fractureiser
is a multi-stage Java virus (and potential worm) that infects Java .jar
files, and is a targeted attack on the Minecraft-playing community.
The virus was initially distributed by infecting legitimate Minecraft mods with the virus and reposting them to CurseForge under a different name, using a brand-new account. Eventually, someone who was logged into CurseForge downloaded and ran one of these infected mods, the stage3 payload swiped their browser cookies; and the attacker used these cookies to log in as them and upload a couple more infected mods under their account.
(CurseForge itself was not hacked - it was simply a stolen cookie.)
You can find more information in our research repository here.