Also known as: GrabBot, TeviRAT, FIN11, Graceful Spider, TA505, FortiProxy web proxies, CVE-2022-40684
LofyGang operates a two‑tier Malvertising platform branded “LofyStealer Advanced C2 Platform V2.0” that offers free and premium services to its operators. Their flagship malware, LofyStealer (also known as GrabBot or Slinky), consists of a 53.5 MB Node.js loader bundled with a 1.4 MB native C++ payload. The payload is injected via syscall‑level process injection into popular web browsers (Chrome, Edge, Firefox, Brave, Opera GX) and extracts cookies, passwords, tokens, credit card numbers and IBANs from up to eight browser profiles. The loader compiles automatically through GitHub Actions, while the native component hides in memory and communicates over WebSocket to a Brazilian‑hosted C2 server (24.152.36.241). Data is compressed and Base64‑encoded with PowerShell before being exfiltrated through channels such as Discord bots, Telegram chats, gofile.io and catbox.moe. Beyond credential theft, LofyGang has been actively leveraging a supply chain vector in the npm ecosystem, employing starjacking and typosquatting to publish malicious packages that delete their own metadata after injection. The actor also exploits Fortinet's authentication bypass (CVE‑2022‑40684) to elevate privileges on devices with unused authentication methods. Their operations extend into social engineering of gaming communities via fake cheat icons for Minecraft, and they monetize stolen data by selling credit card information and gaming‑account credentials through Discord bots that require operator login credentials.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
LofyGang is a financially motivated, sophisticated threat actor that monetises through malware-as-a-service and supply‑chain attacks targeting the npm ecosystem. They deliver dual‑stage infostealers—Node.js loaders with native C++ payloads—that steal browser credentials, credit cards, and IBANs from users of Minecraft, gaming, finance, media and government sectors across North Korea, Brazil and the Netherlands. The group also exploits Fortinet's CVE‑2022‑40684 for privileged network access and uses Discord, Telegram and public cloud sites as exfiltration and command‑and‑control conduits.
Goals & Targeting
LofyGang's strategic objective is pure financial gain. By targeting popular online sectors—gaming, finance, media, government—they can acquire valuable monetary assets such as digital wallets, credit cards, and IBANs. Their supply‑chain approach allows widespread propagation with low effort, while the exploitation of Fortinet devices broadens their reach into corporate networks for lateral movement. The actor focuses on North Korea, Brazil, and the Netherlands, taking advantage of language support in Brazilian Portuguese (for C2 messages) and a large user base of gamers in the Americas. Victims are typically individual users with high-value credentials or developers who inadvertently ship malicious packages. Once compromised, LofyGang monetises through secondary services such as a “Lofy Boost” Discord bot that sells stolen cards and boosts channel activity for operators. Key capabilities include supply‐chain attacks via npm, native syscall injection, credential theft across multiple browsers, exfiltration over WebSocket/Discord, and fortinet device exploitation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LofyGang conducts high‑frequency campaigns that rely on a large number of npm developer accounts to upload almost 200 malicious packages. Their malware-as-a-service offering provides operators with free and premium tiers, allowing rapid scaling of attacks across the targeted sectors. Victims range from individual gamers and e‑commerce users to developers publishing software. The group routinely exploits Fortinet CVE‑2022‑40684 to expand its foothold within corporate networks. Notably, LofyGang resurfaced in early 2024 with new dual‑payload npm packages and a sophisticated browser credential stealer, demonstrating persistence and adaptability. The actor’s operational tempo includes automated compilation via GitHub Actions, immediate exfiltration through WebSocket or Discord, and cleanup mechanisms that delete package metadata after successful injection. Their use of cloud services for C2 adds resilience against takedown efforts. Financial impact is largely driven by the sale of stolen cards in a black‑market ecosystem, while secondary revenue streams emerge from boosting Discord channels using compromised credentials.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information is sourced from multiple independent reports, including academic blogs and malware analysis repositories, giving a reasonable level of confidence in the described capabilities and tactics. However, gaps remain around precise timelines, full attribution confirmation for all observed activities, and the exact financial impact on victims. Additional internal threat intelligence would be required to solidify claims of persistent infrastructure and long‑term operational tempo.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
52
Tools
0
Campaigns
45
IOCs
0
Observed Data
3
Tactics