Video game mods are spreading new ‘Stealka’ crypto infostealer: Kaspersky

cointelegraphPublicado em 2025-12-22Última atualização em 2025-12-22

Resumo

A new malware called "Stealka" is targeting cryptocurrency wallets and browser extensions by disguising itself as video game cheats, mods, and software cracks, according to Kaspersky. The infostealer, discovered in November, is distributed through legitimate platforms like GitHub and Google Sites, and sometimes via fake professional-looking websites. It primarily targets Chromium and Gecko-based browsers—including Chrome, Firefox, and Edge—and steals autofill data, login credentials, and payment details. It also specifically targets 115 browser extensions related to crypto wallets, 2FA services, and password managers, including Binance, MetaMask, Trust Wallet, and Coinbase. Kaspersky advises using reliable antivirus software, avoiding pirated software and unofficial mods, and refraining from storing passwords in browsers.

New malware has been discovered that targets crypto wallets and browser extensions while disguising itself as game cheats and mods, says cybersecurity firm Kaspersky.

Kaspersky reported on Thursday that it had uncovered a new infostealer dubbed “Stealka,” which targets Microsoft Windows user data.

Attackers have used the malware, which was discovered in November, to hijack accounts, steal cryptocurrency, and install crypto miners on their victims’ computers while masquerading as video game cracks, cheats, and mods.

The malicious software has been distributed through legitimate platforms like GitHub, SourceForge, and Google Sites, and disguised as game mods, especially for Roblox, and software cracks for applications such as Microsoft Visio.

Sometimes, attackers go a step further, possibly using artificial intelligence tools, and creating entire fake websites that look “quite professional,” said Kaspersky researcher Artem Ushkov.

A fake website pretending to offer Roblox scripts, Source: Kaspersky

Crypto wallets and extensions targeted

Ushkov noted that Stealka has a fairly “extensive arsenal of capabilities,” but is particularly dangerous because its prime target is data from browsers built on the Chromium and Gecko engines.

This puts over 100 different browsers at risk, including popular ones such as Chrome, Firefox, Opera, Yandex, Edge, Brave, and many others.

Related: Hackers are exploiting a JavaScript library to plant crypto drainers

Its primary targets are autofill data, such as sign-in credentials, addresses, and payment card details, but it also targets the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA (two-factor authentication) services.

Some of the 80 crypto wallets targeted include Binance, Coinbase, Crypto.com, SafePal, Trust Wallet, MetaMask, Ton, Phantom, Nexus, and Exodus.

Kaspersky also said the messaging apps, including Discord, Telegram, Unigram, Pidgin, and Tox, were also at risk, as were email clients, password managers, gaming clients, and even VPN applications.

Avoid pirated software and game mods

To stay protected, Kaspersky recommended using reliable antivirus software and password managers to avoid storing passwords in browsers. It also cautioned against using pirated software and unofficial game mods.

Cloudflare reported last week that more than 5% of all emails sent worldwide contain malicious content, and more than half of those contained a phishing link, while a quarter of all HTML attachments were found to be malicious.

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

Perguntas relacionadas

QWhat is the name of the new infostealer malware discovered by Kaspersky and what does it target?

AThe new infostealer is called 'Stealka'. It primarily targets data from browsers built on Chromium and Gecko engines, including autofill data (sign-in credentials, addresses, payment card details), and the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA services.

QHow is the Stealka malware being distributed to potential victims?

AThe malware is distributed by disguising itself as video game cracks, cheats, and mods. It has been spread through legitimate platforms like GitHub, SourceForge, and Google Sites. Attackers sometimes create entire fake, professional-looking websites to host the malicious software.

QWhich specific types of applications and services are at risk from the Stealka infostealer?

AOver 100 different browsers (Chrome, Firefox, Opera, etc.), 80 crypto wallets (Binance, Coinbase, MetaMask, etc.), messaging apps (Discord, Telegram, etc.), email clients, password managers, gaming clients, and VPN applications are all at risk.

QWhat recommendations does Kaspersky provide to protect against this threat?

AKaspersky recommends using reliable antivirus software, using password managers instead of storing passwords in browsers, and avoiding the use of pirated software and unofficial game mods.

QBeyond game mods, what other type of software is commonly used as a disguise for this malware?

AThe malware is also disguised as software cracks for applications such as Microsoft Visio.

Leituras Relacionadas

Behind HYPE's Repeated Record Highs, the 'Minions' in the Ecosystem Can't Keep Up

While HYPE, the native token of the Hyperliquid ecosystem, surges to new all-time highs above $76 and attracts significant institutional ETF inflows, a starkly different reality unfolds within its HyperEVM application layer. Multiple core DeFi protocols across lending, NFTs, stablecoins, and DEXs have announced shutdowns between May and June. The article argues HYPE functions more like an "application stock" than a traditional ecosystem token. Its value is anchored to the trading fees from Hyperliquid's core perpetual contracts platform (HyperCore), which boasts a diversified revenue stream from crypto, commodities, and indices. Approximately 97% of protocol fees fund buybacks and burns of HYPE. This means HYPE's price is largely decoupled from the health of projects built on HyperEVM. The closures of significant projects like lending protocol HypurrFi (peak TVL >$300M) and NFT marketplace Drip.Trade highlight a structural tension. Hyperliquid's minimalist philosophy offers infrastructure without official grants, liquidity support, or marketing coordination for HyperEVM projects. This forces protocols into a fiercely competitive environment from day one. Furthermore, the success of HyperCore creates a liquidity vacuum, and mechanisms like HIP-3 (allowing direct perpetual market deployment) divert user attention and capital away from application-layer projects. The stronger the core perpetual trading business becomes, the more difficult it is for peripheral "DeFi lego" projects to survive and capture value, despite the flagship token's rising price.

Foresight NewsHá 41m

Behind HYPE's Repeated Record Highs, the 'Minions' in the Ecosystem Can't Keep Up

Foresight NewsHá 41m

Conversation with Arthur Hayes: AI Has Drained Market Liquidity, BTC Will Be Below 100k by Year-End

In this June 2026 podcast interview, BitMEX co-founder Arthur Hayes explains his decision to sell his major crypto holdings (HYPE, NEAR, Worldcoin, Zcash). His rationale is based on a macro view linking oil prices, the Iran conflict, US politics, and an impending AI bubble burst. Hayes argues that high oil prices, driven by the ongoing war, will pressure domestic US inflation. To salvage the Republican Party's chances in the midterm elections, he believes Donald Trump may pivot to a populist, anti-AI stance—advocating for taxes and regulation—which would deflate the AI investment narrative. He sees the AI sector, particularly massive capital expenditure on data centers, as having absorbed nearly all excess market liquidity (around $1.5 trillion in debt issuance since 2025), starving other assets like Bitcoin. He highlights the upcoming SpaceX IPO at a ~$1.8 trillion valuation and 100x price-to-sales ratio as a potential tipping point. If these hyped IPOs underperform, it could shatter market confidence in AI. In such a scenario, all risk assets, including crypto, would fall together as correlations converge to 1 during a broad correction. Hayes has moved his portfolio into Treasuries and energy stocks (like ExxonMobil), predicting Bitcoin will be below $100k by year-end. He sees a potential crypto bull market only after the AI frenzy cools, liquidity stops flowing exclusively into AI, and possibly after a significant market downturn prompts new monetary stimulus.

marsbitHá 52m

Conversation with Arthur Hayes: AI Has Drained Market Liquidity, BTC Will Be Below 100k by Year-End

marsbitHá 52m

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

U.S. Federal Reserve officials who previously advocated for rate cuts, including Governor Christopher Waller, have recently shifted their stance, with many now not ruling out the possibility of future rate hikes. This sets a challenging stage for new Fed Chair Kevin Warsh's first policy meeting. Appointed by President Trump based on his dovish views, Warsh now faces a committee where the debate has pivoted from "when to cut" to "whether to hike," driven by persistent inflation above 3%, a strong labor market, and supply-side pressures from AI infrastructure demands and geopolitical tensions. Key figures illustrate the shift. Governor Waller, once concerned about employment, now says data has pushed him toward considering rate increases. Even moderate voices like Governor Lisa Cook, while expecting inflation to ease, have indicated readiness to hike if it fails to do so. Long-time hawks such as regional Fed presidents Beth Hammack, Lorie Logan, and Neel Kashkari have grown more vocal, arguing that the real policy rate is effectively falling and that action may soon be needed. The upcoming Fed meeting is expected to keep rates steady but will likely remove the "easing bias" from its statement, signaling a neutral stance between cuts and hikes. The quarterly "dot plot" is anticipated to show most officials projecting no cuts this year, with some potentially indicating hikes. Chair Warsh, a critic of the Fed's reliance on forward guidance like the dot plot, must navigate communicating this pivot using tools he has questioned, all while steering policy in a direction counter to the preferences of the president who appointed him. The consensus suggests the Fed's next move could well be a rate increase.

marsbitHá 1h

Fed's Internal Doves Flock to Hawkish Stance, Warsh's Debut "Between a Rock and a Hard Place"

marsbitHá 1h

Trading

Spot
Futuros
活动图片