A new multi-stage malware campaign is targeting Minecraft users with a Java-based malware that employs a distribution-as-service (DaaS) offering called Stargazers Ghost Network.

“The malware was impersonating Oringo and Taunahi, which are ‘Scripts and macros tools’ (aka cheats). Both the first and second stages are developed in Java and can only be executed if the Minecraft runtime is installed on the host machine.”

  • cecilkorik
    link
    fedilink
    English
    arrow-up
    56
    ·
    7 days ago

    This is a slow-news-day story and affects neither you nor anyone you care about.

    The malware was impersonating Oringo and Taunahi

    As usual, these hacks target idiots using cheats and aimbots, downloading them from a fake repository on Github directly, which is no different than downloading an exe. 99.99% of Minecraft mods are fine, so is Prism, so is Modrinth.

    • neons@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      7 days ago

      Me who uses these “cheats” (are they still cheats if there’s noone getting hurt?) in singleplayer:

      0.0

      • Snazz@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 days ago

        What on earth would you need a cheat client for singleplayer? You already have full control of the game

        • neons@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 days ago

          Small qulity of live stuff. i.e. “Meteor client” allows me to put fireforks on a hotkey so I don’t have to keep them in the hotbar/offhand. I also like that it shows me the trajectory of my arrows or fireballs or that it can automate Totems from the inventory so i can keep my offhand free (again).

          Just a lot of small stuff :)

    • Noodle07@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 days ago

      I spend my time downloading exe on my PC everything is fine :D it’s mostly when trying to cheat stuff that you get problems

    • thatonecoder
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      9
      ·
      7 days ago

      The fact that those people didn’t even decompile the JAR files is amazing.

      • pwnicholson@lemmy.world
        link
        fedilink
        English
        arrow-up
        20
        ·
        7 days ago

        You realize that like 0.1% if the population even knows what that means, much less would bother to do it? We’re talking about the best selling video game of all time.

        • thatonecoder
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 days ago

          Considering that the ENTIRE Hypixel SkyBlock cheating community warns about these things (and there are websites that tell you if a JAR file may be compromised), it is impressive.