Brazilian Group Resurfaces with LofyStealer Targeting Minecraft Players
Block LofyStealer by detecting the Slinky disguise and preventing its execution.
Configure endpoint protection to detect and block LofyStealer.
Summary
A Brazilian cybercrime group has resurfaced after more than three years to launch a new campaign targeting Minecraft players with a stealer called LofyStealer, also known as GrabBot. The malware masquerades as a Minecraft hack named 'Slinky' and uses the official game icon to lure users into voluntarily executing the payload. According to ZenoX, the stealer harvests credentials and other sensitive data from infected machines. The campaign spreads via malicious downloads and phishing links. The attackers rely on social engineering to convince players that the hack is legitimate. The stealer is designed to run silently in the background, collecting data without raising suspicion. The group’s resurgence highlights the ongoing threat to online gaming communities.
Key changes
- Brazilian cybercrime group resurfaced after 3+ years targeting Minecraft players.
- Stealer named LofyStealer (GrabBot) masquerades as Minecraft hack 'Slinky'.
- Uses official game icon to lure voluntary execution.
- Harvests credentials and sensitive data from infected machines.
- Campaign spreads via malicious downloads and phishing links.