Fake Minecraft Mod Distributes Myth Stealer Malware, Targeting Player Data
A counterfeit Minecraft optimization mod has been discovered distributing Myth Stealer, a malware strain designed to harvest browser passwords, cookies, and sensitive system data. The malicious file mimics legitimate performance-enhancing tools, with 12 functional modules that deliver the promised optimizations masking its hidden threat.
The campaign exploits players seeking unofficial add-ons for better gameplay. Once installed, the fake mod initiates a multi-stage infection chain, culminating in a remote-access tool that grants attackers broad control over infected Windows devices. Security researcher devmihaylov uncovered the malware after analyzing samples from a buyer of the commodity stealer, noting that initial VirusTotal scans returned zero detections, highlighting how low-distribution threats evade reputation-based security checks.
The mod impersonates the legitimate Lithium optimization project, embedding a 13th hidden component that delays execution before gathering system details and fetching the next payload. To avoid suspicion, the malware includes a polished administrator-rights prompt, mimicking a standard Windows request. If granted, it escalates privileges, employs retry logic to bypass security interruptions, and deploys a private Java runtime to execute even on systems without Java installed.
The final payload, Myth Stealer 3.2-FIX, is heavily obfuscated, using reserved Windows-style filenames, encrypted strings, and anti-analysis techniques to hinder detection. Its capabilities include:
- Data theft: Extracts saved credentials, browsing history, and session cookies from Chromium-based browsers and Firefox, enabling attackers to hijack authenticated sessions.
- System surveillance: Captures screenshots, webcam footage, clipboard content, and chat logs.
- Remote control: Executes commands, downloads/deletes files, manages processes, and persists after reboots.
- Disruptive functions: Alters display settings, interferes with input devices, displays misleading messages, and restricts access to security tools.
Stolen data is exfiltrated via Discord webhooks, a tactic observed in other malware campaigns. While the analyzed command-and-control infrastructure was inactive at the time of reporting, infected systems remain at risk.
The attack mirrors previous incidents involving trojanized Minecraft mods, where social engineering such as fake download links in chats or videos drives distribution. Indicators of compromise (IoCs) include specific SHA-256 hashes, file paths, domains, and IP addresses associated with the malware’s infrastructure.
Source: https://cybersecuritynews.com/fake-minecraft-mod/
Minecraft TPRM report: https://www.rankiteo.com/company/mojangstudios
"id": "moj1788784237",
"linkid": "mojangstudios",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Minecraft players using '
'unofficial mods',
'industry': 'Gaming',
'type': 'Gaming Community'}],
'attack_vector': 'Trojanized Mod',
'customer_advisories': 'Avoid unofficial Minecraft mods, especially those '
'promising performance optimizations.',
'data_breach': {'data_exfiltration': 'Yes, via Discord webhooks',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Browser credentials',
'Session cookies',
'System details',
'Screenshots',
'Webcam footage',
'Clipboard content',
'Chat logs']},
'description': 'A counterfeit Minecraft optimization mod has been discovered '
'distributing Myth Stealer, a malware strain designed to '
'harvest browser passwords, cookies, and sensitive system '
'data. The malicious file mimics legitimate '
'performance-enhancing tools, with 12 functional modules that '
'deliver the promised optimizations masking its hidden threat. '
'The campaign exploits players seeking unofficial add-ons for '
'better gameplay. Once installed, the fake mod initiates a '
'multi-stage infection chain, culminating in a remote-access '
'tool that grants attackers broad control over infected '
'Windows devices.',
'impact': {'data_compromised': 'Browser passwords, cookies, session data, '
'system details, screenshots, webcam footage, '
'clipboard content, chat logs',
'identity_theft_risk': 'High',
'operational_impact': 'Remote control of infected systems, '
'persistence after reboots, restricted '
'access to security tools',
'systems_affected': 'Windows devices'},
'initial_access_broker': {'backdoors_established': 'Remote-access tool',
'entry_point': 'Trojanized Minecraft mod'},
'investigation_status': 'Analyzed',
'lessons_learned': 'Low-distribution threats can evade reputation-based '
'security checks. Malware can use polished social '
'engineering tactics to gain privileges and persist on '
'systems.',
'motivation': 'Data Theft, Remote Control',
'post_incident_analysis': {'corrective_actions': 'Enhanced detection for '
'obfuscated malware, user '
'education on risks of '
'unofficial mods, monitoring '
'for Discord webhook '
'exfiltration',
'root_causes': 'Social engineering (fake download '
'links), evasion of '
'reputation-based security checks, '
'delayed execution of malicious '
'payloads'},
'recommendations': 'Avoid unofficial mods, use reputable sources for '
'downloads, monitor for unusual system behavior, and '
'employ multi-layered security measures.',
'references': [{'source': 'Security researcher devmihaylov'}],
'response': {'third_party_assistance': 'Security researcher devmihaylov'},
'title': 'Fake Minecraft Mod Distributes Myth Stealer Malware, Targeting '
'Player Data',
'type': 'Malware Distribution'}