Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features
Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features
Read Time:3 Minute, 33 Second

A Mod That Mostly Does What It Promises

Minecraft’s modding community thrives on trust: players routinely download unofficial performance tweaks and gameplay tools from forums, Discord servers, and file-sharing sites with little more than a mod’s reputation to go on. A newly documented campaign exploits exactly that trust, distributing a fake optimization mod that impersonates the well-known Lithium project while quietly installing a full-featured information stealer called Myth Stealer.

What makes this campaign notable is its patience. The malicious package includes twelve genuinely functional performance modules that adjust game settings as advertised, alongside a thirteenth, hidden component that has nothing to do with frame rates and everything to do with harvesting the victim’s data.

From Java Archive to Full System Access

The attack starts with a Java archive file dressed up as the Lithium mod. Because many players don’t have a Java runtime installed, or the right version, the package bundles its own runtime environment so the mod runs regardless. During installation, it displays what looks like a standard administrator permission prompt — the same kind Windows shows for countless legitimate applications — to escalate its privileges without raising suspicion. The final payload is then unpacked using encrypted strings, filenames that mimic Windows system conventions, and anti-extraction safeguards designed to frustrate both manual analysis and automated sandboxes.

What Myth Stealer Takes

Once running, Myth Stealer casts a wide net over the infected machine, targeting:

  • Saved usernames and passwords stored in Chromium- and Firefox-based browsers
  • Browsing history and active session cookies, which can let attackers hijack logged-in accounts without needing a password
  • System configuration details useful for further targeting
  • Chat logs and clipboard contents
  • Screenshots and webcam captures, saved locally before exfiltration

Session cookie theft is particularly damaging: it can grant access to accounts that use two-factor authentication, since a stolen active session skips the login step entirely.

Beyond Theft: Remote Control and Disruption

Myth Stealer isn’t limited to one-time data collection. It also functions as a remote access tool, giving its operators the ability to run commands, manage files, manipulate running processes, and maintain persistence by relaunching itself after every reboot. A set of disruption features rounds out the toolkit: manipulating the victim’s display, interfering with mouse and keyboard input, and disabling security tools such as Task Manager — capabilities better suited to harassment or covering tracks than straightforward theft.

Command Infrastructure

The malware communicates with a primary command server and a backup domain styled to look like a gaming-related site, while using Discord webhooks — a common, hard-to-block channel favored by malware distributors — to exfiltrate stolen data. A secondary payload was found hosted on a mainstream file-sharing service, disguised as a “Discord Nitro generator,” a lure commonly used to bait gamers eager for free perks on the platform.

Slipping Past Detection

The researcher who first flagged the campaign found that the samples registered zero detections on VirusTotal at the time of discovery, despite the malware’s broad feature set. That gap illustrates a persistent problem with reputation-based antivirus scanning: a freshly compiled, narrowly distributed sample can sail past signature databases simply because it hasn’t been seen — and flagged — enough times yet.

Why Gaming Communities Keep Getting Targeted

Minecraft and similar games remain a favorite target for malware distributors precisely because their modding ecosystems run on informal trust rather than centralized vetting. Players, especially younger ones, are accustomed to downloading executables from third-party sites, granting administrator prompts without a second thought, and sharing mod recommendations through Discord and chat — all behaviors this campaign is built to exploit.

Protecting Yourself

  • Download mods only from official project pages or well-established repositories, never from links shared in chat, video descriptions, or unfamiliar file-sharing sites.
  • Verify a mod’s publisher and file integrity before running it, and be suspicious of any mod that requests administrator privileges.
  • Treat unexpected Windows permission prompts as a red flag, particularly for software that has no obvious reason to need elevated access.
  • If you’ve installed a suspicious mod, remove it immediately, run a full scan from a clean environment, change passwords for important accounts, and log out of active sessions everywhere.
  • Periodically review installed browser extensions and startup programs for anything unrecognized.
Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features, use the discussion on Forum.

>> forum community

Comments

Leave a Reply