Crypto Theft Hides In Plain Sight Inside Popular Game Mods—Kaspersky

bitcoinist发布于2025-12-23更新于2025-12-23

文章摘要

Kaspersky warns of a new infostealer malware called "Stealka" distributed through fake video game mods and cracked software, primarily targeting Windows users. Disguised as cheats or utility cracks for popular titles like Roblox or Microsoft Visio, the malware is hosted on platforms like GitHub and Google Sites to appear legitimate. Once executed, Stealka steals browser data, saved passwords, and cryptocurrency wallet information—targeting over 115 browser extensions including MetaMask, Binance Wallet, and Coinbase. It collects private keys, seed phrases, and autofill data, enabling account takeovers and further malicious spread. Detected initially in Russia, Turkey, Brazil, Germany, and India, the malware is sometimes bundled with cryptomining code. Users are advised to avoid unofficial software, use antivirus tools, enable two-factor authentication, and verify file checksums before installation.

Kaspersky has warned that a new infostealer called “Stealka” is being spread through bogus video game mods and cracked software, putting crypto users and gamers at risk.

The malware was identified in November 2025 and is delivered as what looks like harmless game add-ons or utility cracks. Systems running Windows are the main target.

Attackers Hide Malware In Mods

Reports have disclosed that Stealka is disguised as cheats, mods and cracks for popular titles, with fake packages posted to places users normally trust. Files have been seen on GitHub, SourceForge, Softpedia and Google Sites, which helps the downloads look legitimate.

In some cases, the malware was packaged as a Roblox mod or as a cracked copy of Microsoft Visio. According to Kaspersky, the campaign uses convincing websites and may employ automated tools to create professional pages that trick people into clicking download links.

Data And Wallets Targeted

Once run, Stealka searches for browser data, saved passwords and crypto wallet information. Based on reports, it targets more than 115 browser extensions tied to wallets, password managers and two-factor apps.

Extensions for MetaMask, Binance Wallet, Coinbase and other popular wallets are among those at risk. Private keys, seed phrases and wallet file paths can be exposed on an infected machine, and stored browser cards and autofill entries are also collected.

Total crypto market cap currently at $3.01 trillion. Chart: TradingView

Victims’ accounts can be taken over using the stolen credentials, and that access can then be used to push further malicious links to friends or followers.

How The Threat Spreads And Where It’s Seen

Kaspersky’s telemetry shows initial detections in Russia, with additional cases reported in Turkey, Brazil, Germany and India.

Distribution methods vary. Sometimes a single download bundle carries Stealka; other times it is paired with cryptominer code so infected computers also mine cryptocurrency for the attackers.

Files hosted on trusted developer portals make it harder for users to spot danger, and the malware’s wide reach means standard precautions can still be bypassed if users ignore basic safety steps.

Recommendations For Users

According to cybersecurity advisories, avoid unofficial or pirated software and only download mods from verified, trusted creators. Use a reputable antivirus product and keep it updated.

Password managers are recommended over saving credentials in browsers, and two-factor authentication should be enabled for crypto accounts when available.

Keep Windows and applications patched, and check that a downloaded file’s checksum or digital signature matches the developer’s published value before running installers.

Featured image from Kaspersky, chart from TradingView

热门币种推荐

相关问答

QWhat is the name of the new infostealer malware being spread through fake game mods and cracked software?

AThe new infostealer malware is called 'Stealka'.

QWhich operating systems are the primary target of the Stealka malware?

ASystems running Windows are the main target of the Stealka malware.

QWhat types of sensitive information does the Stealka malware steal from infected computers?

AStealka steals browser data, saved passwords, crypto wallet information, private keys, seed phrases, wallet file paths, stored browser cards, and autofill entries.

QName at least two trusted online platforms where the fake packages containing the malware were found.

AFake packages containing the malware were found on GitHub, SourceForge, Softpedia, and Google Sites.

QWhat are two key security recommendations provided to protect against this threat?

ATwo key recommendations are to avoid unofficial or pirated software and to use a reputable, updated antivirus product. Additionally, using password managers and enabling two-factor authentication for crypto accounts is advised.

你可能也喜欢

印度最大资管 SBI 上市,交易数据能看出什么信号?

印度最大资管公司SBI Funds Management于7月21日上市,完成约10亿美元发行,获得约42倍认购,但首日收盘价仅较发行价上涨约6.3%。这组交易数据释放出复杂信号:一方面,强劲的认购倍数验证了印度市场对大体量优质资产的需求依然存在;另一方面,温和的首日涨幅(远低于上市前灰市约16%的溢价预期)表明,市场虽有买盘,但拒绝无条件追高,定价趋于理性。 此次IPO被视为印度IPO市场的一个关键“价格锚”和风向标。其成功意味着IPO窗口正在重新打开,但窗口优先面向那些品牌力强、现金流稳定、能清晰阐述长期增长逻辑的公司(如后续可能推进的NSE、Reliance Jio等项目)。SBI的案例显示,强资产可以发行,大资金愿意承接,但估值不能仅依赖稀缺性和故事。 另一个值得关注的变量是极低的承销费率(据报道约0.01%),这导致部分国际大行退出。这并非“华尔街看空印度”,而是反映了如SBI这类强势发行人议价能力的提升。它们倚重自身品牌、母行渠道和本土分销网络,降低了对外部投行销售的依赖。本土券商则更愿意以较低费用换取项目资源。但这种低费率模式若被弱势发行人复制,可能带来定价质量下降等风险。 SBI的高认购得益于印度资管行业渗透率提升的长期叙事,但其温和涨幅也提醒市场,行业增长虽稳定(年复合增长率预计16%-18%),但仍受股市表现、利率环境等多因素影响,投资者不愿提前支付过高溢价。 总之,SBI的上市标志着印度IPO市场有条件重启。其真正意义将在后续大型项目(如Jio、NSE)的推进中得到检验:它们能否在合理估值下成功发行,将决定当前市场信心的成色,以及发行人议价权上升是否是结构性趋势。

marsbit12分钟前

印度最大资管 SBI 上市,交易数据能看出什么信号?

marsbit12分钟前

交易

现货

热门文章

如何购买DATA

欢迎来到HTX.com!我们已经让购买DATA Network(DATA)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买DATA Network(DATA)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的DATA Network(DATA)购买完您的DATA Network(DATA)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易DATA Network(DATA)在HTX的现货市场轻松交易DATA Network(DATA)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

291人学过发布于 2026.07.01更新于 2026.07.01

如何购买DATA

什么是 ANSEM

I. 项目介绍The Black Bull($ANSEM)是 Solana 区块链上一个透明、社区驱动的迷因币(Memecoin),其核心精神只有一个:无论如何,一往无前。该项目采用“前端优先”的模式且完全可验证——其官方网站直接读取 Solana 的链上实时数据和市场指标,包括价格、流动性、交易量、市值以及持币者分布,因此任何人无需登录、无需被收集个人数据即可审计这些信息。除了代币本身,该项目还提供 Ansem 喊单雷达(Ansem-call Radar)、PumpSwap 上的非托管社区流动性池(Pods),以及一个基于浏览器的迷因终端。$ANSEM 是一个标准的 Pump.fun SPL 代币(6 位小数),目前可与 SOL 和 USDC 进行交易。II.代币基本信息代币符号:ANSEM(The Black Bull)III. 相关链接官网:https://www.blackbullsol.com/推特:https://x.com/blknoiz06合约地址:https://solscan.io/token/9cRCn9rGT8V2imeM2BaKs13yhMEais3ruM3rPvTGpump注意:项目简介来自于官方项目团队所发布或提供的的信息资料,可能存在过时、错误或遗漏,相关内容仅供参考且不构成投资建议,HTX不会承担任何依赖这些信息而产生的直接或间接损失。

750人学过发布于 2026.07.01更新于 2026.07.01

什么是 ANSEM

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对A(A)币价的意见。

活动图片