惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
Minecraft mods: When ‘hacking’ your game becomes a security risk
2025-10-16 · via WeLiveSecurity

Kids Online

Minecraft mods: Should you 'hack' your game?

Some Minecraft mods don’t help build worlds – they break them. Here’s how malware can masquerade as a Minecraft mod.

16 Oct 2025  •  , 5 min. read

Minecraft mods: Should you 'hack' your game?

Gaming is one of the defining pastimes of the digital age, and for many children, it’s also their first real experience with online communities. This is where platforms like Minecraft and Roblox stand out, as they have transformed gaming into a space for creativity and learning, all while giving players almost unlimited freedom to build worlds and share their experience with others.

On the other hand, that same openness, along with the ability to download, modify, and share user-made content, also creates opportunities for nefarious actors. As we explored in a blogpost about risks surrounding Roblox executors, cybercriminals are keen to exploit trust, curiosity, and the lure of free enhancements disguised as must-have mods, cheats or automation tools. As shown by ESET researchers way back in 2015 and 2017, the risks facing Minecraft players have been around for years, and they certainly aren’t going anywhere.

What is a Minecraft mod?

First, let’s get the basics out of the way. A mod (short for “modification”) is a custom software extension for Minecraft that alters or enhances gameplay by adding new blocks, dimensions, mechanics, textures or other effects. Over time, modding has evolved into a cornerstone of the game’s appeal for many players, giving rise to a thriving ecosystem supported by communities and repositories like Planet Minecraft, CurseForge and Modrinth.

However, since mods are created by users and are distributed as third-party tools, they can also be a convenient attack vector. Attackers are long known to hide their malicious wares inside files that appear to be harmless mods, plugins, or fan tools. The risks were brought into sharp relief again recently in several large-scale campaigns:

  • Earlier this year, no fewer than 500 GitHub repositories spread an infostealer under the guise of Minecraft mods.
  • In another large-scale attack, bad actors were spotted abusing the popular modding platforms Bukkit and CurseForge to distribute the Fractureiser infostealer.
  • The risks apply to the wider gaming ecosystem, as demonstrated by ESET researchers who looked into campaigns spreading Lumma Stealer disguised as cheats for the Hamster Kombat game.

How do attackers weaponize Minecraft mods?

Malicious campaigns often follow a familiar pattern. The malware poses as a well-known or must-have mod or cheat that is available for download from GitHub, user forums, or various mod repositories. Once installed, it launches malicious background tasks or downloads additional payloads from remote servers in order to execute further instructions on the machine.

Here are some common types of malware that can masquerade as a Minecraft mod:

  • Trojans let attackers take control of a victim’s device, steal data, install other malware or flood your device with ads.
  • Infostealers steal sensitive user data such as login credentials, credit card information or web browser cookies.
  • Ransomware encrypts a victim’s files or system and demands payment, usually in cryptocurrency, for their decryption.
  • Cryptominers allow attackers to misuse someone else's device to illegally mine cryptocurrencies.

Also, mods downloaded from unreputable places carry additional, lesser-known risks. For instance, a mod that updates automatically can become a vehicle for smuggling in malware later. Also, many mods request broad privileges, including modifications to system files, while other mods may contain vulnerabilities that are then exploited by attackers, as was the case with the BleedingPipe vulnerability.

minecraft-mods-android-google-play
Ad-displaying downloader disguised as Minecraft mods on Google Play (source: ESET Research)

How can I reduce the risk of downloading a malicious mod?

As mods exist outside the controlled, verified environment of the official Minecraft client, there is no foolproof way to ensure a mod is completely safe. However, there are a few steps you can take to minimize the risk:

  • Be wary of the source: Only download mods from trusted and verified platforms within the Minecraft community like CurseForge and Modrinth. Steer clear of random file-hosting or other obscure websites, as well as discussion forums, Discord links, links in emails and social media messages, YouTube video descriptions, or other sources unrelated to the game, as these are common vectors for malware.
  • Verify the developer’s reputation: Established mod developers often have a visible track record and community support. If the author is anonymous or has no reviews, consider avoiding the mod altogether. Player feedback can also reveal past malware issues or be a decent indication that a mod is safe.
  • Watch out for unusual file types: Minecraft mods and modpacks are usually distributed as .jar files and compressed archive, such as .zip or .rar, respectively. Be cautious with executables (.exe, .bat) or installers that request administrator privileges as these are often unnecessary for mods and may contain malware.
  • Have the download link and/or the file or its hash checked by your security software or VirusTotal. It also won’t hurt to run the mods in a virtual machine or an online sandbox such as anyrun or joesandbox.

What can I do after installing a suspicious Minecraft mod?

If you suspect that a Minecraft mod you installed contains malware, do this:

  • Delete the mod file and any associated folders or configuration files. Make sure to terminate any related processes in Task Manager.
  • Run a full antimalware scan. Use a trusted security tool to scan your entire computer to remove any malicious files or scripts. A one-time check is also as available courtesy of ESET’s free scanner.
  • Reinstall Minecraft from the official source. To ensure a clean environment, uninstall it and reinstall it only from minecraft.net.
  • Change passwords for linked and any other accounts, especially the valuable ones. In other words, update credentials for not only your Minecraft account, but also for email, banking apps, and any other potentially affected accounts. Enable two-factor authentication wherever possible.
  • Contact cybersecurity professionals: If you suspect lingering malware or data compromise, reach out to security experts to ensure your devices are fully secure.

Staying safe when playing Minecraft with mods

Even if you enjoy modding Minecraft, there are steps you can take to reduce security risks and protect your system:

  • Use non-administrator accounts for gaming: Play Minecraft on a standard user account rather than one with administrator privileges. This limits a malicious mod’s ability to alter critical system settings or install unauthorized software.
  • Keep your system and software updated: Regularly install updates for your operating system and all software on it, including security software. Patches fix known software vulnerabilities and reduce the risk of compromise from malicious mods.
  • Maintain regular backups: Keep copies of both your system files and Minecraft game data. Backups allow you to recover quickly if malware compromises your system or data.
  • Use security software: This is another non-negotiable line of defense against all manner of threats.

To mod or not to mod?

Mods can significantly enhance your Minecraft experience, offering new gameplay, creativity, and customization. However, it’s crucial to remember that any file downloaded from the internet carries inherent risks. As there is no surefire way to guarantee that a mod is completely safe, the safest approach, therefore, is to avoid unofficial mods altogether. If you still choose to use them, exercise extreme caution.

If you’re a parent, educate yourself and your children not only about the risks of downloading software, but talk to them also about other risks lurking online.


Let us keep you
up to date

Sign up for our newsletters