Kaspersky researchers have uncovered Stealka, a sophisticated infostealer masquerading as game mods and pirated software that targets crypto wallets and browserKaspersky researchers have uncovered Stealka, a sophisticated infostealer masquerading as game mods and pirated software that targets crypto wallets and browser

Gamers at Risk as Fake Roblox Mods Spread Crypto-Stealing Malware

Kaspersky researchers have uncovered Stealka, a sophisticated infostealer masquerading as game mods and pirated software that targets crypto wallets and browser credentials across over 115 extensions.

The malware spreads through trusted platforms, including GitHub, SourceForge, and Softpedia, where attackers create professional-looking fake websites and repositories to distribute the threat under the guise of popular game cheats for titles like Roblox and GTA V.

Attackers exploited the website. | Source: Kaspersky

The discovery marks the latest escalation in a broader pattern of gaming-focused malware campaigns, as cybercriminals increasingly exploit the trust gamers place in modding communities.

Attackers leverage popular search terms and authentic-looking download pages to lure victims, with some sites falsely claiming that virus scans are conducted before downloads, even though no such verification occurs.

The malicious files appear deliberately deceptive; one fake site advertised Half-Life 3 while describing it as “professional software solution designed for Windows,” using popular gaming titles merely as bait to maximize search engine visibility.

Source: Kaspersky

Extensive Arsenal Targets Crypto Wallets

According to the security firm, Stealka’s capabilities extend far beyond basic credential theft, targeting data from browsers built on Chromium and Gecko engines, putting over 100 applications, including Chrome, Firefox, Opera, and Edge, at immediate risk.

The malware extracts autofill data, session tokens, and cookies that allow attackers to bypass two-factor authentication and hijack accounts without passwords, while simultaneously targeting 115 browser extensions for crypto wallets, password managers, and authentication services.

High-value targets include crypto wallets such as Binance, Coinbase, MetaMask, Trust Wallet, and Phantom, as well as password managers such as 1Password, Bitwarden, LastPass, and NordPass.

The stealer downloads local configurations from 80 wallet applications, encompassing Bitcoin, Ethereum, Exodus, Monero, and Dogecoin, that may contain encrypted private keys and seed phrase data sufficient to compromise holdings.

Beyond crypto assets, Stealka infiltrates messaging apps like Discord and Telegram, email clients including Outlook and Thunderbird, gaming platforms such as Steam and Roblox launchers, VPN clients like ProtonVPN and Surfshark, and note-taking apps where users often improperly store sensitive information.

The malware additionally harvests system data, installed program lists, hardware specifications, and captures screenshots to maximize intelligence gathering.

Attackers have used compromised accounts to spread the malware further, with Kaspersky discovering the stealer in a GTA V mod posted by a previously hijacked account on a dedicated modding site.

Industry Faces Mounting Security Crisis

The Stealka campaign emerges amid catastrophic industry-wide security failures, as crypto platforms have lost $9.1 billion in 2025 alone, which is 10% of the $90 billion stolen over the past 15 years.

In November, losses exceeded $276 million, pushing the annual total past historical records.

Crypto is facing a security reckoning,” said Mitchell Amador, CEO of Immunefi, a crowdsourced security platform protecting $180 billion in assets.

Most hacks this year haven’t occurred due to poor audits—they’ve happened after launch, during protocol upgrades, or through integration vulnerabilities.

Amador emphasized that 99% of Web3 projects operate without basic firewalls while fewer than 10% deploy modern AI security tools, calling the sector’s approach “willful negligence.

The human element has become the primary attack surface, with threat actors shifting from code vulnerabilities to operational security breaches as smart contracts become harder to exploit.

The threat landscape is shifting from on-chain code vulnerabilities to operational security and treasury-level attacks,” Amador explained. “As code hardens, attackers target the human element.”

Kaspersky’s broader research reveals a sustained malware ecosystem, having previously documented the GitVenom campaign involving hundreds of fake GitHub repositories, SparkKitty mobile malware that infiltrated Apple’s App Store and Google Play to steal seed phrase screenshots via OCR, and ClipBanker trojans hidden in fake Microsoft Office downloads.

North Korean threat groups have also escalated tactics by weaponizing blockchain technology itself, embedding malware payloads in smart contracts on the BNB Smart Chain and Ethereum, creating a decentralized command-and-control infrastructure that law enforcement cannot shut down.

For now, Kaspersky recommends users to do the following:

  • Deploy reliable antivirus software.
  • Avoid storing sensitive credentials in browsers.
  • Exercise extreme caution with game cheats and pirated software.
  • Enable two-factor authentication with backup codes stored in encrypted password managers rather than text files.
  • Refrain from downloading software from untrusted sources despite the convenience they may offer.
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin Perpetual Open Interest Rises to 310,000 BTC as Price Hits $90,000

Bitcoin Perpetual Open Interest Rises to 310,000 BTC as Price Hits $90,000

Perpetual futures open interest for Bitcoin increased from 304,000 BTC to 310,000 BTC on Monday as the cryptocurrency's price briefly touched $90,000, signaling renewed interest in leveraged long positions ahead of year-end trading according to blockchain analytics firm Glassnode. This 2% increase in open interest accompanying price appreciation suggests fresh capital entering leveraged positions rather than mere price-driven expansion, potentially contradicting earlier narratives about muted year-end activity while raising questions about whether building leverage creates vulnerability for the exact Q1 2026 crash scenarios that Anthony Pompliano suggested Bitcoin might avoid.
Share
MEXC NEWS2025/12/24 15:46
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Palmer Luckey Raises $350M for Erebor Digital Bank at $4.3B Valuation

Palmer Luckey Raises $350M for Erebor Digital Bank at $4.3B Valuation

Palmer Luckey has raised $350 million for Erebor, valuing the digital bank at approximately $4.3 billion as it moves toward launch with FDIC approval, according to Axios. The Oculus founder and defense tech entrepreneur's entry into fintech represents remarkable valuation for pre-launch bank and raises questions about whether investors are backing genuinely innovative banking model or simply betting on Luckey's track record of building billion-dollar companies, while the timing amid regional banking stress and cryptocurrency integration ambitions creates both opportunity and scrutiny.
Share
MEXC NEWS2025/12/24 15:42