Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LofyGang Returns with Minecraft Malware Campaign

LofyGang Returns with Minecraft Malware Campaign

Posted on April 28, 2026 By CWS

A Brazilian hacking group known as LofyGang has re-emerged after a hiatus of over three years, launching a new campaign targeting Minecraft players. This operation employs a malicious tool dubbed LofyStealer, which masquerades as a Minecraft cheat called ‘Slinky’. According to cybersecurity firm ZenoX, the malware utilizes the official Minecraft icon to deceive users, mainly targeting younger players familiar with the gaming community.

LofyGang’s Cyber Tactics and History

LofyGang, active since late 2021, has been observed using typosquatting techniques on the npm registry to distribute malware. Their objective is to harvest credit card details and user data from platforms like Discord Nitro, gaming, and streaming services. The group promotes its hacking tools on platforms such as GitHub and YouTube, and under the alias DyPolarLofy, they have leaked thousands of compromised Disney+ and Minecraft accounts.

Acassio Silva, co-founder at ZenoX, noted that Minecraft has been a consistent target for LofyGang since 2022. The group has reportedly leaked numerous Minecraft accounts on forums like Cracked.io, with the current campaign directly aiming to compromise players through the fake ‘Slinky’ hack.

How LofyStealer Operates

The attack commences when the fake Minecraft hack is executed, triggering a JavaScript loader that deploys the LofyStealer malware, identified as “chromelevator.exe”. This malware is designed to extract sensitive information from various web browsers, including Google Chrome, Microsoft Edge, and Mozilla Firefox, among others. The stolen data, such as cookies, passwords, and credit card details, is sent to a command-and-control server for further exploitation.

ZenoX reports that the group’s primary method involves targeting the JavaScript supply chain through tactics like npm package typosquatting. They have also used fraudulent references to inflate credibility and embedded payloads in sub-dependencies to avoid detection. The current campaign marks a shift towards a malware-as-a-service model, featuring both free and premium tiers and a custom builder known as Slinky Cracked.

Broader Implications and Ongoing Challenges

This resurgence of LofyGang coincides with a broader trend of threat actors exploiting trusted platforms such as GitHub to distribute malware. Techniques like SEO poisoning and misleading repository names lure users into downloading malicious software. Some attackers have used platforms like Reddit to spread malware by advertising fake game cheats, redirecting users to malicious websites containing harmful files.

Recent analyses indicate that widely trusted platforms are being manipulated to distribute malicious payloads. This campaign underscores the challenge of safeguarding trusted channels from abuse. Security experts advise treating any GitHub-hosted download that pairs renamed interpreters with opaque data files as potentially harmful.

As cyber threats continue to evolve, it remains crucial for developers and users to remain vigilant against these sophisticated attacks. The rise of malware-as-a-service models and the exploitation of social trust pose significant challenges to conventional security measures, necessitating continued vigilance and innovation in cybersecurity practices.

The Hacker News Tags:Cybersecurity, Discord, GitHub, Hacking, InfoStealer, JavaScript, LofyGang, LofyStealer, Malware, Minecraft

Post navigation

Previous Post: BlobPhish Exploits Microsoft 365 with New Tactics
Next Post: Cyber Insurance Enhances CISO Budget Negotiations

Related Posts

What AI Reveals About Web Applications— and Why It Matters What AI Reveals About Web Applications— and Why It Matters The Hacker News
ZAST.AI Secures M to Enhance AI-Driven Code Security ZAST.AI Secures $6M to Enhance AI-Driven Code Security The Hacker News
UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns The Hacker News
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution The Hacker News
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do The Hacker News
Android Spyware Asin Targets Arabic Users via Fake Apps Android Spyware Asin Targets Arabic Users via Fake Apps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices
  • GitHub to Restrict npm Scripts by Default to Enhance Security
  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark