• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Minecraft Users Warned of Malware Targeting Modpacks

You are here: Home / General Cyber Security News / Minecraft Users Warned of Malware Targeting Modpacks
June 9, 2023

Minecraft players have been warned about a swiftly spreading multi-stage malware marketing campaign targeting modpacks and plugins.

In a superior alert warning posted at 18.00 BST on June 8, cybersecurity company Bitdefender delivered aspects on how infostealer malware named ‘Fractureiser’ is focusing on customers of the well-liked cross-system activity.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The scientists stated that numerous CurseForge and Bukkit accounts have been compromised and applied to publish malware-rigged updates of mods and plugins without the unique author’s know-how. These mods have then been incorporated in popular modpacks “that have been downloaded numerous million moments to date.”

Mods are consumer-established insert-ons that extend the gameplay, collections of which are set with each other and configured in the type of modpacks. CurseForge and Bukkit are two of the major Minecraft mod repositories.

Browse much more: Hackers, Fraudsters and Intruders – Comprehending Cybersecurity in the Gaming Sector

The Fractureiser malware is downloaded in 4 levels, labelled zero through to a few. Stage three brings the last payload in the form of a JAR file that features a native binary named hook.dll.

It at present impacts Linux and Windows Minecraft installs, and makes an attempt to propagate by itself to all JAR documents on the method, such as individuals that are not component of a Minecraft mod.

On modification of the file, the malware can goal victims in a variety of strategies. For starters, it can hijack cryptocurrency transactions by swapping wallet addresses with the attackers. Fractureiser can also steal cookies and user qualifications from web browsers and exfiltrate authentication tokens for Discord, Microsoft and Minecraft.

Bitdefender highlighted “interesting behavior we imagine is aimed at mod or plugin builders.” This is since phase three malware targets Windows Sandbox, the only virtualization atmosphere that will allow alteration of the host clipboard contents when the virtual device is running in the track record.

“We were being able to verify that dozens of mods and plugins have been rigged with the malware,” go through the notify, introducing “the frustrating vast majority of victims are in the US.”

The business shown affected mods in its indicators of compromise area, and urged customers who downloaded the contaminated mods to scan their JAR data files.

Picture credit score: KateV28 /Shutterstock.com


Some areas of this posting are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Organizations Urged to Address Critical Vulnerabilities Found in First Half of 2023
Next Post: Security Experts Highlight Exploit for Patched Windows Flaw Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
  • Cybercriminals Using New ASMCrypt Malware Loader Flying Under the Radar
  • Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm
  • Post-Quantum Cryptography: Finally Real in Consumer Apps?
  • Microsoft’s AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites
  • Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP Server
  • Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
  • GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions
  • China’s BlackTech Hacking Group Exploited Routers to Target U.S. and Japanese Companies
  • The Dark Side of Browser Isolation – and the Next Generation Browser Security Technologies

Copyright © TheCyberSecurity.News, All Rights Reserved.