Video game mods are spreading new ‘Stealka’ crypto infostealer: Kaspersky

cointelegraph發佈於 2025-12-22更新於 2025-12-22

文章摘要

A new malware called "Stealka" is targeting cryptocurrency wallets and browser extensions by disguising itself as video game cheats, mods, and software cracks, according to Kaspersky. The infostealer, discovered in November, is distributed through legitimate platforms like GitHub and Google Sites, and sometimes via fake professional-looking websites. It primarily targets Chromium and Gecko-based browsers—including Chrome, Firefox, and Edge—and steals autofill data, login credentials, and payment details. It also specifically targets 115 browser extensions related to crypto wallets, 2FA services, and password managers, including Binance, MetaMask, Trust Wallet, and Coinbase. Kaspersky advises using reliable antivirus software, avoiding pirated software and unofficial mods, and refraining from storing passwords in browsers.

New malware has been discovered that targets crypto wallets and browser extensions while disguising itself as game cheats and mods, says cybersecurity firm Kaspersky.

Kaspersky reported on Thursday that it had uncovered a new infostealer dubbed “Stealka,” which targets Microsoft Windows user data.

Attackers have used the malware, which was discovered in November, to hijack accounts, steal cryptocurrency, and install crypto miners on their victims’ computers while masquerading as video game cracks, cheats, and mods.

The malicious software has been distributed through legitimate platforms like GitHub, SourceForge, and Google Sites, and disguised as game mods, especially for Roblox, and software cracks for applications such as Microsoft Visio.

Sometimes, attackers go a step further, possibly using artificial intelligence tools, and creating entire fake websites that look “quite professional,” said Kaspersky researcher Artem Ushkov.

A fake website pretending to offer Roblox scripts, Source: Kaspersky

Crypto wallets and extensions targeted

Ushkov noted that Stealka has a fairly “extensive arsenal of capabilities,” but is particularly dangerous because its prime target is data from browsers built on the Chromium and Gecko engines.

This puts over 100 different browsers at risk, including popular ones such as Chrome, Firefox, Opera, Yandex, Edge, Brave, and many others.

Related: Hackers are exploiting a JavaScript library to plant crypto drainers

Its primary targets are autofill data, such as sign-in credentials, addresses, and payment card details, but it also targets the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA (two-factor authentication) services.

Some of the 80 crypto wallets targeted include Binance, Coinbase, Crypto.com, SafePal, Trust Wallet, MetaMask, Ton, Phantom, Nexus, and Exodus.

Kaspersky also said the messaging apps, including Discord, Telegram, Unigram, Pidgin, and Tox, were also at risk, as were email clients, password managers, gaming clients, and even VPN applications.

Avoid pirated software and game mods

To stay protected, Kaspersky recommended using reliable antivirus software and password managers to avoid storing passwords in browsers. It also cautioned against using pirated software and unofficial game mods.

Cloudflare reported last week that more than 5% of all emails sent worldwide contain malicious content, and more than half of those contained a phishing link, while a quarter of all HTML attachments were found to be malicious.

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

相關問答

QWhat is the name of the new infostealer malware discovered by Kaspersky and what does it target?

AThe new infostealer is called 'Stealka'. It primarily targets data from browsers built on Chromium and Gecko engines, including autofill data (sign-in credentials, addresses, payment card details), and the settings and databases of 115 browser extensions for crypto wallets, password managers, and 2FA services.

QHow is the Stealka malware being distributed to potential victims?

AThe malware is distributed by disguising itself as video game cracks, cheats, and mods. It has been spread through legitimate platforms like GitHub, SourceForge, and Google Sites. Attackers sometimes create entire fake, professional-looking websites to host the malicious software.

QWhich specific types of applications and services are at risk from the Stealka infostealer?

AOver 100 different browsers (Chrome, Firefox, Opera, etc.), 80 crypto wallets (Binance, Coinbase, MetaMask, etc.), messaging apps (Discord, Telegram, etc.), email clients, password managers, gaming clients, and VPN applications are all at risk.

QWhat recommendations does Kaspersky provide to protect against this threat?

AKaspersky recommends using reliable antivirus software, using password managers instead of storing passwords in browsers, and avoiding the use of pirated software and unofficial game mods.

QBeyond game mods, what other type of software is commonly used as a disguise for this malware?

AThe malware is also disguised as software cracks for applications such as Microsoft Visio.

你可能也喜歡

«我们回来了»:Saylor给了比特币购买策略恢复的希望

Strategy公司首席执行官迈克尔·塞勒在社交媒体X上发布了简短短语“We're Back”,市场解读为暗示该公司在为期两个月的暂停后,将恢复购买比特币。此前暂停旨在加强公司资产负债表。 观察人士认为,此帖可能是一个强烈的心理信号:塞勒有一系列在周末发布的隐晦帖子,往往预示着周一正式宣布购买比特币。如果模式延续,这暗示在经历了明显的夏季中断后,比特币积累活动将恢复。 过去两个月,Strategy暂停了其常规的每周比特币购买,转而专注于稳固资产负债表,包括稳定优先股发行、积累51亿美元现金储备以及通过大规模普通股发行形成15.9亿美元独立资金池。这段战略暂停期恰逢市场艰难时期,但近期比特币价格突破8万美元,使公司的持仓重返盈利状态。 Strategy持有超过840,447枚比特币,平均购买价格约为每枚75,385美元。随着价格上涨,其总持仓多月来首次转为盈利。 从数据分析角度看,“We're Back”的声明应结合更广泛的背景来看。几个月前,塞勒曾公开提及出售比特币的可能性,打破了五年来的“永不卖出”立场,夏季公司也确实出售了部分比特币以支持优先股股息。因此,当前转向购买可能并非年内首次立场转变,而是其储备管理政策比通常认为的更具灵活性。这种模式也引发了对其融资机制可持续性的疑问,因为其购买通常依赖于发行股票和优先证券,而非仅靠自由现金流。

cryptonews.ru12 分鐘前

«我们回来了»:Saylor给了比特币购买策略恢复的希望

cryptonews.ru12 分鐘前

第九巡回法院支持内华达州体育博彩规则,Kalshi面临新的法律挫折

美国第九巡回上诉法院于8月28日一致裁定,驳回了预测市场平台Kalshi的最新法律挑战,使其在与内华达州监管机构的纠纷中再次遭遇重大法律挫折。法院认为Kalshi未能证明内华达州的体育赛事合约规则可能违反联邦商品法。 Kalshi声称其作为受美国商品期货交易委员会(CFTC)监管的指定合约市场,其合约属于掉期交易,应优先于州博彩法规。但第九巡回法院判定,Kalshi的合约运作方式类似体育博彩,可能不符合相关定义,因此驳回了其关于联邦法律明示、冲突及领域优先权的诉求。法院还强调CFTC并非国家赌博监管机构,并撤销了此前禁止内华达州在诉讼期间对Kalshi采取执法行动的初步禁令。 虽然法院在裁决中提及了“重大问题原则”,但并未裁定CFTC未来的规则制定行为违宪。法律专家指出,CFTC的相关规则可能面临依据《行政程序法》提起的诉讼。 值得注意的是,第九巡回法院的裁决与支持Kalshi的第三巡回法院判决存在分歧,这种巡回法院间的意见分歧可能增加案件提交至美国最高法院审理的可能性。目前,内华达州将可对Kalshi的体育合约执行其博彩法律,而CFTC的拟议规则仍在审议中,此事在联邦法院、州机构及联邦规则制定层面仍在持续。

TheNewsCrypto30 分鐘前

第九巡回法院支持内华达州体育博彩规则,Kalshi面临新的法律挫折

TheNewsCrypto30 分鐘前

交易

現貨
活动图片