Crypto Theft Hides In Plain Sight Inside Popular Game Mods—Kaspersky

bitcoinist發佈於 2025-12-23更新於 2025-12-23

文章摘要

Kaspersky warns of a new infostealer malware called "Stealka" distributed through fake video game mods and cracked software, primarily targeting Windows users. Disguised as cheats or utility cracks for popular titles like Roblox or Microsoft Visio, the malware is hosted on platforms like GitHub and Google Sites to appear legitimate. Once executed, Stealka steals browser data, saved passwords, and cryptocurrency wallet information—targeting over 115 browser extensions including MetaMask, Binance Wallet, and Coinbase. It collects private keys, seed phrases, and autofill data, enabling account takeovers and further malicious spread. Detected initially in Russia, Turkey, Brazil, Germany, and India, the malware is sometimes bundled with cryptomining code. Users are advised to avoid unofficial software, use antivirus tools, enable two-factor authentication, and verify file checksums before installation.

Kaspersky has warned that a new infostealer called “Stealka” is being spread through bogus video game mods and cracked software, putting crypto users and gamers at risk.

The malware was identified in November 2025 and is delivered as what looks like harmless game add-ons or utility cracks. Systems running Windows are the main target.

Attackers Hide Malware In Mods

Reports have disclosed that Stealka is disguised as cheats, mods and cracks for popular titles, with fake packages posted to places users normally trust. Files have been seen on GitHub, SourceForge, Softpedia and Google Sites, which helps the downloads look legitimate.

In some cases, the malware was packaged as a Roblox mod or as a cracked copy of Microsoft Visio. According to Kaspersky, the campaign uses convincing websites and may employ automated tools to create professional pages that trick people into clicking download links.

Data And Wallets Targeted

Once run, Stealka searches for browser data, saved passwords and crypto wallet information. Based on reports, it targets more than 115 browser extensions tied to wallets, password managers and two-factor apps.

Extensions for MetaMask, Binance Wallet, Coinbase and other popular wallets are among those at risk. Private keys, seed phrases and wallet file paths can be exposed on an infected machine, and stored browser cards and autofill entries are also collected.

Total crypto market cap currently at $3.01 trillion. Chart: TradingView

Victims’ accounts can be taken over using the stolen credentials, and that access can then be used to push further malicious links to friends or followers.

How The Threat Spreads And Where It’s Seen

Kaspersky’s telemetry shows initial detections in Russia, with additional cases reported in Turkey, Brazil, Germany and India.

Distribution methods vary. Sometimes a single download bundle carries Stealka; other times it is paired with cryptominer code so infected computers also mine cryptocurrency for the attackers.

Files hosted on trusted developer portals make it harder for users to spot danger, and the malware’s wide reach means standard precautions can still be bypassed if users ignore basic safety steps.

Recommendations For Users

According to cybersecurity advisories, avoid unofficial or pirated software and only download mods from verified, trusted creators. Use a reputable antivirus product and keep it updated.

Password managers are recommended over saving credentials in browsers, and two-factor authentication should be enabled for crypto accounts when available.

Keep Windows and applications patched, and check that a downloaded file’s checksum or digital signature matches the developer’s published value before running installers.

Featured image from Kaspersky, chart from TradingView

熱門幣種推薦

相關問答

QWhat is the name of the new infostealer malware being spread through fake game mods and cracked software?

AThe new infostealer malware is called 'Stealka'.

QWhich operating systems are the primary target of the Stealka malware?

ASystems running Windows are the main target of the Stealka malware.

QWhat types of sensitive information does the Stealka malware steal from infected computers?

AStealka steals browser data, saved passwords, crypto wallet information, private keys, seed phrases, wallet file paths, stored browser cards, and autofill entries.

QName at least two trusted online platforms where the fake packages containing the malware were found.

AFake packages containing the malware were found on GitHub, SourceForge, Softpedia, and Google Sites.

QWhat are two key security recommendations provided to protect against this threat?

ATwo key recommendations are to avoid unofficial or pirated software and to use a reputable, updated antivirus product. Additionally, using password managers and enabling two-factor authentication for crypto accounts is advised.

你可能也喜歡

福建晋江,一家存储超级独角兽静悄悄

近日,随着长鑫科技A股上市成为股王,同为国内三大存储芯片项目之一的福建晋华集成电路有限公司(晋华)重新进入公众视野。这家位于福建晋江的DRAM企业,自2016年成立起便肩负打破海外垄断的使命,却因2018年被美国列入实体清单并遭遇司法指控而陷入长达数年的沉寂。2024年2月,美国法院裁定其无罪,晋华才得以摆脱法律阴影。 晋华的曲折发展与灵魂人物陈正坤密不可分。这位拥有美光与联电背景的工程师,怀揣自主开发DRAM的梦想加入晋华。公司初期通过与联电合作快速推进,但随后美光发起诉讼,指控技术窃密,导致晋华产线因设备禁运而停摆。在极端困难下,陈正坤带领团队改造国产设备、重构工艺,艰难维持运营。尽管最终赢得清白,但发展进度已被严重拖慢。目前,晋华专注于利基型DRAM市场,月产能约4万片,拥有千余项专利,但仍在美国实体清单限制之下。 晋江这座以鞋服闻名的民营经济强市,为引入晋华这一“硬科技”项目投入巨资,并以政府基金、全链条配套和持续的政策支持,助力企业在制裁中生存下来。如今,以晋华为龙头,晋江已形成超千亿规模的集成电路产业集群。在全球AI驱动存储繁荣的周期中,晋华虽规模尚小,但其在封锁中重建的经历,已成为中国存储产业自主攻坚的缩影。

marsbit42 分鐘前

福建晋江,一家存储超级独角兽静悄悄

marsbit42 分鐘前

《夏季拉锯战》仍在继续:突破67000美元将是比特币上涨的起点

比特币价格在8月1日跌至62,217美元,延续了自6月5日开始的盘整格局。目前比特币被困在58,000至67,000美元的区间内,市场参与者对下一步走向存在分歧。 技术分析显示关键价位在60,000美元和67,000美元。交易员Crypto Candy认为,只要价格低于66,000美元,就可能跌向60,000美元或更低。投资者Jelle则将当前市场比作“夏季拉锯战”,坚持定期买入的平均成本策略。 上行突破的关键在于能否站稳67,000美元以上。交易员Daan Crypto Trades认为,若无法突破此位,市场可能继续盘整。交易员Roman则预测,若伴随足够交易量有效突破67,000美元,价格可能快速上涨至70,000-80,000美元区间。 宏观分析师Gert van Lagen从更长周期观察,认为比特币正在测试一个持续七年之久的“杯柄形态”的颈线位,市场恐惧情绪在盘整中逐渐消退。他强调,长期持有者仍未出现投降迹象,NUPL指标显示他们远未进入抛售区域。 总而言之,市场共识是比特币正处于积累阶段,60,000美元和67,000美元是关键水平,对任一水平的突破都将决定资产的下一个方向。当前围绕67,000美元的博弈,也反映出短期持有者盈亏平衡点附近的心理压力。近期价格在利好新闻后迅速回落,表明市场叙事尚未转化为持续的资本流入,能否构建更稳固的上涨基础仍有待观察。

cryptonews.ru2 小時前

《夏季拉锯战》仍在继续:突破67000美元将是比特币上涨的起点

cryptonews.ru2 小時前

交易

現貨

熱門文章

如何購買PROS

歡迎來到HTX.com!在這裡,購買Pharos (PROS)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買Pharos (PROS)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的Pharos (PROS)購買Pharos (PROS)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易Pharos (PROS)在HTX的現貨市場輕鬆交易Pharos (PROS)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

656 人學過發佈於 2026.06.22更新於 2026.06.29

如何購買PROS

什麼是 VERONA

I. 項目介紹VERONA是第一個為大規模採用而專門建構的 L1。 它已經取得了顯著的進展,擁有數百萬用戶帳戶和超過200個應用程序的生態系統。 VERONA已從 Multicoin、Animoca、Circle、Hashkey、Spartan、Figment 等眾多頂級支持者處籌集了超過3600萬美元。 VERONA消除了所有技術複雜性,使任何用戶都能輕鬆訪問 Web3。VERONA提供了類似 Web2 的用戶體驗,利用協議級實現來處理抽象帳戶、簽名、費用、互操作性等問題,使開發者能夠構建安全、直觀且無縫的用戶體驗。II. 代幣信息1) 代幣基本信息代幣符號:VERONA(Verona)III. 相關鏈接 官網鏈接:https://xion.burnt.com/ 區塊鏈鏈接:https://explorer.burnt.com/ 白皮書鏈接:https://xion.burnt.com/whitepaper.pdf 社交媒體: https://x.com/burnt_xion 注意:項目簡介來自於官方項目團隊所發布或提供的信息資料,可能存在過時、錯誤或遺漏,相關內容僅供參考且不構成投資建議,HTX不會承擔任何依賴這些信息而產生的直接或間接損失。

724 人學過發佈於 2026.06.22更新於 2026.06.22

什麼是 VERONA

如何購買VERONA

歡迎來到HTX.com!在這裡,購買VERONA (VERONA)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買VERONA (VERONA)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的VERONA (VERONA)購買VERONA (VERONA)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易VERONA (VERONA)在HTX的現貨市場輕鬆交易VERONA (VERONA)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

524 人學過發佈於 2026.06.22更新於 2026.06.22

如何購買VERONA

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 A (A)幣價的意見。

活动图片