Gamers Beware! Fake Minecraft Mods Let Attackers Hijack Your System

A sophisticated cyber threat campaign has been uncovered, specifically targeting Minecraft enthusiasts through malicious mods shared on GitHub.

The campaign, dubbed Stargazers Ghost Network, employs a “Distribution as a Service” (DaaS) operation to propagate a multistage malware infection, exploiting the immense popularity of user-created Minecraft modifications.

Technical Breakdown of the Attack Chain

The attack begins with cybercriminals uploading malicious Java Archive (JAR) files disguised as popular Minecraft cheat tools and macro scripts, such as Oringo and Taunahi.

Minecraft Mods
Infection Chain

These files, masquerading as legitimate gameplay enhancers, are hosted within repositories bearing high star counts to maximize credibility and lure unsuspecting users.

Both first and second-stage payloads are written in Java and require a Minecraft runtime environment to activate, allowing the malware to evade traditional sandbox and antivirus detection methods.

Upon installation, the mod leverages a series of anti-analysis mechanisms. It checks for telltale signs of virtual machines or security analysis environments by querying system properties (os.name, java.vm.name, java.vm.vendor) for known keywords such as “vmware,” “virtualbox,” or “qemu.”

Minecraft Mods
Installing required mod loader

If any are found, the mod self-terminates. The malicious loader further scrutinizes running processes to identify debuggers, protocol analyzers, or network sniffers like Wireshark and TCPView, ceasing execution if detected.

Once these checks are passed, the first-stage JAR downloads additional code from a Pastebin URL, executing it in-memory to limit forensic visibility.

The Java-based stealer component then activates, collecting sensitive information such as Minecraft credentials (including tokens from Feather, Essential, and Lunar launchers), Discord and Telegram tokens, and user IDs.

Exfiltrated data is transmitted to attacker-controlled endpoints, including URLs and Discord webhooks hidden behind Pastebin links.

A key feature of this campaign is the deployment of a third-stage payload a .NET-based stealer, which broadens the attack surface dramatically.

This final component targets browser credentials (Chrome, Edge, Firefox), desktop files, cryptocurrency wallets (Bitcoin, Ethereum, Monero, and more), VPN profiles (ProtonVPN, NordVPN, OpenVPN), Steam accounts, FileZilla, and even clipboard contents and screenshots.

All data is zipped and exfiltrated, often accompanied by attacker comments in Russian, corroborating Check Point’s assessment of a Russian-speaking threat actor.

According to the Report, Check Point tracked the Stargazers Ghost Network since March 2025 and observed that all GitHub commits occurred within the UTC+3 time zone.

The Pastebin account used as a staging server shows over 1,500 hits, suggesting a sizable victim pool.

The malicious Java loaders remain undetected by all known antivirus engines on VirusTotal, underscoring the increasing sophistication of threat actors exploiting niche, gaming-related attack vectors.

Implications for the Minecraft Community

With over 200 million monthly active Minecraft players and a thriving modding ecosystem, this campaign signals a clear and present danger to the gaming community.

The technical complexity and multistage architecture of the Stargazers Ghost Network campaign demonstrate how modding intended to enhance user experience can be subverted into a high-impact attack surface.

Security researchers emphasize vigilance when downloading mods from unofficial or unverified sources.

As threat actors target gaming communities with increasingly complex malware, utilizing robust endpoint security and anti-malware solutions such as Check Point Harmony Endpoint becomes critical for safe gameplay.

Indicators of Compromise (IOC)

DescriptionValue/Hash/Link
Stage 1 JAR SHA25605b143fd7061bdd317bd42c373c5352bec351a44fa849ded58236013126d2963
Stage 1 JAR SHA2569ca41431df9445535b96a45529fce9f9a8b7f26c08ac8989a57787462da3342f
Stage 1 JAR SHA256c5936514e05e8b1327f0df393f4d311afd080e5467062151951e94bbd7519703
Stage 1 JAR SHA2569a678140ce41bdd8c02065908ee85935e8d01e2530069df42856a1d6c902bae1
Stage 2 JAR SHA2564c8a6ad89c4218507e27ad6ef4ddadb6b507020c74691d02b986a252fb5dc612
Stage 2 JAR SHA25651e423e8ab1eb49691d8500983f601989286f0552f444f342245197b74bc6fcf
Stage 2 JAR SHA2565d80105913e42efe58f4c325ac9b7c89857cc67e1dcab9d99f865a28ef084b37
Stage 2 JAR SHA25697df45c790994bbe7ac1a2cf83d42791c9d832fa21b99c867f5b329e0cc63f64
Stage 2 Download URLhxxp://147[.]45[.]79[.]104/download
Stage 2 Download URLhxxp://негры[.]рф/MixinLoader-v2.4[.]jar
Stage 2 Upload URLhxxp://185[.]95[.]159[.]125/upload
Hosting Domainнегры[.]рф
Stage 3 Stealer SHA2567aefd6442b09e37aa287400825f81b2ff896b9733328814fb7233978b104127f
Stage 3 Stealer SHA256886a694ee4be77242f501b20d37395e1a8a7a8f734f460cae269eb1309c5b196
GitHub Repositoryhxxps://github.com/A1phaD3v/Oringo-Client
GitHub Repositoryhxxps://github.com/AlphaPigeonDev/Polar-Client
GitHub Repositoryhxxps://github.com/P1geonD3v/Taunahi-V3

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories