Minecraft’s vibrant modding community has been hit by a dangerous cyber threat. Check Point Research (CPR) recently uncovered a three-stage malware campaign disguised as fake Minecraft mods, which were shared on GitHub to infiltrate players' systems.
A Multi-Stage Attack Targeting Gamers
Cybercriminals have exploited the popularity of Minecraft mods by embedding malware into seemingly legitimate files.The infection unfolds in three stages:
1. Java Downloader: A hidden script activates upon installation.
2. Second-Stage Stealer: This component extracts sensitive data like login credentials.
3. Final Advanced Spyware: This more sophisticated malware harvests cryptocurrency wallets, browser passwords, and system information.
1. Java Downloader: A hidden script activates upon installation.
2. Second-Stage Stealer: This component extracts sensitive data like login credentials.
3. Final Advanced Spyware: This more sophisticated malware harvests cryptocurrency wallets, browser passwords, and system information.