ThreatCluster

Fake Minecraft Mod Distributes Myth Stealer RAT for Credential Theft

First seen 7 Sep 2026, 11:51 UTC GbhackersCybersecuritynews 59

Article Content

Browse articles
ThreatCluster

A counterfeit Minecraft optimization mod has been identified deploying Myth Stealer 3.2-FIX, a Remote Access Trojan (RAT) designed to steal passwords and browser credentials. The malicious file, disguised as Lithium Extras 0.15.0+mc1.21.1, exploits users seeking performance enhancements from unofficial mods. Victims unknowingly install the trojanized mod, which then executes a multi-stage attack to harvest sensitive information. The malware is capable of remote control, surveillance, and harassment of victims. This campaign primarily targets Minecraft players, raising concerns about the security of unofficial game modifications. The current status indicates ongoing exploitation as users continue to download the malicious mod. No specific numbers or CVEs are mentioned in the articles.

Key Points: • Myth Stealer RAT is being distributed via a fake Minecraft optimization mod. • The malware can steal sensitive browser credentials and control infected PCs remotely. • The attack exploits users looking for performance improvements from unofficial mods.

Ask AI about this cluster

Timeline

2026-09-07
Fake Minecraft mod identified
A trojanized mod masquerading as Lithium Extras was reported to deploy Myth Stealer RAT.
Gbhackers
2026-09-07
Malware capabilities detailed
Myth Stealer RAT is confirmed to steal passwords and remotely control PCs, affecting Minecraft players.
Cybersecuritynews