Crypto Theft Hides In Plain Sight Inside Popular Game Mods—Kaspersky

bitcoinist发布于2025-12-23更新于2025-12-23

文章摘要

Kaspersky warns of a new infostealer malware called "Stealka" distributed through fake video game mods and cracked software, primarily targeting Windows users. Disguised as cheats or utility cracks for popular titles like Roblox or Microsoft Visio, the malware is hosted on platforms like GitHub and Google Sites to appear legitimate. Once executed, Stealka steals browser data, saved passwords, and cryptocurrency wallet information—targeting over 115 browser extensions including MetaMask, Binance Wallet, and Coinbase. It collects private keys, seed phrases, and autofill data, enabling account takeovers and further malicious spread. Detected initially in Russia, Turkey, Brazil, Germany, and India, the malware is sometimes bundled with cryptomining code. Users are advised to avoid unofficial software, use antivirus tools, enable two-factor authentication, and verify file checksums before installation.

Kaspersky has warned that a new infostealer called “Stealka” is being spread through bogus video game mods and cracked software, putting crypto users and gamers at risk.

The malware was identified in November 2025 and is delivered as what looks like harmless game add-ons or utility cracks. Systems running Windows are the main target.

Attackers Hide Malware In Mods

Reports have disclosed that Stealka is disguised as cheats, mods and cracks for popular titles, with fake packages posted to places users normally trust. Files have been seen on GitHub, SourceForge, Softpedia and Google Sites, which helps the downloads look legitimate.

In some cases, the malware was packaged as a Roblox mod or as a cracked copy of Microsoft Visio. According to Kaspersky, the campaign uses convincing websites and may employ automated tools to create professional pages that trick people into clicking download links.

Data And Wallets Targeted

Once run, Stealka searches for browser data, saved passwords and crypto wallet information. Based on reports, it targets more than 115 browser extensions tied to wallets, password managers and two-factor apps.

Extensions for MetaMask, Binance Wallet, Coinbase and other popular wallets are among those at risk. Private keys, seed phrases and wallet file paths can be exposed on an infected machine, and stored browser cards and autofill entries are also collected.

Total crypto market cap currently at $3.01 trillion. Chart: TradingView

Victims’ accounts can be taken over using the stolen credentials, and that access can then be used to push further malicious links to friends or followers.

How The Threat Spreads And Where It’s Seen

Kaspersky’s telemetry shows initial detections in Russia, with additional cases reported in Turkey, Brazil, Germany and India.

Distribution methods vary. Sometimes a single download bundle carries Stealka; other times it is paired with cryptominer code so infected computers also mine cryptocurrency for the attackers.

Files hosted on trusted developer portals make it harder for users to spot danger, and the malware’s wide reach means standard precautions can still be bypassed if users ignore basic safety steps.

Recommendations For Users

According to cybersecurity advisories, avoid unofficial or pirated software and only download mods from verified, trusted creators. Use a reputable antivirus product and keep it updated.

Password managers are recommended over saving credentials in browsers, and two-factor authentication should be enabled for crypto accounts when available.

Keep Windows and applications patched, and check that a downloaded file’s checksum or digital signature matches the developer’s published value before running installers.

Featured image from Kaspersky, chart from TradingView

热门币种推荐

相关问答

QWhat is the name of the new infostealer malware being spread through fake game mods and cracked software?

AThe new infostealer malware is called 'Stealka'.

QWhich operating systems are the primary target of the Stealka malware?

ASystems running Windows are the main target of the Stealka malware.

QWhat types of sensitive information does the Stealka malware steal from infected computers?

AStealka steals browser data, saved passwords, crypto wallet information, private keys, seed phrases, wallet file paths, stored browser cards, and autofill entries.

QName at least two trusted online platforms where the fake packages containing the malware were found.

AFake packages containing the malware were found on GitHub, SourceForge, Softpedia, and Google Sites.

QWhat are two key security recommendations provided to protect against this threat?

ATwo key recommendations are to avoid unofficial or pirated software and to use a reputable, updated antivirus product. Additionally, using password managers and enabling two-factor authentication for crypto accounts is advised.

你可能也喜欢

«我们回来了»:Saylor给了比特币购买策略恢复的希望

Strategy公司首席执行官迈克尔·塞勒在社交媒体X上发布了简短短语“We're Back”,市场解读为暗示该公司在为期两个月的暂停后,将恢复购买比特币。此前暂停旨在加强公司资产负债表。 观察人士认为,此帖可能是一个强烈的心理信号:塞勒有一系列在周末发布的隐晦帖子,往往预示着周一正式宣布购买比特币。如果模式延续,这暗示在经历了明显的夏季中断后,比特币积累活动将恢复。 过去两个月,Strategy暂停了其常规的每周比特币购买,转而专注于稳固资产负债表,包括稳定优先股发行、积累51亿美元现金储备以及通过大规模普通股发行形成15.9亿美元独立资金池。这段战略暂停期恰逢市场艰难时期,但近期比特币价格突破8万美元,使公司的持仓重返盈利状态。 Strategy持有超过840,447枚比特币,平均购买价格约为每枚75,385美元。随着价格上涨,其总持仓多月来首次转为盈利。 从数据分析角度看,“We're Back”的声明应结合更广泛的背景来看。几个月前,塞勒曾公开提及出售比特币的可能性,打破了五年来的“永不卖出”立场,夏季公司也确实出售了部分比特币以支持优先股股息。因此,当前转向购买可能并非年内首次立场转变,而是其储备管理政策比通常认为的更具灵活性。这种模式也引发了对其融资机制可持续性的疑问,因为其购买通常依赖于发行股票和优先证券,而非仅靠自由现金流。

cryptonews.ru39分钟前

«我们回来了»:Saylor给了比特币购买策略恢复的希望

cryptonews.ru39分钟前

交易

现货

热门文章

什么是 SHEIN

公司成立于 2008 年,是全球顶尖的跨境快时尚与在线零售巨头。公司以“按需生产”的敏捷柔性供应链为核心优势,业务覆盖女装、男装、童装、美妆及家居等多元品类,通过自营线上独立站及移动端 App 销往全球 150 多个国家和地区,在欧美等主流消费市场拥有极高的品牌认知度与用户黏性。

257人学过发布于 2026.08.28更新于 2026.08.28

什么是 SHEIN

如何购买SHEIN

欢迎来到HTX.com!我们已经让购买希音(SHEIN)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买希音(SHEIN)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的希音(SHEIN)购买完您的希音(SHEIN)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易希音(SHEIN)在HTX的现货市场轻松交易希音(SHEIN)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

223人学过发布于 2026.08.28更新于 2026.08.28

如何购买SHEIN

火币HTX大咖讲堂 · 美股投资入门系列:指数、板块与基本面分析

欢迎来到第六期课程。今天我们将学习如何看懂美股的“地图”和“价值”。我们会了解代表市场整体的三大指数,构成市场的各个行业板块,以及最核心的基本面分析方法。掌握这些工具,能帮助我们从宏观到微观,建立起一套完整的分析框架。

171人学过发布于 2026.08.28更新于 2026.08.28

火币HTX大咖讲堂 · 美股投资入门系列:指数、板块与基本面分析

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对A(A)币价的意见。

活动图片