Fake Minecraft Mods

Overview

A counterfeit Minecraft optimisation mod has been discovered deploying Myth Stealer, a remote access trojan (RAT) designed to steal browser credentials, cookies, and sensitive data. The malicious mod appears legitimate because its advertised performance features actually work, leaving players unaware of the hidden threat.

Infection Chain

  • Decoy optimisation modules: The mod includes 12 working modules that adjust game performance settings.
  • Hidden loader: A thirteenth component gathers system info, retrieves the next stage, and runs it silently.
  • Administrator prompt: Displays a polished Windows‑style elevation request to gain higher privileges.
  • Multi‑stage payload: Uses a private Java runtime to execute even on systems without Java installed.

Stealth & Concealment

  • Reserved Windows names and encrypted text disguise the final payload.
  • Retry logic helps bypass security software interruptions.
  • Visual deception: Because optimisation features work, victims assume the mod is safe.

Capabilities of Myth Stealer

  • Credential theft: Targets Chromium‑based browsers and Firefox, stealing usernames, passwords, browsing history, and cookies.
  • Session hijacking: Stolen cookies allow attackers to reuse authenticated sessions.
  • System surveillance: Collects system details, clipboard data, chat content, screenshots, and webcam captures.
  • Remote control: Executes commands, manages processes, downloads/deletes files, and persists after reboot.
  • Disruption tools: Alters display settings, interferes with input devices, and blocks security tools.

📜 Indicators of Compromise (IoCs)

  • Files: MythStealer.jar, DiscordNitroGenerator.exe, client.jar.
  • Paths: %APPDATA%\Microsoft\Windows\javaw.exe, %TEMP%\webcam-<timestamp>.jpg.
  • Libraries: sqlitejdbc.dll, jnidispatch.dll.
  • Domains/URLs: ays[.]gamepazarin[.]com, multiple Discord webhook endpoints.
  • Registry changes: Disables Task Manager, alters cursor and colour settings.

Defensive Guidance

Players should:

  • Download mods only from trusted sources such as official project pages.
  • Verify developer identity and file integrity before installation.
  • Avoid unofficial links promoted via chats, videos, or file‑sharing sites.
  • Run full security scans if a suspicious mod was installed.
  • Change passwords from a clean device and sign out of accounts to invalidate sessions.
  • Check browser extensions and auto‑start programs for unfamiliar entries.

Expert in the Cloud Insight

This campaign demonstrates how gaming mods are weaponized as malware delivery vehicles. By embedding Myth Stealer inside a functioning optimisation mod, attackers exploit trust and curiosity in the gaming community. The lesson is clear: visual checks are not enough—security hygiene and trusted sources are essential to avoid hidden RAT infections.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.