Minecraft: SugarSMPs Dark Tale of Scams, Malware & Extortion

General News

Summary

Researchers investigated SugarSMP, a Minecraft community site, and found that a distributed modpack contained a Java stealer (named Spark stealer) that exfiltrates credentials, Discord tokens, browser data and crypto-wallet information via Discord webhooks and other channels. The malware hid inside a modified AppleSkin mod JAR, used Java Native Access to call Windows crypto APIs, injected code into Discord to persist and capture data, and installed scheduled tasks for long-term persistence. The operators used social engineering—fake community sites, videos, and takedown requests to Reddit moderators—to protect reputation and erase warnings, and the investigators found dozens of lookalike domains hosting similar stealers. The report lists indicators of compromise, remediation steps (reinstall Discord, remove malicious scheduled tasks, rotate passwords and crypto keys) and warns developers and players to avoid unofficial modpacks and verify downloads.

Classifications

industries
Entertainment
applications
ERP & Process Management

AskAI Classifications

Labels
Cybersecurity Antivirus Software IT Security Solutions

Linked Companies

G DATA CyberDefense AG
$50M to $100M