Fake Minecraft Mod Deploys Myth Stealer RAT to Steal Browser Credentials and Cookies
A counterfeit Minecraft optimization mod is distributing the Myth Stealer RAT, which steals browser credentials and cookies, masking its malicious intent with functional game enhancements.

A deceptive campaign is leveraging a fake Minecraft optimization mod to distribute the Myth Stealer Remote Access Trojan (RAT), a malware designed to pilfer browser credentials and session cookies. The malicious mod is engineered to appear legitimate, offering actual performance improvements to unsuspecting players, thereby masking a sophisticated, multi-stage infection chain that ultimately deploys the RAT. This tactic exploits the common practice of gamers seeking unofficial add-ons to enhance their gaming experience.
Once installed, the counterfeit mod initiates a hidden infection process. Analysts first identified the malware through samples obtained from buyers of commodity stealers, noting that the initial files received zero detections on VirusTotal, highlighting the effectiveness of lightly distributed threats in evading reputation-based security checks. The mod's manifest falsely claims affiliation with the legitimate Lithium project, further lending it an air of authenticity.
The threat actor pairs a convincing decoy with a loader designed to blend seamlessly into a gaming setup. The Java archive masquerades as a legitimate optimization tool, complete with 12 functional modules that alter game performance settings. However, a concealed thirteenth component lies dormant, gathering system information before retrieving and executing the next stage of the infection in the background. This stealthy approach ensures that victims, observing the expected optimization behaviors, are unlikely to suspect any underlying malicious activity.
Before launching the final payload, the loader presents a polished administrator-rights request that closely mimics a standard Windows prompt. Granting these elevated privileges allows the malware greater access to the system, facilitating its installation and operation. The loader also incorporates retry logic to circumvent interruptions from security software, increasing its chances of successful deployment.
The final component, the Myth Stealer RAT, is heavily obfuscated to impede analysis. Its code employs reserved Windows-style names, encrypted data, and anti-analysis obstacles designed to break common extraction tools. This deliberate concealment, combined with the seemingly legitimate mod, renders a quick visual inspection of downloaded files an unreliable safeguard against this threat.
Myth Stealer specifically targets data stored by Chromium-based browsers and Firefox, including saved usernames, passwords, browsing history, and active session cookies. The theft of session cookies is particularly damaging, as it can allow attackers to hijack authenticated web sessions without needing to re-enter credentials. Beyond browser data, the malware is capable of collecting system details, chat content, clipboard data, and files, and can capture screenshots or webcam imagery.
The RAT's remote-control capabilities are extensive, allowing operators to execute commands, download or delete files, manage processes, and establish persistence by configuring itself to launch after a reboot. Researchers also noted features designed to disrupt victims, such as altering display settings, interfering with mouse and keyboard input, displaying misleading full-screen messages, and attempting to disable security tools. These disruptive functions can complicate recovery efforts and pressure victims into complying with attacker demands.
Stolen information is exfiltrated via web-based reporting channels, a technique commonly seen in Discord webhook abuse. While the analyzed command-and-control infrastructure was inactive at the time of reporting, systems already infected remain at risk. Players are strongly advised to download mods exclusively from trusted project pages, verify developer authenticity and file integrity, and avoid downloads promoted through unofficial channels. Anyone who suspects they have installed a malicious mod should remove it, perform a full security scan, change passwords from a clean device, and sign out of important accounts to invalidate potentially compromised sessions.