Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LofyGang

Also known as: GrabBot, TeviRAT, FIN11, Graceful Spider, TA505, FortiProxy web proxies, CVE-2022-40684

Description

LofyGang operates a two‑tier Malvertising platform branded “LofyStealer Advanced C2 Platform V2.0” that offers free and premium services to its operators. Their flagship malware, LofyStealer (also known as GrabBot or Slinky), consists of a 53.5 MB Node.js loader bundled with a 1.4 MB native C++ payload. The payload is injected via syscall‑level process injection into popular web browsers (Chrome, Edge, Firefox, Brave, Opera GX) and extracts cookies, passwords, tokens, credit card numbers and IBANs from up to eight browser profiles. The loader compiles automatically through GitHub Actions, while the native component hides in memory and communicates over WebSocket to a Brazilian‑hosted C2 server (24.152.36.241). Data is compressed and Base64‑encoded with PowerShell before being exfiltrated through channels such as Discord bots, Telegram chats, gofile.io and catbox.moe. Beyond credential theft, LofyGang has been actively leveraging a supply chain vector in the npm ecosystem, employing starjacking and typosquatting to publish malicious packages that delete their own metadata after injection. The actor also exploits Fortinet's authentication bypass (CVE‑2022‑40684) to elevate privileges on devices with unused authentication methods. Their operations extend into social engineering of gaming communities via fake cheat icons for Minecraft, and they monetize stolen data by selling credit card information and gaming‑account credentials through Discord bots that require operator login credentials.

Goals & Targeting

Targeted Sectors

Gaming
Financial services
Media
Government

Targeted Countries / Regions

KP
BR
NL

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

LofyGang is a financially motivated, sophisticated threat actor that monetises through malware-as-a-service and supply‑chain attacks targeting the npm ecosystem. They deliver dual‑stage infostealers—Node.js loaders with native C++ payloads—that steal browser credentials, credit cards, and IBANs from users of Minecraft, gaming, finance, media and government sectors across North Korea, Brazil and the Netherlands. The group also exploits Fortinet's CVE‑2022‑40684 for privileged network access and uses Discord, Telegram and public cloud sites as exfiltration and command‑and‑control conduits.

Goals & Targeting

LofyGang's strategic objective is pure financial gain. By targeting popular online sectors—gaming, finance, media, government—they can acquire valuable monetary assets such as digital wallets, credit cards, and IBANs. Their supply‑chain approach allows widespread propagation with low effort, while the exploitation of Fortinet devices broadens their reach into corporate networks for lateral movement. The actor focuses on North Korea, Brazil, and the Netherlands, taking advantage of language support in Brazilian Portuguese (for C2 messages) and a large user base of gamers in the Americas. Victims are typically individual users with high-value credentials or developers who inadvertently ship malicious packages. Once compromised, LofyGang monetises through secondary services such as a “Lofy Boost” Discord bot that sells stolen cards and boosts channel activity for operators. Key capabilities include supply‐chain attacks via npm, native syscall injection, credential theft across multiple browsers, exfiltration over WebSocket/Discord, and fortinet device exploitation.

Enhanced Description

Key Capabilities

  • Starjacking in the npm ecosystem
  • Typosquatting of npm package names
  • Distributing malicious packages that delete release artifacts and metadata
  • Credential theft via browser injection (cookies/passwords/IBANs) from Chrome, Edge, Firefox, Brave and Opera
  • Stealth process injection into browser processes using syscall‑level techniques
  • Exploiting Fortinet CVE‑2022-40684 to gain privileged access on network devices
  • Tracking Linux devices via new TCP source port generation mechanism
  • Employing hardcoded strings and Discord webhook injection for persistence
  • Social engineering through fake game cheat icons (e.g. Minecraft icon in Slinky)
  • Deploying stolen credit cards via a Discord bot requiring operator credentials
  • Leveraging native binaries with syscall‑level process injection
  • Exfiltrating data through Discord, Telegram, gofile.io, and catbox.moe
  • Capturing screenshots to a WebSocket RAT named ScreenLiveClient
  • Using multiple cloud services (Discord, Repl.it, glitch, GitHub, Heroku) as command‑and‑control infrastructure
  • Implementing persistent hidden malware within infected operators

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Command and Control
Exfiltration

ATT&CK Techniques

T1195
T1195.002
T1055
T1041

Software / Tooling

LofyStealer
Slinky
BeaverTail
InvisibleFerret
LofyBoost
ScreenLiveClient
chromelevator.exe
undicy-http

Campaigns & Victims

LofyGang conducts high‑frequency campaigns that rely on a large number of npm developer accounts to upload almost 200 malicious packages. Their malware-as-a-service offering provides operators with free and premium tiers, allowing rapid scaling of attacks across the targeted sectors. Victims range from individual gamers and e‑commerce users to developers publishing software. The group routinely exploits Fortinet CVE‑2022‑40684 to expand its foothold within corporate networks. Notably, LofyGang resurfaced in early 2024 with new dual‑payload npm packages and a sophisticated browser credential stealer, demonstrating persistence and adaptability. The actor’s operational tempo includes automated compilation via GitHub Actions, immediate exfiltration through WebSocket or Discord, and cleanup mechanisms that delete package metadata after successful injection. Their use of cloud services for C2 adds resilience against takedown efforts. Financial impact is largely driven by the sale of stolen cards in a black‑market ecosystem, while secondary revenue streams emerge from boosting Discord channels using compromised credentials.

IOC Patterns

  • hardcoded strings such as 'ConsoleLofy' or '=== Lofygang Started ==='
  • author field containing keyword 'Lofy'
  • webhook usernames set to 'Lofygang'
  • folder name 'lofygang-local'
  • Portuguese log messages like 'Conectado ao servidor'
  • Discord injection techniques
  • command line patterns such as 'node client.js --bg', '_nyx_launch.vbs', 'svchost.vbs'
  • malicious npm package uploads across multiple developer accounts
  • typosquatting and starjacking in npm packages
  • use of Discord bots for command‑and‑control
  • cloud services (Repl.it, glitch, Heroku) used as C2

Recommended Actions

  • Uninstall malicious npm packages such as undicy-http and any packages authored by suspicious developer accounts.
  • Terminate suspicious processes including Node.js running 'client.js --bg', '_nyx_launch.vbs', and 'svchost.vbs' via task manager or scripts.
  • Remove persistence artifacts (e.g., registry keys, scheduled tasks, hidden directories like 'lofygang-local').
  • Patch Fortinet devices against CVE‑2022-40684 and disable unused authentication methods on all network appliances.
  • Monitor npm repositories for unauthorized deletions of package metadata or sudden appearance of duplicate descriptions (starjacking).
  • Educate users to verify authenticity of game cheat tools, check official icons, and update passwords after potential compromise.
  • Implement continuous scanning of npm packages during build pipelines (package lock file integrity checks) using tools like Snyk or JFrog Xray.
  • Block or heavily filter traffic to known exfiltration domains such as gofile.io and catbox.moe via firewalls and endpoint detection.
  • Deploy WebSocket activity monitoring to detect unauthorized ScreenLiveClient connections.
  • Implement strict outbound controls for Discord, Telegram, and other public cloud services unless required.

Suggested Tags

supply-chain-compromise
malicious-npm-package
credential-theft
browser-injection
process-injection
fortinet-exploitation
CVE-2022-40684
social-engineering
threat-actor-lofygang
discord-bot
browser-stealer
websocket-C2
exfiltration-web-services

Confidence Assessment

The information is sourced from multiple independent reports, including academic blogs and malware analysis repositories, giving a reasonable level of confidence in the described capabilities and tactics. However, gaps remain around precise timelines, full attribution confirmation for all observed activities, and the exact financial impact on victims. Additional internal threat intelligence would be required to solidify claims of persistent infrastructure and long‑term operational tempo.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. research.jfrog.com — Cited by web research for: Node.js
  2. riskybiznews.substack.com — Cited by web research for: PLAY
  3. checkmarx.com — Cited by web research for: Repl.it
  4. https://www.linkedin.com/posts/cyber-news-live_brazilian-lofygang-resurfaces-after-three-activity-7455172745081982976-FgPu — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/js.beavertail — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/py.invisibleferret — Cited by AI analysis.
  7. https://lofygang.info/ — Cited by AI analysis.

Intel Summary

4

Techniques

52

Tools

0

Campaigns

45

IOCs

0

Observed Data

3

Tactics

Tags

Backdoor / C2
APT
financial‑gain
MaaS
infostealer
gaming
Brazilian cybercrime
supply-chain-compromise
malicious-npm-package
credential-theft
browser-injection
process-injection
fortinet-exploitation
CVE-2022-40684
social-engineering
threat-actor-lofygang
discord-bot
browser-stealer
websocket-C2
exfiltration-web-services

Details

Type
Apt
Primary Motivation
Financial gain
Country of Origin
Brazil (BR)
Confidence
50%
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.