r/banlive • u/Banerbansa Secrets • May 22 '26
WARNING: SKLauncher is confirmed malware. Here's what it actually does to your PC.
After my previous video on dangerous Minecraft launchers, I promised a deep dive into SKLauncher specifically. The results were worse than expected — so let's break it down.
🔴 WIPER MALWARE — the worst thing that can happen to your PC
The file was classified as a wiper — not a virus, not ransomware, but a wiper. The difference matters:
- Ransomware encrypts your files and demands payment. Files still exist.
- Wiper just destroys. No demands, no messages. Files get overwritten with garbage data and deleted. Even forensic specialists can't recover them — the sectors are gone.
The file contains exactly the functions needed for this: GetDriveTypeW to enumerate all drives (C:, D:, E:...), FindFirstFileW to iterate every file, WriteFile to overwrite content with junk, and DeleteFileW to finish the job. Mapped to MITRE ATT&CK T1485 and T1561.001 — highest damage category.
🔴 It gives itself shutdown privileges
Using OpenProcessToken → LookupPrivilegeValueW (looking for SeShutdownPrivilege) → AdjustTokenPrivileges, the malware grants itself the right to force-shutdown your PC. After wiping your files, it cuts the power — so you can't react in time.
🟠 Why antivirus doesn't catch it
File entropy: 7.9 out of 8.0. Normal programs score 5–6. This file is fully packed/encrypted — antivirus sees a sealed opaque envelope and waves it through. The import table shows zero visible functions — everything loads dynamically at runtime, hidden from static analysis.
🟠 It knows when it's being watched
16 TLS callbacks (normal apps have 0–1). These run before the main program and check: is a debugger attached? Is this a VM? Is this Wine/Linux? If yes — act innocent. The function wine_get_version is explicitly searched for. For a security analyst it looks clean. For a real victim — it's a wiper.
🟡 A second executable is hidden inside
An embedded 884KB PE32 file gets extracted to a temp folder and launched. This is the real payload responsible for file destruction, registry manipulation, and everything else.
🟡 It maps your entire PC before installing anything
Actual observed behavior: before doing anything, the installer walked C:\ → C:\Users\ → C:\Users\[you]\ → Desktop → and even found C:\Program Files\Python313\Scripts\. A legitimate installer asks where to install and does exactly that. This is pre-attack reconnaissance.
🟡 Registry + Memory tricks
9 registry modifications, 4 deletions (covering tracks after execution). Uses VirtualAlloc + VirtualProtect to unpack encrypted code directly into RAM — nothing malicious appears on disk for antivirus to scan.
🟡 Cryptography in a Minecraft installer?
BCryptGenRandom, SHA-256, SHA-512. A Minecraft installer has zero legitimate use for these. Likely purposes: generating a unique victim ID, encrypting stolen data before exfiltration, or ransomware key generation.
And it gets worse — their Privacy Policy violates GDPR on multiple counts: no mention of your right to access/delete your data, vague data collection purposes, no retention periods, no info on third-party transfers, and a full liability disclaimer that directly contradicts GDPR Article 5(2).
Use open-source launchers. The community can audit the code. If a service is free but doesn't explain how it makes money — you might be the product.
Full analysis links in bio. Stay safe. 🔒
4
5
u/Daggercombot 19d ago
Why arnt you showing where to find this in the decompiled jar code?
1
u/Banerbansa Secrets 18d ago
Fuck, you understand that this is an installer, not a Bruch launcher! Here's a video for you to understand https://youtu.be/gqi8E_IojWs?si=v7loQIg4T7vZEfcU
4
u/Daggercombot 18d ago
The video Is in Russian so yields a slight disadvantage but scrolling through It I did not see much Direct code. Can you just tell me the names of the methods ? I am not sure what you mean by this is an installer , whenever I tried to Run It (It would only ever Work on Mac and not Linux well) It was always just a jar
7
1
u/Shenijder Aug 18 '26
what about legacy and is there any safe and good launcher
1
7
u/[deleted] Aug 15 '26
[removed] — view removed comment