A new cybercrime operation is targeting Minecraft players through a complex malware distribution network called Stargazers Ghost Network, according to Check Point researchers. The campaign uses fake gaming modifications to steal sensitive user data.
## How the Attack Works
The malware disguises itself as popular Minecraft cheating tools called “Oringo” and “Taunahi.” Cybercriminals create fake GitHub repositories containing malicious Java files that appear to be legitimate game modifications. When players download and install these fake mods, a three-stage attack begins:
1. **First Stage**: A Java loader file (like “Oringo-1.8.9.jar”) activates when Minecraft starts
2. **Second Stage**: Downloads another malicious component that steals Discord, Minecraft, and Telegram data
3. **Final Stage**: Deploys a .NET information stealer that harvests browser passwords, cryptocurrency wallet data, and system information
## Scale of the Operation
Check Point discovered approximately 500 malicious GitHub repositories supported by around 70 fake accounts generating 700 fraudulent endorsements. The campaign, first detected in March 2025, has potentially infected over 1,500 devices.
The attackers use sophisticated evasion techniques, including anti-detection measures and Base64-encoded command servers hosted on Pastebin. Evidence suggests the operation is run by Russian-speaking cybercriminals.
## Additional Threat: KimJongRAT Variants
Separately, Palo Alto Networks identified two new versions of the KimJongRAT information stealer, linked to North Korean threat actors. These variants use both executable files and PowerShell scripts to steal credentials, browser data, and cryptocurrency information.
The malware spreads through malicious Windows shortcut files that download additional components from compromised content delivery networks.
## Protection Recommendations
Security experts emphasize the importance of downloading gaming modifications only from official sources and verified developers. The campaign demonstrates how popular gaming communities serve as effective targets for malware distribution, making user caution essential when installing third-party content.
