Briefing

Brazilian Group Resurfaces with LofyStealer Targeting Minecraft Players

security
by [email protected] (The Hacker News) ·

Block LofyStealer by detecting the Slinky disguise and preventing its execution.

What to do now

Configure endpoint protection to detect and block LofyStealer.

Summary

A Brazilian cybercrime group has resurfaced after more than three years to launch a new campaign targeting Minecraft players with a stealer called LofyStealer, also known as GrabBot. The malware masquerades as a Minecraft hack named 'Slinky' and uses the official game icon to lure users into voluntarily executing the payload. According to ZenoX, the stealer harvests credentials and other sensitive data from infected machines. The campaign spreads via malicious downloads and phishing links. The attackers rely on social engineering to convince players that the hack is legitimate. The stealer is designed to run silently in the background, collecting data without raising suspicion. The group’s resurgence highlights the ongoing threat to online gaming communities.

Key changes

  • Brazilian cybercrime group resurfaced after 3+ years targeting Minecraft players.
  • Stealer named LofyStealer (GrabBot) masquerades as Minecraft hack 'Slinky'.
  • Uses official game icon to lure voluntary execution.
  • Harvests credentials and sensitive data from infected machines.
  • Campaign spreads via malicious downloads and phishing links.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting