Netskope flags a Python remote access trojan disguised as Nursultan Client that hits players downloading unofficial Minecraft mods and tools then uses Telegram to pull screenshots webcams and login keys.

Minecraft players chasing custom clients mods or unofficial tools just got another loud warning. According to a report published today a new Python-based remote access trojan is circulating under the name Nursultan Client. Once installed it quietly steals Discord login data and opens the door for attackers to run commands like taking screenshots activating the webcam or opening arbitrary files and pages.
The malware leans on familiar social engineering. Players looking for modified Minecraft versions outside official channels download the fake client which then installs the RAT. From there the attacker controls it through a Telegram bot giving them persistent access without needing the victim to stay logged into a specific server or launcher. This is not some ancient recycled threat. The details surfaced in a fresh analysis tying it to malware-as-a-service models that let multiple operators rent or resell the tool.
What the RAT actually does once inside

- Exfiltrates Discord tokens and login keys stored on the machine
- Captures screenshots and webcam footage on command
- Opens web pages or local files chosen by the attacker
- Supports full remote shell capabilities typical of Python RATs
- Operates as part of a larger MaaS ecosystem that can be resold
This campaign follows the same pattern seen in earlier Minecraft malware waves such as WeedHack but focuses on Discord as a primary target after initial infection. Attackers know the community frequently uses Discord for server coordination mod sharing and voice chat making it high value real estate. The use of a named unofficial client like Nursultan Client shows deliberate targeting of specific player communities that already trust modified versions.
Netskope researchers highlighted the Telegram command structure which lets the operator issue instructions without exposing a traditional C2 server that might get taken down quickly. This design keeps the operation resilient. While exact infection numbers for this specific variant are not yet public the pattern matches prior campaigns that racked up thousands of hits per day.
Basic protection steps that actually work
- Only download Minecraft from the official launcher or trusted platforms
- Avoid YouTube links promising free mods cracked clients or exclusive features
- Use antivirus that scans JAR files and Python scripts before execution
- Enable two-factor authentication everywhere especially Discord and Microsoft accounts
- Keep Java and your OS updated since many RATs exploit outdated runtimes
The Minecraft ecosystem has always had a lively modding and server scene but that openness creates constant pressure from scammers and malware authors. Stories like this surface every few months because the incentive is obvious: millions of players many of them young and some willing to click anything for an edge or a cool texture pack. Until the community gets stricter about sources these warnings will keep coming.
Using the name of a known Minecraft client is a clear social engineering tactic to trick gamers especially those in modding communities.
That blunt assessment from the researchers cuts through the noise. The best defense remains boring but effective: stick to verified downloads and treat anything promising too-good-to-be-true Minecraft extras as a likely vector. Your Discord account and connected services are worth more than one suspicious mod.
Other