# BlossCraft Launcher: Electron-Based Information Stealer Masquerading as Game Launcher

> BlossCraft Launcher is an Electron-based stealer delivered via an NSIS installer posing as a Minecraft-style game launcher. Obfuscated JavaScript performs reconnaissance and downloads a Python script from GitHub to harvest browser data, Discord tokens, gaming and messaging app sessions, and Wi-Fi passwords, then exfiltrates zipped data to attacker-controlled Discord webhooks.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3187
- **ID:** TL-2026-3187
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

BlossCraft Launcher is a Windows information stealer built on the Electron framework and distributed as an NSIS installer (BlossCraft-Launcher.exe, 32-bit PE, ~75.30 MB) that spoofs the PE CompanyName field as "Mojang Studios" to pass as a Minecraft-related game launcher. The installer extracts to a random %TEMP%\nsxXXXX.tmp directory, unpacks App-64.7z (a 64-bit Electron runtime, ~168.95 MB, Launcher.exe) into %PROGRAMFILES%\launcher\, drops a copy at %LOCALAPPDATA%\minecraft-launcher-core-updater\installer.exe, and uses nsExec to run a tasklist check for Launcher.exe before launching it. The report was published 2026-10-02 by Ayberk Cataloluk and Yavuzhan Özgen (GitHub 0xAyb3rK) and indexed in Malpedia; MalwareBazaar lists the installer SHA256 under the signature AminOgluStealer, first seen 2026-07-27. No CVE, CVSS, or threat actor attribution is stated in the source, and severity is an analyst assignment.

The Electron app loads app.asar containing crypted.js, which is protected with name mangling, string-array indexing, AES-256-GCM (key derived via SHA-256, Base64 master key and salt embedded) and an additional XOR layer, then executed in memory via new Function. It sets NODE_TLS_REJECT_UNAUTHORIZED=0 to disable certificate validation, loads adm-zip, axios, form-data, datavault-win and sqlite3, writes debug output to %TEMP%\debug.log, and kills browser/client processes with taskkill /F /IM. Discord webhook URLs are stored Base64-encoded and decoded by helper functions (_dw, _dw2); exfiltration is JSON and multipart form-data via axios with fallback to native https/http, and messages carry the signature string "ste4ler" in the footer. The JavaScript layer targets Discord, Discord Canary, PTB, Development and Lightcord (plaintext tokens via LevelDB regex scanning, encrypted tokens with the dQw4w9WgXcQ: prefix, an onBeforeSendHeaders hook for live credential capture, Webpack-module token extraction, and 2FA code interception) plus Chromium-family browsers (Chrome, Chrome Beta/Canary, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Epic Privacy) and Firefox for passwords, cookies, autofill, cards, history, downloads and bookmarks.

The JavaScript stage downloads a Python stealer (browser.py) from raw.githubusercontent.com/kazakh15/browser/refs/heads/main/browser.py into %TEMP% and runs it in the background, using a Python runtime under %LOCALAPPDATA%\HostService\py\. browser.py hides a zlib-compressed, Base64-encoded marshal bytecode blob (written as dumped.pyc with a Python 3.14 header). It checks IsUserAnAdmin, terminates browsers via psutil, impersonates SYSTEM by duplicating tokens from system processes (winlogon.exe, services.exe, etc.), falls back to starting TrustedInstaller, enables privileges such as SeDebugPrivilege/SeImpersonatePrivilege, and can relaunch with the ShellExecuteExW runas verb. This lets it decrypt Chromium app-bound encryption (v20, app_bound_encrypted_key) as well as v10 and Yandex-specific formats, and Firefox logins via NSS (PK11SDR_Decrypt). Output is consolidated into output.zip using a thread pool.

Other collection includes Wi-Fi passwords (netsh wlan show profile name="<SSID>" key=clear), PowerShell System.Drawing screenshots, camera capture via the WIA.DeviceManager COM object, and session/configuration theft (file copy and reg export) for Steam, Minecraft, Epic Games, Growtopia, Riot Games, Battle.net, Origin/EA, Ubisoft, Roblox, Rockstar, Genshin Impact, Wargaming, WhatsApp, Skype, Zoom, Guilded, Twitch, WeChat, Spotify, FileZilla, WinSCP and PuTTY. The report documents no persistence mechanism and does not disclose the Discord webhook values.

## MITRE ATT&CK

- T1204.002 Malicious File
- T1059.007 JavaScript
- T1059.006 Python
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1134 Access Token Manipulation
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1027.013 Encrypted/Encoded File
- T1140 Deobfuscate/Decode Files or Information
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1057 Process Discovery
- T1016.002 Wi-Fi Discovery
- T1518 Software Discovery
- T1005 Data from Local System
- T1113 Screen Capture
- T1125 Video Capture
- T1560.001 Archive via Utility
- T1070.004 Indicator Removal: File Deletion
- T1222 File and Directory Permissions Modification
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1567.004 Exfiltration Over Webhook

## Sources

- [Electron-Based Stealer Technical Analysis Report: BlossCraft Launcher (Malpedia entry)](https://malpedia.caad.fkie.fraunhofer.de/library/68470060-6d1d-40a0-b32f-204738e1d9c6/)
- [Electron-Based Stealer Technical Analysis Report: BlossCraft Launcher (Cataloluk, Özgen)](https://github.com/0xAyb3rK/BlossCraft-Electron-Malware-Analysis/blob/main/reports/blosscraft-electron-malware-analysis-en.md)
- [MalwareBazaar sample 4e40ac26... (BlossCraft-Launcher.exe, AminOgluStealer)](https://bazaar.abuse.ch/sample/4e40ac262149dde5d453c18cf700c384c846aa51dfcc5dcb9d57eac720b06d3f/)
- [Acronis TRU: Threat actors go gaming - Electron-based stealers in disguise](https://www.acronis.com/en/tru/posts/threat-actors-go-gaming-electron-based-stealers-in-disguise/)
- [Cybersecurity News: Hackers Weaponized Electron Framework to Steal Data Stealthily (related technique context)](https://cybersecuritynews.com/electron-framework-malware-exploit/amp/)
- [MITRE ATT&CK T1567.004 Exfiltration Over Webhook](https://attack.mitre.org/techniques/T1567/004/)
- [MITRE ATT&CK T1555.003 Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3187
