PULSE NAME
IOC - LofyStealer: Malware targeting Minecraft players.
WHITE celestre 2026-04-30 Modified: 2026-05-30
6
IOCs
LOW VOLUME
During threat hunting activities conducted on the ANY.RUN platform, the artifact was identified in public submissions of the interactive sandbox. The analysis of samples available in the public repository allowed correlating hashes and network behaviors with the already mapped C2 infrastructure (24.152.36.241), confirming that the GrabBot/Slinky campaign is active and being distributed in a real environment. The sandbox results complement the static analysis presented in this report, providing dynamic execution evidence.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (2 / 6 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 9b1264eb4ff5ee8f00b8b80341fb6917dc3d3148 2026-04-30
FileHash-SHA1 f9fe23f24d45eae418c60819c523a83ddba4ca50 2026-04-30