Crypto Theft Hides In Plain Sight Inside Popular Game Mods—Kaspersky

bitcoinist發佈於 2025-12-23更新於 2025-12-23

文章摘要

Kaspersky warns of a new infostealer malware called "Stealka" distributed through fake video game mods and cracked software, primarily targeting Windows users. Disguised as cheats or utility cracks for popular titles like Roblox or Microsoft Visio, the malware is hosted on platforms like GitHub and Google Sites to appear legitimate. Once executed, Stealka steals browser data, saved passwords, and cryptocurrency wallet information—targeting over 115 browser extensions including MetaMask, Binance Wallet, and Coinbase. It collects private keys, seed phrases, and autofill data, enabling account takeovers and further malicious spread. Detected initially in Russia, Turkey, Brazil, Germany, and India, the malware is sometimes bundled with cryptomining code. Users are advised to avoid unofficial software, use antivirus tools, enable two-factor authentication, and verify file checksums before installation.

Kaspersky has warned that a new infostealer called “Stealka” is being spread through bogus video game mods and cracked software, putting crypto users and gamers at risk.

The malware was identified in November 2025 and is delivered as what looks like harmless game add-ons or utility cracks. Systems running Windows are the main target.

Attackers Hide Malware In Mods

Reports have disclosed that Stealka is disguised as cheats, mods and cracks for popular titles, with fake packages posted to places users normally trust. Files have been seen on GitHub, SourceForge, Softpedia and Google Sites, which helps the downloads look legitimate.

In some cases, the malware was packaged as a Roblox mod or as a cracked copy of Microsoft Visio. According to Kaspersky, the campaign uses convincing websites and may employ automated tools to create professional pages that trick people into clicking download links.

Data And Wallets Targeted

Once run, Stealka searches for browser data, saved passwords and crypto wallet information. Based on reports, it targets more than 115 browser extensions tied to wallets, password managers and two-factor apps.

Extensions for MetaMask, Binance Wallet, Coinbase and other popular wallets are among those at risk. Private keys, seed phrases and wallet file paths can be exposed on an infected machine, and stored browser cards and autofill entries are also collected.

Total crypto market cap currently at $3.01 trillion. Chart: TradingView

Victims’ accounts can be taken over using the stolen credentials, and that access can then be used to push further malicious links to friends or followers.

How The Threat Spreads And Where It’s Seen

Kaspersky’s telemetry shows initial detections in Russia, with additional cases reported in Turkey, Brazil, Germany and India.

Distribution methods vary. Sometimes a single download bundle carries Stealka; other times it is paired with cryptominer code so infected computers also mine cryptocurrency for the attackers.

Files hosted on trusted developer portals make it harder for users to spot danger, and the malware’s wide reach means standard precautions can still be bypassed if users ignore basic safety steps.

Recommendations For Users

According to cybersecurity advisories, avoid unofficial or pirated software and only download mods from verified, trusted creators. Use a reputable antivirus product and keep it updated.

Password managers are recommended over saving credentials in browsers, and two-factor authentication should be enabled for crypto accounts when available.

Keep Windows and applications patched, and check that a downloaded file’s checksum or digital signature matches the developer’s published value before running installers.

Featured image from Kaspersky, chart from TradingView

熱門幣種推薦

相關問答

QWhat is the name of the new infostealer malware being spread through fake game mods and cracked software?

AThe new infostealer malware is called 'Stealka'.

QWhich operating systems are the primary target of the Stealka malware?

ASystems running Windows are the main target of the Stealka malware.

QWhat types of sensitive information does the Stealka malware steal from infected computers?

AStealka steals browser data, saved passwords, crypto wallet information, private keys, seed phrases, wallet file paths, stored browser cards, and autofill entries.

QName at least two trusted online platforms where the fake packages containing the malware were found.

AFake packages containing the malware were found on GitHub, SourceForge, Softpedia, and Google Sites.

QWhat are two key security recommendations provided to protect against this threat?

ATwo key recommendations are to avoid unofficial or pirated software and to use a reputable, updated antivirus product. Additionally, using password managers and enabling two-factor authentication for crypto accounts is advised.

你可能也喜歡

«我们回来了»:Saylor给了比特币购买策略恢复的希望

Strategy公司首席执行官迈克尔·塞勒在社交媒体X上发布了简短短语“We're Back”,市场解读为暗示该公司在为期两个月的暂停后,将恢复购买比特币。此前暂停旨在加强公司资产负债表。 观察人士认为,此帖可能是一个强烈的心理信号:塞勒有一系列在周末发布的隐晦帖子,往往预示着周一正式宣布购买比特币。如果模式延续,这暗示在经历了明显的夏季中断后,比特币积累活动将恢复。 过去两个月,Strategy暂停了其常规的每周比特币购买,转而专注于稳固资产负债表,包括稳定优先股发行、积累51亿美元现金储备以及通过大规模普通股发行形成15.9亿美元独立资金池。这段战略暂停期恰逢市场艰难时期,但近期比特币价格突破8万美元,使公司的持仓重返盈利状态。 Strategy持有超过840,447枚比特币,平均购买价格约为每枚75,385美元。随着价格上涨,其总持仓多月来首次转为盈利。 从数据分析角度看,“We're Back”的声明应结合更广泛的背景来看。几个月前,塞勒曾公开提及出售比特币的可能性,打破了五年来的“永不卖出”立场,夏季公司也确实出售了部分比特币以支持优先股股息。因此,当前转向购买可能并非年内首次立场转变,而是其储备管理政策比通常认为的更具灵活性。这种模式也引发了对其融资机制可持续性的疑问,因为其购买通常依赖于发行股票和优先证券,而非仅靠自由现金流。

cryptonews.ru39 分鐘前

«我们回来了»:Saylor给了比特币购买策略恢复的希望

cryptonews.ru39 分鐘前

交易

現貨

熱門文章

什麼是 MRK

全球領先製藥企業,專注創新處方藥、疫苗與生物製劑研發。核心產品涵蓋癮免疫療法Keytruda、HPV疫苗Gardasil等,同時布局動物保健業務。在美加地區以“默克”品牌運營,全球其他地區以“默沙東(MSD)”名稱開展業務。

272 人學過發佈於 2026.08.26更新於 2026.08.26

什麼是 MRK

如何購買MRK

歡迎來到HTX.com!在這裡,購買默沙东 (MRK)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買默沙东 (MRK)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的默沙东 (MRK)購買默沙东 (MRK)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易默沙东 (MRK)在HTX的現貨市場輕鬆交易默沙东 (MRK)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

204 人學過發佈於 2026.08.26更新於 2026.08.26

如何購買MRK

什麼是 SHEIN

公司成立於 2008 年,是全球頂尖的跨境快時尚與在線零售巨頭。公司以“按需生產”的敏捷柔性供應鏈為核心優勢,業務覆蓋女裝、男裝、童裝、美妝及家居等多元品類,通過自營線上獨立站及移動端 App 銷往全球 150 多個國家和地區,在歐美等主流消費市場擁有極高的品牌認知度與用戶黏性。

218 人學過發佈於 2026.08.28更新於 2026.08.28

什麼是 SHEIN

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 A (A)幣價的意見。

活动图片