LofyStealer Malware Targets Minecraft Players with Node.js Loader

LofyStealer Malware Targets Minecraft Players with Node.js Loader

First seen 29 Apr 2026, 12:30 UTC GbhackersCybersecuritynewsScworld 89% similarity 66.5

Article Content

Browse articles
ThreatCluster

A new infostealer malware named LofyStealer is targeting Minecraft players by masquerading as a cheat tool called 'Slinky.' This malware, linked to the Brazilian cybercrime group LofyGang, employs a Node.js-based loader and an in-memory C++ payload to conduct a two-stage attack. It stealthily extracts sensitive data from popular web browsers and sends it to a command-and-control (C2) server. The campaign is sophisticated, evading detection by standard security software. Victims are primarily gamers who unknowingly download the malicious tool. The attack's scope is concerning, given the popularity of Minecraft and the potential for widespread data theft. Currently, the malware is active and poses a significant risk to affected users.

Key Points: • LofyStealer is disguised as a cheat tool named 'Slinky' targeting Minecraft players. • The malware uses a Node.js loader and an in-memory C++ payload for data theft. • It is linked to the Brazilian cybercrime group LofyGang, indicating organized cybercrime involvement.

ThreatCluster AI

Timeline

2026-04-29
LofyStealer campaign targeting Minecraft players reported
2026-04-29
Malware identified as linked to Brazilian group LofyGang
Date unknown
Malware uses Node.js loader and C++ payload for attacks

Community

Browse all →

Tracked Entities in This Story