New Python RAT Posing as Minecraft Client Steals Discord Logins

New Python RAT Posing as Minecraft Client Steals Discord Logins

Netskope flags Nursultan Client as the latest social engineering trap for players hunting cracked launches or mods. Attackers gain webcam access, screenshots, file access and Discord tokens via Telegram commands.

Minecraft players chasing modified clients or cracked launches are feeding a growing malware pipeline. The latest example is a Python remote access trojan dressed up as Nursultan Client, an unofficial build popular in certain circles.

Once installed, the RAT waits for commands sent over Telegram. Attackers can snap screenshots, flip on the webcam, open arbitrary links, and rifle through files looking for Discord tokens and login data. Netskope says the social engineering is straightforward: gamers already download random jars and mods outside official channels, so the bar is low.

This is not theoretical. The tactic preys on the exact habits the community has normalized for years. Official launcher bad, random Discord link good. The result is predictable and keeps happening.

The campaign is not isolated. Similar operations have cycled through the Minecraft ecosystem for months, swapping names and delivery methods while the core lure stays the same. Players who value their accounts and linked services should treat anything outside the official Minecraft launcher as hostile until proven otherwise.

What the RAT Actually Does

  • Takes screenshots of the victim's screen on command
  • Activates the webcam for live feeds
  • Steals Discord login keys and browser credentials
  • Opens arbitrary web pages or images
  • General file system reconnaissance and exfiltration

Netskope researcher Nikhil Hegde noted the use of a known community client name is deliberate social engineering. It lowers suspicion among users already comfortable sideloading tools. The malware is not especially sophisticated but it does not need to be. The volume of willing downloads does the heavy lifting.

Netskope report by Nikhil Hegde on Python RAT impersonating Nursultan Minecraft client
Netskope analysis detailing social engineering via known community Minecraft client name Source

Using the name of a known Minecraft client is a clear social engineering tactic to trick victims, especially gamers.

The report surfaces at a time when Minecraft’s mod and server scene remains decentralized and lightly policed. Official warnings exist but the player base has demonstrated it will ignore them in favor of convenience or free features. That gap is where these campaigns live.

If you are still downloading random .jar files from Discord or shady sites in 2026, the odds are not in your favor. The attackers have automated the process and the payoff is reliable.

The fix is boring but effective: stick to the official launcher, use reputable mod repositories with verification, and treat every “friend sent me this client” message as a potential vector. Until the community internalizes that, stories like this will keep appearing every few weeks.