Video game mods are spreading new ‘Stealka’ crypto infostealer: Kaspersky

cointelegraph发布于2025-12-22更新于2025-12-22

文章摘要

A new malware called "Stealka" is targeting cryptocurrency wallets and browser extensions by disguising itself as video game cheats, mods, and software cracks, according to Kaspersky. The infostealer, discovered in November, is distributed through legitimate platforms like GitHub and Google Sites, and sometimes via fake professional-looking websites. It primarily targets Chromium and Gecko-based browsers—including Chrome, Firefox, and Edge—and steals autofill data, login credentials, and payment details. It also specifically targets 115 browser extensions related to crypto wallets, 2FA services, and password managers, including Binance, MetaMask, Trust Wallet, and Coinbase. Kaspersky advises using reliable antivirus software, avoiding pirated software and unofficial mods, and refraining from storing passwords in browsers.

New malware has been discovered that targets crypto wallets and browser extensions while disguising itself as game cheats and mods, says cybersecurity firm Kaspersky.

Kaspersky reported on Thursday that it had uncovered a new infostealer dubbed “Stealka,” which targets Microsoft Windows user data.

Attackers have used the malware, which was discovered in November, to hijack accounts, steal cryptocurrency, and install crypto miners on their victims’ computers while masquerading as video game cracks, cheats, and mods.

The malicious software has been distributed through legitimate platforms like GitHub, SourceForge, and Google Sites, and disguised as game mods, especially for Roblox, and software cracks for applications such as Microsoft Visio.

Sometimes, attackers go a step further, possibly using artificial intelligence tools, and creating entire fake websites that look “quite professional,” said Kaspersky researcher Artem Ushkov.

A fake website pretending to offer Roblox scripts, Source: Kaspersky

Crypto wallets and extensions targeted

Ushkov noted that Stealka has a fairly “extensive arsenal of capabilities,” but is particularly dangerous because its prime target is data from browsers built on the Chromium and Gecko engines.

This puts over 100 different browsers at risk, including popular ones such as Chrome, Firefox, Opera, Yandex, Edge, Brave, and many others.

Related: Hackers are exploiting a JavaScript library to plant crypto drainers

Its primary targets are autofill data, such as sign-in credentials, addresses, and payment card details, but it also targets the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA (two-factor authentication) services.

Some of the 80 crypto wallets targeted include Binance, Coinbase, Crypto.com, SafePal, Trust Wallet, MetaMask, Ton, Phantom, Nexus, and Exodus.

Kaspersky also said the messaging apps, including Discord, Telegram, Unigram, Pidgin, and Tox, were also at risk, as were email clients, password managers, gaming clients, and even VPN applications.

Avoid pirated software and game mods

To stay protected, Kaspersky recommended using reliable antivirus software and password managers to avoid storing passwords in browsers. It also cautioned against using pirated software and unofficial game mods.

Cloudflare reported last week that more than 5% of all emails sent worldwide contain malicious content, and more than half of those contained a phishing link, while a quarter of all HTML attachments were found to be malicious.

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

相关问答

QWhat is the name of the new infostealer malware discovered by Kaspersky and what does it target?

AThe new infostealer is called 'Stealka'. It primarily targets data from browsers built on Chromium and Gecko engines, including autofill data (sign-in credentials, addresses, payment card details), and the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA services.

QHow is the Stealka malware being distributed to potential victims?

AThe malware is distributed by disguising itself as video game cracks, cheats, and mods. It has been spread through legitimate platforms like GitHub, SourceForge, and Google Sites. Attackers sometimes create entire fake, professional-looking websites to host the malicious software.

QWhich specific types of applications and services are at risk from the Stealka infostealer?

AOver 100 different browsers (Chrome, Firefox, Opera, etc.), 80 crypto wallets (Binance, Coinbase, MetaMask, etc.), messaging apps (Discord, Telegram, etc.), email clients, password managers, gaming clients, and VPN applications are all at risk.

QWhat recommendations does Kaspersky provide to protect against this threat?

AKaspersky recommends using reliable antivirus software, using password managers instead of storing passwords in browsers, and avoiding the use of pirated software and unofficial game mods.

QBeyond game mods, what other type of software is commonly used as a disguise for this malware?

AThe malware is also disguised as software cracks for applications such as Microsoft Visio.

你可能也喜欢

Agent 赛马结束,超级工作台上位

过去一个月,腾讯、阿里、字节三家巨头不约而同地开始调整其AI战略:他们并未发布新的Agent(智能体),反而着手缩减和整合现有的众多Agent产品。腾讯将QClaw业务并入其战略级产品WorkBuddy;阿里计划将多款办公智能体整合进“千问办公”,由钉钉统一主导;字节则将其AI编程产品TRAE SOLO更名为TRAE Work,转向工作流协同。这标志着行业对Agent发展的共识正在形成:分散探索阶段结束,资源开始向统一入口集中。 此前,各大厂曾效仿早期互联网,在各个部门和场景广泛布局Agent,导致产品功能重叠、资源分散、成本高昂。随着技术壁垒因开源工具而降低,竞争核心转向算力效率与市场聚焦。当下的调整类似于PC时代的浏览器和移动时代的超级App,预示着AI时代正进入以“超级工作台”统一入口的新阶段。 这一转变背后是市场重心的深刻转移:AI的最大市场并非最初的程序员群体,而是更广阔的数十亿职场人的通用办公场景。超级工作台的目标是成为员工处理邮件、文档、数据、审批等日常工作的首要AI入口,从而掌握企业数据和系统API的调度权。 这并非要取代现有的企业软件(如ERP、CRM),而是通过引入“Skills”(标准化能力接口)让软件能力无缝接入工作台。软件的前端交互界面重要性下降,其价值将转向按能力调用和结果付费。Agent本身也从独立产品,逐渐演变为一种底层能力,最终像电力和网络协议一样,无处不在却又隐于无形。 行业正从Agent作为明星产品的第一阶段,快速迈向其作为统一工作入口的第二阶段,并终将进入其化为无形基础设施的第三阶段。

marsbit19分钟前

Agent 赛马结束,超级工作台上位

marsbit19分钟前

Michael Saylor:反对 BIP—110 的 110 个理由

Michael Saylor发表长文,系统性地阐述了反对比特币改进提案BIP 110的110个理由。他认为,BIP 110旨在通过修改共识规则来限制区块链上的非支付类数据存储(如铭文等),但其根本动机源于对特定应用的价值判断和“垃圾信息”的担忧,而非修复协议的安全或技术漏洞。Saylor强调,比特币的核心优势在于其中立性、硬共识和开放的无许可创新环境。 他反对BIP 110的主要论点包括:该提案将社会性价值判断提升为协议法律,破坏了规则的中立性;其举证不足,未能量化所谓“紧急威胁”的具体影响;提案捆绑了七项过于宽泛的技术限制,可能误伤未来的合法金融应用与升级路径;临时性的共识规则增加了系统复杂性和协调风险;可能对矿工收入、网络安全和长期创新产生不确定的负面经济影响。 Saylor指出,比特币已具备区块大小和手续费市场等中立的调节机制,节点和矿工也可以自行制定中继和打包策略,这些是比动用共识分叉更优的解决方案。他警告,BIP 110会开创一个危险的先例,即通过协议规则排除不受欢迎的用途,这可能导致未来更多的治理冲突,并扼杀尚未被发现的创新。他呼吁社区应完善测量、采用更精准的资源定价机制,并等待压倒性的共识,而非仓促实施一个可能弊大于利的方案。他最终主张,比特币需要的是“中立性的守护者”,而非“救赎性的守护者”。

marsbit34分钟前

Michael Saylor:反对 BIP—110 的 110 个理由

marsbit34分钟前

United Stables 市值突破 10 亿美元,Chainlink 数据喂价保障 U 代币抵押资产

United Stables发行的稳定币U市值已突破10亿美元,其关键在于采用了Chainlink数据预言机网络来提供抵押品定价和数据基础设施。 这一里程碑事件突显了在稳定币领域,可靠的数据基础设施已非可选,而是必需品。稳定币的价值依赖于用户对其抵押品、定价和赎回机制的信任,若相关数据薄弱或不透明,将阻碍其在DeFi中的整合与应用。Chainlink通过提供外部数据源,为U稳定币生态系统支持自动化的抵押品审计和定价。 需要明确的是,Chainlink在此扮演的是基础设施角色,它本身并不直接赋予稳定币价值,而是通过提供可靠的数据层,使其他系统能更安全地与稳定币交互。U市值的增长也表明,尽管稳定币市场仍由巨头主导,但新的发行方正在凭借强大的基础设施支持找到发展空间。 对于LINK持有者而言,这一集成案例巩固了Chainlink在稳定币关键基础设施(如抵押品验证)领域的战略地位,增强了其网络效应和机构相关性。然而,单一稳定币的增长并不能直接等同于LINK代币的费用增长或价格驱动,其影响更多是间接和战略层面的。核心在于,稳定币正变得越来越重要、受监管且依赖基础设施,而Chainlink正将自己定位为该环境中的关键服务提供商。

bitcoinist1小时前

United Stables 市值突破 10 亿美元,Chainlink 数据喂价保障 U 代币抵押资产

bitcoinist1小时前

交易

现货
活动图片