Threat reportMalwareTL-2026-3187
BlossCraft Launcher: Electron-Based Information Stealer Masquerading as Game Launcher
BlossCraft Launcher (TL-2026-3187), also tracked as BlossCraft, is a medium-severity malware campaign, first published 2026-10-10. It has no confirmed attribution, affects Microsoft Windows, maps to 25 MITRE ATT&CK techniques (T1005, T1016.002, T1027), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-3187
- Threat ID
- TL-2026-3187
- Also known as
- BlossCraft, BlossCraft-Launcher, AminOgluStealer
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- gaming, consumer
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in BlossCraft Launcher
Malware and tooling: BlossCraft
How BlossCraft Launcher works
BlossCraft Launcher is an Electron-based stealer delivered via an NSIS installer posing as a Minecraft-style game launcher. Obfuscated JavaScript performs reconnaissance and downloads a Python script from GitHub to harvest browser data, Discord tokens, gaming and messaging app sessions, and Wi-Fi passwords, then exfiltrates zipped data to attacker-controlled Discord webhooks.
BlossCraft Launcher is a Windows information stealer built on the Electron framework and distributed as an NSIS installer (BlossCraft-Launcher.exe, 32-bit PE, ~75.30 MB) that spoofs the PE CompanyName field as "Mojang Studios" to pass as a Minecraft-related game launcher. The installer extracts to a random %TEMP%\nsxXXXX.tmp directory, unpacks App-64.7z (a 64-bit Electron runtime, ~168.95 MB, Launcher.exe) into %PROGRAMFILES%\launcher\, drops a copy at %LOCALAPPDATA%\minecraft-launcher-core-updater\installer.exe, and uses nsExec to run a tasklist check for Launcher.exe before launching it. The report was published 2026-10-02 by Ayberk Cataloluk and Yavuzhan Özgen (GitHub 0xAyb3rK) and indexed in Malpedia; MalwareBazaar lists the installer SHA256 under the signature AminOgluStealer, first seen 2026-07-27. No CVE, CVSS, or threat actor attribution is stated in the source, and severity is an analyst assignment.
The Electron app loads app.asar containing crypted.js, which is protected with name mangling, string-array indexing, AES-256-GCM (key derived via SHA-256, Base64 master key and salt embedded) and an additional XOR layer, then executed in memory via new Function. It sets NODE_TLS_REJECT_UNAUTHORIZED=0 to disable certificate validation, loads adm-zip, axios, form-data, datavault-win and sqlite3, writes debug output to %TEMP%\debug.log, and kills browser/client processes with taskkill /F /IM. Discord webhook URLs are stored Base64-encoded and decoded by helper functions (_dw, _dw2); exfiltration is JSON and multipart form-data via axios with fallback to native https/http, and messages carry the signature string "ste4ler" in the footer. The JavaScript layer targets Discord, Discord Canary, PTB, Development and Lightcord (plaintext tokens via LevelDB regex scanning, encrypted tokens with the dQw4w9WgXcQ: prefix, an onBeforeSendHeaders hook for live credential capture, Webpack-module token extraction, and 2FA code interception) plus Chromium-family browsers (Chrome, Chrome Beta/Canary, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Epic Privacy) and Firefox for passwords, cookies, autofill, cards, history, downloads and bookmarks.
The JavaScript stage downloads a Python stealer (browser.py) from raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py into %TEMP% and runs it in the background, using a Python runtime under %LOCALAPPDATA%\HostService\py\. browser.py hides a zlib-compressed, Base64-encoded marshal bytecode blob (written as dumped.pyc with a Python 3.14 header). It checks IsUserAnAdmin, terminates browsers via psutil, impersonates SYSTEM by duplicating tokens from system processes (winlogon.exe, services.exe, etc.), falls back to starting TrustedInstaller, enables privileges such as SeDebugPrivilege/SeImpersonatePrivilege, and can relaunch with the ShellExecuteExW runas verb. This lets it decrypt Chromium app-bound encryption (v20, app_bound_encrypted_key) as well as v10 and Yandex-specific formats, and Firefox logins via NSS (PK11SDR_Decrypt). Output is consolidated into output.zip using a thread pool.
Other collection includes Wi-Fi passwords (netsh wlan show profile name="<SSID>" key=clear), PowerShell System.Drawing screenshots, camera capture via the WIA.DeviceManager COM object, and session/configuration theft (file copy and reg export) for Steam, Minecraft, Epic Games, Growtopia, Riot Games, Battle.net, Origin/EA, Ubisoft, Roblox, Rockstar, Genshin Impact, Wargaming, WhatsApp, Skype, Zoom, Guilded, Twitch, WeChat, Spotify, FileZilla, WinSCP and PuTTY. The report documents no persistence mechanism and does not disclose the Discord webhook values.
MITRE ATT&CK techniques used in TL-2026-3187
Collection
T1005 Data from Local System; T1113 Screen Capture; T1125 Video Capture; T1560.001 Archive via Utility
Discovery
T1016.002 Wi-Fi Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File
Privilege Escalation
T1134 Access Token Manipulation
defense-impairment
T1222 File and Directory Permissions Modification
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Exfiltration
Affected products and versions in BlossCraft Launcher
- Microsoft — Windows
Vulnerable versions: Windows endpoints where the trojanized installer is executed
Remediation for BlossCraft Launcher
Immediate actions
- Block or alert on execution of BlossCraft-Launcher.exe and the published SHA256/MD5 hashes
- Alert on requests to raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py and report the GitHub account kazakh15
- Hunt for %PROGRAMFILES%\launcher\, %LOCALAPPDATA%\minecraft-launcher-core-updater\ and %LOCALAPPDATA%\HostService\py\ on endpoints
- If infection is confirmed: isolate the host, revoke Discord tokens, sessions and browser-saved credentials, rotate Wi-Fi, game, FTP/SSH passwords and enable fresh MFA
Workarounds
- Avoid storing credentials in browsers on gaming machines; use a dedicated password manager with MFA
Longer-term hardening
- Restrict installation of unsigned software and game launchers from untrusted sources via application control
- Detect NSIS installers spawning Electron apps that launch Python from user-writable paths
- Monitor for NODE_TLS_REJECT_UNAUTHORIZED=0, bulk taskkill of browsers, netsh wlan key=clear, WIA.DeviceManager COM use and DuplicateTokenEx/SetThreadToken sequences
- Restrict or monitor outbound traffic to Discord webhook endpoints from non-Discord processes
Timeline of BlossCraft Launcher
- Acronis TRU publishes research on Electron-based stealers (Leet, RMC, Sniffer) hiding in fake indie game installers distributed via Discord and fraudulent sites, the same lure-and-Electron pattern later seen in BlossCraft (BlossCraft itself is not named in that report)
- BlossCraft-Launcher.exe (SHA256 4e40ac26...) first seen on MalwareBazaar under the signature AminOgluStealer
- Report documents the Python stage payload URL (raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py) and lists the kazakh15 GitHub account as a potential IOC; Discord webhook values are not disclosed
- Report added to the Malpedia library with date 2026-10-02
- Ayberk Cataloluk and Yavuzhan Özgen publish the BlossCraft Electron stealer technical analysis on GitHub (0xAyb3rK)
- Threadlinqs opens tracking of BlossCraft Launcher as TL-2026-3187; no CVE, actor attribution or persistence mechanism documented in the source
Sources cited for BlossCraft Launcher
- Electron-Based Stealer Technical Analysis Report: BlossCraft Launcher (Malpedia entry)
- Electron-Based Stealer Technical Analysis Report: BlossCraft Launcher (Cataloluk, Özgen)
- MalwareBazaar sample 4e40ac26... (BlossCraft-Launcher.exe, AminOgluStealer)
- Acronis TRU: Threat actors go gaming - Electron-based stealers in disguise
- Cybersecurity News: Hackers Weaponized Electron Framework to Steal Data Stealthily (related technique context)
- MITRE ATT&CK T1567.004 Exfiltration Over Webhook
- MITRE ATT&CK T1555.003 Credentials from Web Browsers
Detection coverage for TL-2026-3187
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3187 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.