f865a28ef084b37
  • 5590eaa4f11a6ed4351bc983e47d9dfd91245b89f3108bfd8b7f86e40d00b9fa
  • 51e423e8ab1eb49691d8500983f601989286f0552f444f342245197b74bc6fcf
  • 4c944b07832d5c29e7b499d9dd17a3d71f0fd918ab68694d110cbb8523b8af49
  • 4c8a6ad89c4218507e27ad6ef4ddadb6b507020c74691d02b986a252fb5dc612
  • 05b143fd7061bdd317bd42c373c5352bec351a44fa849ded58236013126d2963
  • 185.95.159.125
  • 147.45.79.104