Crypto Theft Hides In Plain Sight Inside Popular Game Mods—Kaspersky

bitcoinist发布于2025-12-23更新于2025-12-23

文章摘要

Kaspersky warns of a new infostealer malware called "Stealka" distributed through fake video game mods and cracked software, primarily targeting Windows users. Disguised as cheats or utility cracks for popular titles like Roblox or Microsoft Visio, the malware is hosted on platforms like GitHub and Google Sites to appear legitimate. Once executed, Stealka steals browser data, saved passwords, and cryptocurrency wallet information—targeting over 115 browser extensions including MetaMask, Binance Wallet, and Coinbase. It collects private keys, seed phrases, and autofill data, enabling account takeovers and further malicious spread. Detected initially in Russia, Turkey, Brazil, Germany, and India, the malware is sometimes bundled with cryptomining code. Users are advised to avoid unofficial software, use antivirus tools, enable two-factor authentication, and verify file checksums before installation.

Kaspersky has warned that a new infostealer called “Stealka” is being spread through bogus video game mods and cracked software, putting crypto users and gamers at risk.

The malware was identified in November 2025 and is delivered as what looks like harmless game add-ons or utility cracks. Systems running Windows are the main target.

Attackers Hide Malware In Mods

Reports have disclosed that Stealka is disguised as cheats, mods and cracks for popular titles, with fake packages posted to places users normally trust. Files have been seen on GitHub, SourceForge, Softpedia and Google Sites, which helps the downloads look legitimate.

In some cases, the malware was packaged as a Roblox mod or as a cracked copy of Microsoft Visio. According to Kaspersky, the campaign uses convincing websites and may employ automated tools to create professional pages that trick people into clicking download links.

Data And Wallets Targeted

Once run, Stealka searches for browser data, saved passwords and crypto wallet information. Based on reports, it targets more than 115 browser extensions tied to wallets, password managers and two-factor apps.

Extensions for MetaMask, Binance Wallet, Coinbase and other popular wallets are among those at risk. Private keys, seed phrases and wallet file paths can be exposed on an infected machine, and stored browser cards and autofill entries are also collected.

Total crypto market cap currently at $3.01 trillion. Chart: TradingView

Victims’ accounts can be taken over using the stolen credentials, and that access can then be used to push further malicious links to friends or followers.

How The Threat Spreads And Where It’s Seen

Kaspersky’s telemetry shows initial detections in Russia, with additional cases reported in Turkey, Brazil, Germany and India.

Distribution methods vary. Sometimes a single download bundle carries Stealka; other times it is paired with cryptominer code so infected computers also mine cryptocurrency for the attackers.

Files hosted on trusted developer portals make it harder for users to spot danger, and the malware’s wide reach means standard precautions can still be bypassed if users ignore basic safety steps.

Recommendations For Users

According to cybersecurity advisories, avoid unofficial or pirated software and only download mods from verified, trusted creators. Use a reputable antivirus product and keep it updated.

Password managers are recommended over saving credentials in browsers, and two-factor authentication should be enabled for crypto accounts when available.

Keep Windows and applications patched, and check that a downloaded file’s checksum or digital signature matches the developer’s published value before running installers.

Featured image from Kaspersky, chart from TradingView

相关问答

QWhat is the name of the new infostealer malware being spread through fake game mods and cracked software?

AThe new infostealer malware is called 'Stealka'.

QWhich operating systems are the primary target of the Stealka malware?

ASystems running Windows are the main target of the Stealka malware.

QWhat types of sensitive information does the Stealka malware steal from infected computers?

AStealka steals browser data, saved passwords, crypto wallet information, private keys, seed phrases, wallet file paths, stored browser cards, and autofill entries.

QName at least two trusted online platforms where the fake packages containing the malware were found.

AFake packages containing the malware were found on GitHub, SourceForge, Softpedia, and Google Sites.

QWhat are two key security recommendations provided to protect against this threat?

ATwo key recommendations are to avoid unofficial or pirated software and to use a reputable, updated antivirus product. Additionally, using password managers and enabling two-factor authentication for crypto accounts is advised.

你可能也喜欢

解读大航海时代投资机遇,景顺长城基金发布《2026年中国企业出海报告》

景顺长城基金发布《2026年中国企业出海报告》,指出在当前全球产业链重构背景下,“出海”已成为中国企业的“必选项”和新增长引擎。报告认为,出海行情并非昙花一现,而是可能持续影响A股投资的长期趋势。 报告分析了中国企业出海的版本迭代:从早期赚取加工费的“产品出口”(出海1.0),演进至当前包含产能、经营能力及服务输出的“出海2.0”。后者具体体现在资本品投资高增长、消费品品牌拓展、服务业(如创新药BD、大模型Token)加速出海以及供应链深度嵌入全球AI产业链。 中国企业出海的底气源于多重系统性优势:庞大的工程师红利、完善且低成本的基础设施以及完整的产业链集群效应。这些优势在光模块、创新药等行业已转化为全球竞争力。 针对具体投资机遇,报告重点提及: 1. **资本品**:如工程机械、电力设备(变压器、电网配电设备等),凭借成本与服务优势,正快速进入“一带一路”及全球市场。 2. **科技与高端制造**:新能源车需注重海外本地化;AI应用(大模型、云服务等)及光模块企业展现出非线性增长潜力。 3. **消费与医药**:消费品牌正从“链价比”优势转向品牌溢价;创新药在肿瘤、减重等大适应症领域孕育着巨大的市场机会。 报告也指出,出海之路面临地缘政治、合规、文化等多重挑战,成功的企业需具备前置合规、本地化运营及构建海外核心能力等关键素质。

marsbit6分钟前

解读大航海时代投资机遇,景顺长城基金发布《2026年中国企业出海报告》

marsbit6分钟前

GitHub,被 AI 打穿了

2026年2月9日,GitHub发生大规模服务中断,核心数据库集群因“缓存重写风暴”过载,导致网站、API、Actions及Copilot等服务瘫痪。事故根源是一个配置改动(缓存刷新时间从12小时改为2小时),但背后是平台面临的结构性挑战。 2026年前三个月,GitHub发生至少8次重大事故,故障原因各异但相互关联。深层原因是AI Agent的爆发式使用导致负载性质剧变。数据显示,2026年单周代码提交量达2.75亿次,按此推算全年将达140亿次,是2025年的14倍。AI贡献的提交量和PR数量在数月内增长数十倍。这些不眠不休的AI“用户”以远超人类的速率提交代码、创建仓库,使GitHub的负载模式从可预测的人类节奏转变为持续高压的自动化洪流。 同时,AI Agent(尤其是Agentic工作流)消耗的计算资源远超预期,使GitHub基于座位的Copilot订阅模式严重亏损。GitHub不得不实施限流,并于6月1日全面转向按用量计费。 为应对挑战,GitHub宣布需按当前规模的30倍重新设计架构,而非简单扩容,重点包括解耦服务、增强故障隔离、改进流量管控等。行业如Stripe、AWS也面临类似问题。 本质上,GitHub正从“人类协作平台”转变为“AI工作流的输出管道”。这不仅是基础设施的压力测试,也引发对其商业模式和核心身份的重塑。频繁的事故报告和高透明度,是平台在重建过程中争取社区耐心的方式。这次停机事件标志着软件开发在AI时代的一次深刻转折。

marsbit46分钟前

GitHub,被 AI 打穿了

marsbit46分钟前

交易

现货
合约

热门文章

如何购买AMAT

欢迎来到HTX.com!我们已经让购买Applied Materials, Inc.(AMAT)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Applied Materials, Inc.(AMAT)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Applied Materials, Inc.(AMAT)购买完您的Applied Materials, Inc.(AMAT)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Applied Materials, Inc.(AMAT)在HTX的现货市场轻松交易Applied Materials, Inc.(AMAT)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

134人学过发布于 2026.06.03更新于 2026.06.03

如何购买AMAT

什么是 BBX

BBX,黑莓(BlackBerry Limited,股票代码:BB)是一家总部位于加拿大的软件公司,于纽交所、多伦多证券交易所双重上市,专注于网络安全和物联网(IoT)领域。公司已从手机制造商成功转型为安全软件服务商,其QNX操作系统在智能汽车和工业领域占据领先地位,是全球关键数字基础设施安全方案的重要供应商。

72人学过发布于 2026.06.03更新于 2026.06.03

什么是 BBX

如何购买BBX

欢迎来到HTX.com!我们已经让购买黑莓(BBX)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买黑莓(BBX)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的黑莓(BBX)购买完您的黑莓(BBX)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易黑莓(BBX)在HTX的现货市场轻松交易黑莓(BBX)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

63人学过发布于 2026.06.03更新于 2026.06.03

如何购买BBX

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对A(A)币价的意见。

活动图片