Threat reportMalwareTL-2026-3187

BlossCraft Launcher: Electron-Based Information Stealer Masquerading as Game Launcher

mediumACTIVE

BlossCraft Launcher (TL-2026-3187), also tracked as BlossCraft, is a medium-severity malware campaign, first published 2026-10-10. It has no confirmed attribution, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1005, T1016.002, T1027), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-3187

Threat ID
TL-2026-3187
Also known as
BlossCraft, BlossCraft-Launcher, AminOgluStealer
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
gaming, consumer
Detection rules
9
Indicators of compromise
22

Malware and tooling in BlossCraft Launcher

Malware and tooling: BlossCraft

How BlossCraft Launcher works

BlossCraft Launcher is an Electron-based stealer delivered via an NSIS installer posing as a Minecraft-style game launcher. Obfuscated JavaScript performs reconnaissance and downloads a Python script from GitHub to harvest browser data, Discord tokens, gaming and messaging app sessions, and Wi-Fi passwords, then exfiltrates zipped data to attacker-controlled Discord webhooks.

BlossCraft Launcher is a Windows information stealer built on the Electron framework and distributed as an NSIS installer (BlossCraft-Launcher.exe, 32-bit PE, ~75.30 MB) that spoofs the PE CompanyName field as "Mojang Studios" to pass as a Minecraft-related game launcher. The installer extracts to a random %TEMP%\nsxXXXX.tmp directory, unpacks App-64.7z (a 64-bit Electron runtime, ~168.95 MB, Launcher.exe) into %PROGRAMFILES%\launcher\, drops a copy at %LOCALAPPDATA%\minecraft-launcher-core-updater\installer.exe, and uses nsExec to run a tasklist check for Launcher.exe before launching it. The report was published 2026-10-02 by Ayberk Cataloluk and Yavuzhan Özgen (GitHub 0xAyb3rK) and indexed in Malpedia; MalwareBazaar lists the installer SHA256 under the signature AminOgluStealer, first seen 2026-07-27. No CVE, CVSS, or threat actor attribution is stated in the source, and severity is an analyst assignment.

The Electron app loads app.asar containing crypted.js, which is protected with name mangling, string-array indexing, AES-256-GCM (key derived via SHA-256, Base64 master key and salt embedded) and an additional XOR layer, then executed in memory via new Function. It sets NODE_TLS_REJECT_UNAUTHORIZED=0 to disable certificate validation, loads adm-zip, axios, form-data, datavault-win and sqlite3, writes debug output to %TEMP%\debug.log, and kills browser/client processes with taskkill /F /IM. Discord webhook URLs are stored Base64-encoded and decoded by helper functions (_dw, _dw2); exfiltration is JSON and multipart form-data via axios with fallback to native https/http, and messages carry the signature string "ste4ler" in the footer. The JavaScript layer targets Discord, Discord Canary, PTB, Development and Lightcord (plaintext tokens via LevelDB regex scanning, encrypted tokens with the dQw4w9WgXcQ: prefix, an onBeforeSendHeaders hook for live credential capture, Webpack-module token extraction, and 2FA code interception) plus Chromium-family browsers (Chrome, Chrome Beta/Canary, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Epic Privacy) and Firefox for passwords, cookies, autofill, cards, history, downloads and bookmarks.

The JavaScript stage downloads a Python stealer (browser.py) from raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py into %TEMP% and runs it in the background, using a Python runtime under %LOCALAPPDATA%\HostService\py\. browser.py hides a zlib-compressed, Base64-encoded marshal bytecode blob (written as dumped.pyc with a Python 3.14 header). It checks IsUserAnAdmin, terminates browsers via psutil, impersonates SYSTEM by duplicating tokens from system processes (winlogon.exe, services.exe, etc.), falls back to starting TrustedInstaller, enables privileges such as SeDebugPrivilege/SeImpersonatePrivilege, and can relaunch with the ShellExecuteExW runas verb. This lets it decrypt Chromium app-bound encryption (v20, app_bound_encrypted_key) as well as v10 and Yandex-specific formats, and Firefox logins via NSS (PK11SDR_Decrypt). Output is consolidated into output.zip using a thread pool.

Other collection includes Wi-Fi passwords (netsh wlan show profile name="<SSID>" key=clear), PowerShell System.Drawing screenshots, camera capture via the WIA.DeviceManager COM object, and session/configuration theft (file copy and reg export) for Steam, Minecraft, Epic Games, Growtopia, Riot Games, Battle.net, Origin/EA, Ubisoft, Roblox, Rockstar, Genshin Impact, Wargaming, WhatsApp, Skype, Zoom, Guilded, Twitch, WeChat, Spotify, FileZilla, WinSCP and PuTTY. The report documents no persistence mechanism and does not disclose the Discord webhook values.

MITRE ATT&CK techniques used in TL-2026-3187

Collection

T1005 Data from Local System; T1113 Screen Capture; T1125 Video Capture; T1560.001 Archive via Utility

Discovery

T1016.002 Wi-Fi Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File

Privilege Escalation

T1134 Access Token Manipulation

defense-impairment

T1222 File and Directory Permissions Modification

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers

Exfiltration

T1567.004 Exfiltration Over Webhook

Affected products and versions in BlossCraft Launcher

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints where the trojanized installer is executed

Remediation for BlossCraft Launcher

Immediate actions

  • Block or alert on execution of BlossCraft-Launcher.exe and the published SHA256/MD5 hashes
  • Alert on requests to raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py and report the GitHub account kazakh15
  • Hunt for %PROGRAMFILES%\launcher\, %LOCALAPPDATA%\minecraft-launcher-core-updater\ and %LOCALAPPDATA%\HostService\py\ on endpoints
  • If infection is confirmed: isolate the host, revoke Discord tokens, sessions and browser-saved credentials, rotate Wi-Fi, game, FTP/SSH passwords and enable fresh MFA

Workarounds

  • Avoid storing credentials in browsers on gaming machines; use a dedicated password manager with MFA

Longer-term hardening

  • Restrict installation of unsigned software and game launchers from untrusted sources via application control
  • Detect NSIS installers spawning Electron apps that launch Python from user-writable paths
  • Monitor for NODE_TLS_REJECT_UNAUTHORIZED=0, bulk taskkill of browsers, netsh wlan key=clear, WIA.DeviceManager COM use and DuplicateTokenEx/SetThreadToken sequences
  • Restrict or monitor outbound traffic to Discord webhook endpoints from non-Discord processes

Timeline of BlossCraft Launcher

  • Acronis TRU publishes research on Electron-based stealers (Leet, RMC, Sniffer) hiding in fake indie game installers distributed via Discord and fraudulent sites, the same lure-and-Electron pattern later seen in BlossCraft (BlossCraft itself is not named in that report)
  • BlossCraft-Launcher.exe (SHA256 4e40ac26...) first seen on MalwareBazaar under the signature AminOgluStealer
  • Report documents the Python stage payload URL (raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py) and lists the kazakh15 GitHub account as a potential IOC; Discord webhook values are not disclosed
  • Report added to the Malpedia library with date 2026-10-02
  • Ayberk Cataloluk and Yavuzhan Özgen publish the BlossCraft Electron stealer technical analysis on GitHub (0xAyb3rK)
  • Threadlinqs opens tracking of BlossCraft Launcher as TL-2026-3187; no CVE, actor attribution or persistence mechanism documented in the source

Sources cited for BlossCraft Launcher

Detection coverage for TL-2026-3187

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3187 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats