A sophisticated cyber threat campaign has been uncovered, specifically targeting Minecraft enthusiasts through malicious mods shared on GitHub.
The campaign, dubbed Stargazers Ghost Network, employs a “Distribution as a Service” (DaaS) operation to propagate a multistage malware infection, exploiting the immense popularity of user-created Minecraft modifications.
Technical Breakdown of the Attack Chain
The attack begins with cybercriminals uploading malicious Java Archive (JAR) files disguised as popular Minecraft cheat tools and macro scripts, such as Oringo and Taunahi.

These files, masquerading as legitimate gameplay enhancers, are hosted within repositories bearing high star counts to maximize credibility and lure unsuspecting users.
Both first and second-stage payloads are written in Java and require a Minecraft runtime environment to activate, allowing the malware to evade traditional sandbox and antivirus detection methods.
Upon installation, the mod leverages a series of anti-analysis mechanisms. It checks for telltale signs of virtual machines or security analysis environments by querying system properties (os.name, java.vm.name, java.vm.vendor) for known keywords such as “vmware,” “virtualbox,” or “qemu.”

If any are found, the mod self-terminates. The malicious loader further scrutinizes running processes to identify debuggers, protocol analyzers, or network sniffers like Wireshark and TCPView, ceasing execution if detected.
Once these checks are passed, the first-stage JAR downloads additional code from a Pastebin URL, executing it in-memory to limit forensic visibility.
The Java-based stealer component then activates, collecting sensitive information such as Minecraft credentials (including tokens from Feather, Essential, and Lunar launchers), Discord and Telegram tokens, and user IDs.
Exfiltrated data is transmitted to attacker-controlled endpoints, including URLs and Discord webhooks hidden behind Pastebin links.
A key feature of this campaign is the deployment of a third-stage payload a .NET-based stealer, which broadens the attack surface dramatically.
This final component targets browser credentials (Chrome, Edge, Firefox), desktop files, cryptocurrency wallets (Bitcoin, Ethereum, Monero, and more), VPN profiles (ProtonVPN, NordVPN, OpenVPN), Steam accounts, FileZilla, and even clipboard contents and screenshots.
All data is zipped and exfiltrated, often accompanied by attacker comments in Russian, corroborating Check Point’s assessment of a Russian-speaking threat actor.
According to the Report, Check Point tracked the Stargazers Ghost Network since March 2025 and observed that all GitHub commits occurred within the UTC+3 time zone.
The Pastebin account used as a staging server shows over 1,500 hits, suggesting a sizable victim pool.
The malicious Java loaders remain undetected by all known antivirus engines on VirusTotal, underscoring the increasing sophistication of threat actors exploiting niche, gaming-related attack vectors.
Implications for the Minecraft Community
With over 200 million monthly active Minecraft players and a thriving modding ecosystem, this campaign signals a clear and present danger to the gaming community.
The technical complexity and multistage architecture of the Stargazers Ghost Network campaign demonstrate how modding intended to enhance user experience can be subverted into a high-impact attack surface.
Security researchers emphasize vigilance when downloading mods from unofficial or unverified sources.
As threat actors target gaming communities with increasingly complex malware, utilizing robust endpoint security and anti-malware solutions such as Check Point Harmony Endpoint becomes critical for safe gameplay.
Indicators of Compromise (IOC)
| Description | Value/Hash/Link |
|---|---|
| Stage 1 JAR SHA256 | 05b143fd7061bdd317bd42c373c5352bec351a44fa849ded58236013126d2963 |
| Stage 1 JAR SHA256 | 9ca41431df9445535b96a45529fce9f9a8b7f26c08ac8989a57787462da3342f |
| Stage 1 JAR SHA256 | c5936514e05e8b1327f0df393f4d311afd080e5467062151951e94bbd7519703 |
| Stage 1 JAR SHA256 | 9a678140ce41bdd8c02065908ee85935e8d01e2530069df42856a1d6c902bae1 |
| Stage 2 JAR SHA256 | 4c8a6ad89c4218507e27ad6ef4ddadb6b507020c74691d02b986a252fb5dc612 |
| Stage 2 JAR SHA256 | 51e423e8ab1eb49691d8500983f601989286f0552f444f342245197b74bc6fcf |
| Stage 2 JAR SHA256 | 5d80105913e42efe58f4c325ac9b7c89857cc67e1dcab9d99f865a28ef084b37 |
| Stage 2 JAR SHA256 | 97df45c790994bbe7ac1a2cf83d42791c9d832fa21b99c867f5b329e0cc63f64 |
| Stage 2 Download URL | hxxp://147[.]45[.]79[.]104/download |
| Stage 2 Download URL | hxxp://негры[.]рф/MixinLoader-v2.4[.]jar |
| Stage 2 Upload URL | hxxp://185[.]95[.]159[.]125/upload |
| Hosting Domain | негры[.]рф |
| Stage 3 Stealer SHA256 | 7aefd6442b09e37aa287400825f81b2ff896b9733328814fb7233978b104127f |
| Stage 3 Stealer SHA256 | 886a694ee4be77242f501b20d37395e1a8a7a8f734f460cae269eb1309c5b196 |
| GitHub Repository | hxxps://github.com/A1phaD3v/Oringo-Client |
| GitHub Repository | hxxps://github.com/AlphaPigeonDev/Polar-Client |
| GitHub Repository | hxxps://github.com/P1geonD3v/Taunahi-V3 |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.