A large-scale malware campaign launched by the Stargazers group is targeting Minecraft players, distributing infected mods and cheats that infect Windows devices with infostealers — malicious programs that steal credentials, identification tokens, and cryptocurrency wallets
See also: Minecraft: New update turns the game into a thrilling horror experience

The campaign, uncovered by Check Point Research, is being run by the Stargazers Ghost network and is exploiting Minecraft's extensive modding ecosystem and legitimate services like GitHub to reach a large number of potential victims.
Check Point has identified thousands of views or “hits” on Pastebin links used by cybercriminals to distribute malicious files to victims’ devices, indicating the scale of the campaign.
The Stargazers Ghost network is a Distribution-as-a-Service (DaaS) operation that has been operating on GitHub since last year and was first detected by Check Point in a campaign involving 3,000 accounts spreading infostealers. The same operation, which is reinforced by fake “stars” on GitHub, was observed to have infected over 17,000 systems in late 2024 with a new malware based on the Godot engine.
The latest campaign, as described by Check Point researchers Jaromír Hořejší and Antonis Terefos, targets Minecraft players with Java-based malware that manages to evade detection by all antivirus. The researchers identified multiple repositories on GitHub run by the Stargazers network, disguised as Minecraft mods and cheats, with names such as Skyblock Extras, Polar Client, FunnyMap, Oringo , and Taunahi.
See also: Minecraft: Will it stop supporting VR in 2025?
Once executed within Minecraft, the first stage loader in JAR format downloads the next stage from Pastebin, using a base64 encoded URL, and receives a stealer-type malware written in Java.

This stealer targets Minecraft account tokens and user data from the official Minecraft launcher, as well as popular third-party launchers such as Feather, Lunar , and Essential . It also attempts to steal Discord and Telegram account tokens , sending the stolen data via HTTP POST requests to the attackers' server.
The Java-based stealer also acts as a loader for the next stage: a .NET-based stealer called “44 CALIBER,” which is more “traditional” in its approach, targeting information stored in web browsers, VPN account data, cryptocurrency wallets, applications like Steam, Discord, and others. 44 CALIBER also collects system information, clipboard content, and can take screenshots of the victim’s computer.
To stay safe from this and similar campaigns, Microsoft players should only download mods from trusted platforms and verified community portals and choose reputable publishers.
See also: Netflix: New animated series inspired by Minecraft
Based on the above, it becomes clear that attackers are leveraging the popularity and open nature of the Minecraft ecosystem to distribute malware in very clever and targeted ways. What makes the threat particularly dangerous is the targeting of young or careless users who may download mods without checking their source. Thus, user education and rigorous evaluation of the files they download (especially from unofficial sources) are crucial for security.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
