Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators LofyStealer: Malware targeting Minecraft players.

f9fe23f24d45eae418c60819c523a83ddba4ca50

TLP:CLEAR
Active

sha1

Description

A sophisticated two-stage infostealer named LofyStealer, also known as GrabBot/Slinky, targets Minecraft players through social engineering. The malware comprises a 53.5MB Node.js-based loader disguised within legitimate libraries and a 1.4MB native C++ payload that executes directly in memory. It extracts cookies, passwords, tokens, credit cards, and IBANs from eight different browsers including Chrome, Edge, Brave, Opera GX, and Firefox. The loader uses GitHub Actions for automated compilation while the payload employs direct syscalls to bypass EDR detection. Data is compressed via PowerShell, Base64-encoded, and exfiltrated to a Brazilian-hosted C2 server at 24.152.36.241. The operation is attributed with high confidence to the Brazilian cybercrime group LofyGang, operating a Malware-as-a-Service platform with Free and Premium tiers through a web panel branded as LofyStealer Advanced C2 Platform V2.0.

Sightings (0)

No sightings recorded yet

Details

Name / Label
LofyStealer: Malware targeting Minecraft players.
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 00:55
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of f9fe23f24d45eae418c60819c523a83ddba4ca50

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.