Video game mods are spreading new ‘Stealka’ crypto infostealer: Kaspersky

cointelegraph发布于2025-12-22更新于2025-12-22

文章摘要

A new malware called "Stealka" is targeting cryptocurrency wallets and browser extensions by disguising itself as video game cheats, mods, and software cracks, according to Kaspersky. The infostealer, discovered in November, is distributed through legitimate platforms like GitHub and Google Sites, and sometimes via fake professional-looking websites. It primarily targets Chromium and Gecko-based browsers—including Chrome, Firefox, and Edge—and steals autofill data, login credentials, and payment details. It also specifically targets 115 browser extensions related to crypto wallets, 2FA services, and password managers, including Binance, MetaMask, Trust Wallet, and Coinbase. Kaspersky advises using reliable antivirus software, avoiding pirated software and unofficial mods, and refraining from storing passwords in browsers.

New malware has been discovered that targets crypto wallets and browser extensions while disguising itself as game cheats and mods, says cybersecurity firm Kaspersky.

Kaspersky reported on Thursday that it had uncovered a new infostealer dubbed “Stealka,” which targets Microsoft Windows user data.

Attackers have used the malware, which was discovered in November, to hijack accounts, steal cryptocurrency, and install crypto miners on their victims’ computers while masquerading as video game cracks, cheats, and mods.

The malicious software has been distributed through legitimate platforms like GitHub, SourceForge, and Google Sites, and disguised as game mods, especially for Roblox, and software cracks for applications such as Microsoft Visio.

Sometimes, attackers go a step further, possibly using artificial intelligence tools, and creating entire fake websites that look “quite professional,” said Kaspersky researcher Artem Ushkov.

A fake website pretending to offer Roblox scripts, Source: Kaspersky

Crypto wallets and extensions targeted

Ushkov noted that Stealka has a fairly “extensive arsenal of capabilities,” but is particularly dangerous because its prime target is data from browsers built on the Chromium and Gecko engines.

This puts over 100 different browsers at risk, including popular ones such as Chrome, Firefox, Opera, Yandex, Edge, Brave, and many others.

Related: Hackers are exploiting a JavaScript library to plant crypto drainers

Its primary targets are autofill data, such as sign-in credentials, addresses, and payment card details, but it also targets the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA (two-factor authentication) services.

Some of the 80 crypto wallets targeted include Binance, Coinbase, Crypto.com, SafePal, Trust Wallet, MetaMask, Ton, Phantom, Nexus, and Exodus.

Kaspersky also said the messaging apps, including Discord, Telegram, Unigram, Pidgin, and Tox, were also at risk, as were email clients, password managers, gaming clients, and even VPN applications.

Avoid pirated software and game mods

To stay protected, Kaspersky recommended using reliable antivirus software and password managers to avoid storing passwords in browsers. It also cautioned against using pirated software and unofficial game mods.

Cloudflare reported last week that more than 5% of all emails sent worldwide contain malicious content, and more than half of those contained a phishing link, while a quarter of all HTML attachments were found to be malicious.

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

相关问答

QWhat is the name of the new infostealer malware discovered by Kaspersky and what does it target?

AThe new infostealer is called 'Stealka'. It primarily targets data from browsers built on Chromium and Gecko engines, including autofill data (sign-in credentials, addresses, payment card details), and the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA services.

QHow is the Stealka malware being distributed to potential victims?

AThe malware is distributed by disguising itself as video game cracks, cheats, and mods. It has been spread through legitimate platforms like GitHub, SourceForge, and Google Sites. Attackers sometimes create entire fake, professional-looking websites to host the malicious software.

QWhich specific types of applications and services are at risk from the Stealka infostealer?

AOver 100 different browsers (Chrome, Firefox, Opera, etc.), 80 crypto wallets (Binance, Coinbase, MetaMask, etc.), messaging apps (Discord, Telegram, etc.), email clients, password managers, gaming clients, and VPN applications are all at risk.

QWhat recommendations does Kaspersky provide to protect against this threat?

AKaspersky recommends using reliable antivirus software, using password managers instead of storing passwords in browsers, and avoiding the use of pirated software and unofficial game mods.

QBeyond game mods, what other type of software is commonly used as a disguise for this malware?

AThe malware is also disguised as software cracks for applications such as Microsoft Visio.

你可能也喜欢

助记词:12个词,介于你与失去一切之间的鸿沟

种子短语,通常由12或24个标准字典中的单词组成,并非打开远程资金账户的登录凭证,它本身就是数字钱包的数学体现。通过BIP39标准算法,这些单词可转换为主私钥,并派生出所有关联的比特币地址。没有备份数据库或客服能帮助恢复它,谁掌握了这些词,谁就完全控制了所有资产。 一月的盗窃案正是因此发生,并非利用技术漏洞,而是通过社会工程学手段——诱骗受害者在错误位置输入了12个单词。随后,约1.39亿美元比特币和1.53亿美元莱特币在几分钟内被转移和转换。监控团队虽成功冻结了部分资金,但这凸显了种子短语一旦泄露,资金极难追回。 12个单词提供了约128位的巨大熵值,其组合数天文数字,暴力破解在现实中不可能。真正的风险在于信息泄露:如果部分单词通过照片、云备份或诈骗手段泄露,安全性的衰减并非线性,而是呈断崖式下降。例如,已知7个单词,破解时间会从已知6个单词的千年量级骤降至不足一年。 BIP39中的校验和功能主要用于检测输入错误,防止因笔误导致创建出空钱包,而非防御恶意攻击。 与备受瞩目的数亿美元盗窃案相比,更大量、更悄无声息的损失源于人们自行丢失访问权限。据估计,高达23%已挖出的比特币因忘记短语、备份损毁或持有人离世而无继承人等原因永久丢失。这揭示了种子短语的本质:它不是可重置的密码,而是资产所有权的唯一且不可恢复的终极证明。记录错误会安全地失效,部分泄露会导致安全性崩溃,而完全丢失则意味着背后的比特币对任何人而言都不复存在。

cryptonews.ru8分钟前

助记词:12个词,介于你与失去一切之间的鸿沟

cryptonews.ru8分钟前

交易

现货
活动图片