The gaming community faces a sophisticated new threat as cybercriminals exploit the massive popularity of Minecraft to distribute advanced malware through fake modifications.
With over 200 million monthly active players and more than 1 million users actively involved in modding, Minecraft has become an irresistible target for threat actors seeking to compromise systems on a global scale.
The malicious campaign leverages the trust players place in community-created content, transforming what appears to be harmless gameplay enhancements into dangerous system infiltration tools.
The attack campaign operates through the Stargazers Ghost Network, a sophisticated Distribution as a Service (DaaS) platform that has been actively targeting Minecraft users since March 2025.
This network creates convincing GitHub repositories that masquerade as legitimate mod distribution points, complete with multiple user accounts starring the repositories to enhance their credibility.
The malicious files impersonate popular “Scripts and Macro” tools such as Oringo and Taunahi, which are commonly used cheats in the Minecraft community.
Check Point researchers identified this multistage malware campaign while investigating suspicious GitHub repositories distributing undetected Java-based malware to Minecraft users.
The security experts discovered that the threat actor behind these campaigns is likely of Russian origin, evidenced by Russian language artifacts embedded within the malware code and the consistent use of UTC+3 timezone in commit timestamps.
The campaign’s sophistication lies in its three-stage attack chain, where each component serves a specific purpose in the overall data exfiltration strategy.
The malware’s impact extends far beyond simple gameplay disruption, as it systematically harvests sensitive information including Discord tokens, Telegram data, cryptocurrency wallet credentials, browser passwords, and even takes screenshots of infected systems.
What makes this threat particularly concerning is its ability to remain undetected by traditional antivirus solutions, with VirusTotal showing zero detections across 64 security vendors for the initial Java downloader component.
The campaign’s reach has been substantial, with monitoring data showing over 1,500 hits on command and control infrastructure, suggesting thousands of potential victims.
The malware’s most ingenious evasion technique lies in its fundamental design requirement for Minecraft runtime environments to execute properly.
Unlike traditional malware that can run on any system, these malicious JAR files are specifically crafted as Minecraft Forge mods, requiring the game’s modding framework to be installed and operational.
This dependency creates a natural sandbox evasion mechanism, as most automated analysis environments lack the complex Minecraft runtime requirements necessary for the malware to activate.
The first-stage loader implements comprehensive anti-analysis measures that immediately terminate execution if virtual machine environments are detected.
The malware systematically checks system properties including os.name, java.vm.name, and java.vm.vendor for keywords associated with VMware, VirtualBox, KVM, QEMU, and other virtualization platforms.
Additionally, it executes the tasklist utility to scan for running processes related to virtual machines, protocol analyzers like Wireshark, and network monitoring tools such as TCPView.
The infection mechanism begins when users manually download and install the malicious JAR files into their Minecraft mods directory. Upon game startup, the Minecraft Forge mod loader automatically loads all modifications, including the malicious component.
The malware then retrieves base64-encoded download URLs from Pastebin accounts, specifically from a user named “JoeBidenMama,” who has created multiple pastes containing command and control infrastructure addresses.
The modular design allows the first stage to download and execute a second-stage Java stealer, which subsequently deploys a final .NET-based credential harvester.
This sophisticated approach effectively bypasses traditional security measures by exploiting the legitimate Minecraft modding ecosystem, demonstrating how threat actors continue to evolve their tactics to target specific communities and applications that users trust implicitly.
Power up early threat detection, escalation, and mitigation with ANY.RUN’s Threat Intelligence Lookup. Get 50 trial searches.
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…