Threats Tagged 'minecraft'
View all threats tagged with 'minecraft'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'minecraft'
Click on any threat for detailed analysis and mitigation recommendations
Children are targeted by a sprawling ecosystem of websites exploiting their interest in Roblox and Minecraft through offerwall reward schemes and phishing campaigns. These sites promise free in-game currency in exchange for completing tasks, collecting personal data, enrolling minors in paid subscriptions, and violating platform terms of service that can result in account bans. The infrastructure relies on cheap, disposable hosting with aggressive domain rotation. Using Internet-wide scan data from Censys, this analysis characterizes two categories: offerwall get-paid-to reward sites and credential harvesting generators. The exposed infrastructure handles children's data with minimal security, monetizing their attention at scale through affiliate commissions while presenting significant privacy and security risks. Join the discussion | AlienVault OTX General | 07/03/2026, 10:55:03 UTC Added: 07/03/2026, 11:06:38 UTC |
An exposed open directory on a Netherlands-hosted server revealed the complete operational toolkit of xlabs_v1, a Mirai-derived IoT botnet operated by an actor using the handle Tadashi. The operation provides DDoS-for-hire services specifically targeting game servers and Minecraft hosts through 21 distinct flood attack variants. The botnet exploits Android Debug Bridge (ADB) on TCP/5555 to compromise over 4 million potentially vulnerable IoT devices including Android TV boxes, smart TVs, and routers. The operation features bandwidth profiling to price-tier infected devices, ChaCha20 string encryption with cryptographic weaknesses, and competitor-eradication routines. Infrastructure analysis consolidated the entire operation within a single bulletproof /24 netblock in the Netherlands, with co-located cryptojacking infrastructure also identified. Join the discussion | AlienVault OTX General | 04/29/2026, 19:42:01 UTC Added: 04/30/2026, 07:51:22 UTC |
A sophisticated two-stage infostealer named LofyStealer, also known as GrabBot/Slinky, targets Minecraft players through social engineering. The malware comprises a 53.5MB Node.js-based loader disguised within legitimate libraries and a 1.4MB native C++ payload that executes directly in memory. It extracts cookies, passwords, tokens, credit cards, and IBANs from eight different browsers including Chrome, Edge, Brave, Opera GX, and Firefox. The loader uses GitHub Actions for automated compilation while the payload employs direct syscalls to bypass EDR detection. Data is compressed via PowerShell, Base64-encoded, and exfiltrated to a Brazilian-hosted C2 server at 24.152.36.241. The operation is attributed with high confidence to the Brazilian cybercrime group LofyGang, operating a Malware-as-a-Service platform with Free and Premium tiers through a web panel branded as LofyStealer Advanced C2 Platform V2.0. Join the discussion | AlienVault OTX General | 04/29/2026, 12:09:47 UTC Added: 04/30/2026, 08:06:23 UTC |
The article exposes a sophisticated scam targeting Minecraft players through fake 'grief-free' server communities. The SugarSMP website, promising a safe gaming experience, was found to distribute malware-infected mod packs. The malware, named Spark stealer, steals sensitive data including Discord tokens, browser credentials, and crypto wallet information. The threat actors employ social engineering tactics to maintain their fake community's reputation and remove warnings about their activities. Multiple similar websites were discovered, all hosting various types of malware. The scam's persistence mechanisms and social engineering techniques are detailed, along with remediation steps for affected users. Join the discussion | AlienVault OTX General | 03/18/2026, 10:42:02 UTC Added: 03/18/2026, 11:27:29 UTC |
A new Python-based Remote Access Trojan (RAT) named 'Nursultan Client' targets gamers by masquerading as a legitimate Minecraft client. It uses the Telegram Bot API for command and control, enabling attackers to capture screenshots, access webcams, steal Discord authentication tokens, open URLs, and perform system reconnaissance on Windows machines. Although it attempts persistence, its implementation has flaws. The malware's focus on Discord tokens and gaming users suggests a Malware-as-a-Service model, likely sold to other threat actors. No known exploits in the wild have been reported yet. The threat poses a medium severity risk but could escalate if customized versions improve persistence or evasion. European organizations with gaming communities or employees using Discord and Minecraft are at risk, especially in countries with high gaming engagement and Discord usage. Mitigation requires targeted detection of the fake client, monitoring Telegram API usage, and securing Discord tokens. Countries like Germany, France, the UK, and the Netherlands are most likely affected due to their large gaming populations and technology adoption. The threat is medium severity given its impact on confidentiality and moderate ease of exploitation without user interaction beyond initial infection. Join the discussion | AlienVault OTX General | 10/22/2025, 19:02:29 UTC Added: 10/22/2025, 19:52:59 UTC |
A multistage malware campaign targeting Minecraft users has been discovered, distributed through the Stargazers Ghost Network on GitHub. The malware impersonates popular Minecraft mods and cheats, using a Java-based downloader that evades detection. The infection chain includes multiple stages: a Java loader, a Java stealer, and a .NET stealer. The malware steals gaming credentials, browser data, cryptocurrency wallets, and other sensitive information. The campaign, likely of Russian origin, exploits the popularity of Minecraft mods to spread malware, highlighting the risks in gaming communities. Over 1500 potential infections have been recorded based on Pastebin hits. Join the discussion | AlienVault OTX General | 06/18/2025, 16:36:04 UTC Added: 06/18/2025, 19:46:49 UTC |
Showing 1 to 6 of 6 results