312 lines
21 KiB
Markdown
312 lines
21 KiB
Markdown
# Gaming Community Malware Distribution: Defensive Threat Intelligence Report
|
|||
|
|
|
||
|
|
**Date:** March 2026
|
||
|
|
**Scope:** 2025-2026 threat landscape
|
||
|
|
**Classification:** Defensive Threat Intelligence
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Executive Summary
|
||
|
|
|
||
|
|
Gaming communities have become the single largest attack surface for infostealer malware distribution. Research by Flare analyzing 50,000+ infected devices found that **41.47% of all infostealer infections originated from gaming-related files**, making gaming the #1 lure category for threat actors in 2025. The first half of 2025 saw an **800% increase in credential theft via infostealers**, with 1.8 billion credentials stolen. Gaming-specific lures (cheats, mod menus, aimbots, skin changers) accounted for over 50% of gaming-related infections.
|
||
|
|
|
||
|
|
The dominant malware families are operated as **Malware-as-a-Service (MaaS)** — Lumma Stealer, StealC, RedLine, Raccoon, and Vidar — responsible for 75%+ of infections. The attack chain is industrialized: developers sell subscriptions, affiliates ("traffers") distribute via gaming communities, and stolen credentials are sold on dark markets.
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 1. Distribution Methods and Platforms
|
||
|
|
|
||
|
|
### 1.1 YouTube — "Ghost Network" Campaign
|
||
|
|
|
||
|
|
The single largest documented gaming malware operation in 2025. Check Point Research identified a campaign that **hijacked legitimate YouTube accounts** to post tutorial videos promising free game cheats, cracked software, and Roblox hacks.
|
||
|
|
|
||
|
|
- **Scale:** 3,000+ malicious videos identified; output tripled in 2025 vs. prior years
|
||
|
|
- **Structure:** Three-tier operation — some accounts posted videos, others flooded comments with fake praise, a third set posted community links with download URLs and passwords
|
||
|
|
- **Lures:** Roblox hacks (380M monthly active players), Fortnite cheats, cracked software (Photoshop, FL Studio)
|
||
|
|
- **Delivery:** Viewers instructed to disable antivirus, then download archives from Dropbox, Google Drive, or MediaFire
|
||
|
|
- **Payloads:** Rhadamanthys and Lumma infostealers
|
||
|
|
- **Takedown:** Google and Check Point collaborated to remove the network in October 2025
|
||
|
|
|
||
|
|
### 1.2 Discord — Invite Hijacking and Fake Beta Testing
|
||
|
|
|
||
|
|
Discord is abused through multiple vectors:
|
||
|
|
|
||
|
|
**Expired Invite Link Hijacking:**
|
||
|
|
- Check Point Research discovered attackers re-registering expired vanity invite links
|
||
|
|
- Users clicking trusted links from legitimate sources were silently redirected to malicious servers
|
||
|
|
- Payloads: AsyncRAT, Skuld Stealer, ChromeKatz
|
||
|
|
|
||
|
|
**"Try My Game" / Fake Beta Testing Scam:**
|
||
|
|
- Victims receive DMs from compromised accounts asking if they want to beta test a "new game"
|
||
|
|
- Download links provided via Dropbox, Catbox, or Discord CDN
|
||
|
|
- Archives contain NSIS or MSI installers delivering Nova Stealer, Ageo Stealer, or Hexon Stealer
|
||
|
|
- Targets: Discord tokens, browser credentials, cryptocurrency wallets
|
||
|
|
- Notable case: An NFT artist lost $170,000 in crypto and NFTs within hours
|
||
|
|
- Download counts from hosting repos exceeded 1,300 per campaign
|
||
|
|
|
||
|
|
**Discord CDN Abuse:**
|
||
|
|
- Malware hosted directly on Discord's CDN using compromised accounts
|
||
|
|
- Links appear more trustworthy because they originate from discord.com domains
|
||
|
|
|
||
|
|
### 1.3 Steam — Malicious Games and Workshop Mods
|
||
|
|
|
||
|
|
**PirateFi Incident (February 2025):**
|
||
|
|
- Free-to-play survival game on Steam Store for ~1 week (Feb 6-12, 2025)
|
||
|
|
- Built by modifying the "Easy Survival RPG" template — was never a legitimate game
|
||
|
|
- Contained Vidar infostealer packed in InnoSetup installer (Pirate.exe -> Howard.exe)
|
||
|
|
- ~1,500 downloads before removal
|
||
|
|
- Vidar used Dead Drop Resolvers on Telegram, Mastodon, and Steam profiles for C2
|
||
|
|
- Stolen browser cookies enabled session hijacking without passwords/2FA
|
||
|
|
- Victims' accounts then used to send phishing to contacts on Steam, Discord, email
|
||
|
|
- **FBI opened investigation** and sought victims publicly
|
||
|
|
- Valve responded reactively; sent notifications to affected users
|
||
|
|
|
||
|
|
**Steam Workshop — People Playground Worm (February 2026):**
|
||
|
|
- Malicious mod "FPS++" uploaded to People Playground's Steam Workshop
|
||
|
|
- Functioned as a worm: when activated, it replaced existing mods with infected copies
|
||
|
|
- Destroyed save files and Steam achievements
|
||
|
|
- Developer disabled Workshop entirely (Feb 1), released security update, re-enabled (Feb 6)
|
||
|
|
- Highlighted that **Valve does not perform universal antivirus vetting** of Workshop uploads
|
||
|
|
|
||
|
|
**Systemic Gaps:**
|
||
|
|
- Valve has only ~79 employees assigned to Steam (as of last public data) — small for a platform serving tens of millions
|
||
|
|
- Moderation is largely reactive; action taken after malware reaches users
|
||
|
|
- External links to Discord servers allowed in game listings create additional attack surface
|
||
|
|
|
||
|
|
### 1.4 GitHub and Code Repositories
|
||
|
|
|
||
|
|
**Webrat (2025):**
|
||
|
|
- Initially distributed as cheats for Rust, Counter-Strike, and Roblox
|
||
|
|
- Later expanded to target security researchers via fake PoC exploits
|
||
|
|
- Capabilities: credential theft, crypto wallet access, webcam/microphone spying, keylogging, Steam/Discord/Telegram data theft
|
||
|
|
|
||
|
|
**Blitz (2025):**
|
||
|
|
- Distributed through backdoored game cheats on Telegram channel (@sw1zzx_dev)
|
||
|
|
- Targeted players of mobile game Standoff 2
|
||
|
|
- C2 infrastructure hosted on Hugging Face Spaces (AI code repository)
|
||
|
|
|
||
|
|
**Vidar 2.0:**
|
||
|
|
- Distributed via fake game cheats on GitHub and Reddit
|
||
|
|
- Operated by Acronis-tracked campaign using both platforms for distribution
|
||
|
|
|
||
|
|
### 1.5 Mod Distribution Platforms (CurseForge, Modrinth)
|
||
|
|
|
||
|
|
**Fractureiser (June 2023 — legacy but foundational):**
|
||
|
|
- Multiple CurseForge and Bukkit accounts compromised
|
||
|
|
- Malicious code injected into popular mods/plugins, picked up by modpacks like "Better Minecraft" (4.6M downloads)
|
||
|
|
- Multi-stage, multi-platform (Windows + Linux) infostealer
|
||
|
|
- Capabilities: clipboard crypto-address swapping, Minecraft/Discord token theft, browser credential theft
|
||
|
|
- Led to creation of community detection tools and improved platform security
|
||
|
|
- CurseForge and Modrinth both enhanced their scanning post-incident
|
||
|
|
|
||
|
|
### 1.6 Fake Client/Launcher Websites
|
||
|
|
|
||
|
|
**Lunar Client Impersonation:**
|
||
|
|
- Fake websites mimicking lunarclient.com distribute malware or credential phishing
|
||
|
|
- Fake Discord bots with altered Lunar Client logos send links to phishing sites
|
||
|
|
- Scam pages prompt Microsoft email entry, then use verification codes to hijack accounts
|
||
|
|
- Legitimate domains: lunarclient.com, moonsworth.com, overwolf.com only
|
||
|
|
|
||
|
|
### 1.7 Telegram Channels
|
||
|
|
|
||
|
|
- Used by Blitz developer to distribute backdoored cheats
|
||
|
|
- CS2 skin scams increasingly spread through Telegram and Discord bots
|
||
|
|
- Fake giveaways, phishing links, and fake investment offers
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 2. Malware Families Targeting Gamers
|
||
|
|
|
||
|
|
| Family | Type | Distribution | Notable Traits |
|
||
|
|
|--------|------|-------------|----------------|
|
||
|
|
| **Lumma Stealer** | MaaS Infostealer | YouTube, Discord, fake cheats | 394K+ PCs infected (Mar-May 2025); tracked as Storm-2477 by Microsoft |
|
||
|
|
| **Vidar** | Infostealer | Steam games (PirateFi), GitHub, fake cheats | Dead Drop Resolvers on Telegram/Steam profiles; Vidar 2.0 emerged after Lumma disruption |
|
||
|
|
| **RedLine** | Infostealer | Fake cheats ("Cheat Lab"), GitHub | Self-propagating variant asked victims to recruit friends |
|
||
|
|
| **StealC** | Infostealer | Gaming cheats | $135K+ stolen assets via gaming infection chains |
|
||
|
|
| **Raccoon** | Infostealer | Roblox mods, game cracks | Common in Roblox ecosystem |
|
||
|
|
| **Rhadamanthys** | Infostealer | YouTube Ghost Network | Delivered via GachiLoader with novel VEH-based PE injection |
|
||
|
|
| **Webrat** | RAT/Backdoor | GitHub repos, fake game cheats | Evolved from gaming cheats to fake security PoCs |
|
||
|
|
| **Blitz** | Malware | Telegram, game cheats | Hosted C2 on Hugging Face Spaces |
|
||
|
|
| **AsyncRAT** | RAT | Discord invite hijacking | Full remote access capability |
|
||
|
|
| **Skuld Stealer** | Infostealer | Discord campaigns | Targets credentials and Discord tokens |
|
||
|
|
| **GodLoader** | Loader | Godot engine abuse | Undetected by nearly all AV engines on VirusTotal |
|
||
|
|
| **RenEngine** | Loader | Pirated game installers | 400K+ systems compromised; 30K+ in US alone |
|
||
|
|
| **Stealka** | Infostealer | Roblox executors, game cracks | Kaspersky-discovered; targets younger users |
|
||
|
|
| **Myth Stealer** | Infostealer | Fake gaming sites | Rust-based; targets Chrome/Firefox |
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 3. Infection Chain — End-to-End
|
||
|
|
|
||
|
|
### Typical Flow:
|
||
|
|
|
||
|
|
```
|
||
|
|
1. LURE CREATION
|
||
|
|
- Threat actor creates YouTube video / Discord message / GitHub repo
|
||
|
|
- Content promises: free cheats, game cracks, skin changers, Robux generators
|
||
|
|
- Social proof manufactured: fake comments, likes, download counts
|
||
|
|
|
||
|
|
2. TRAFFIC ROUTING
|
||
|
|
- Victim clicks link in video description / Discord DM / GitHub README
|
||
|
|
- Routed through Linkvertise or similar ad-gate services (monetization + obfuscation)
|
||
|
|
- May pass through Prometheus TDS (Traffic Distribution System) on compromised sites
|
||
|
|
- Final landing: MediaFire, Mega.nz, Dropbox, Google Drive, Discord CDN
|
||
|
|
|
||
|
|
3. SOCIAL ENGINEERING
|
||
|
|
- Instructions to disable antivirus ("required for the cheat to work")
|
||
|
|
- Password-protected archives (evades automated scanning)
|
||
|
|
- Sometimes partially functional tools included to build trust
|
||
|
|
|
||
|
|
4. INITIAL EXECUTION
|
||
|
|
- Archive contains installer (NSIS, MSI, InnoSetup) or direct executable
|
||
|
|
- May use game engines as loaders (Godot/GDScript, Ren'Py, Lua runtime)
|
||
|
|
- GachiLoader uses Node.js with Vectored Exception Handler abuse
|
||
|
|
- Batch files, Lua scripts, or compiled binaries serve as first stage
|
||
|
|
|
||
|
|
5. PAYLOAD DELIVERY
|
||
|
|
- Loader contacts C2 via Dead Drop Resolvers (Telegram, Steam profiles, Mastodon)
|
||
|
|
- Downloads final payload: Lumma, Vidar, RedLine, Rhadamanthys, etc.
|
||
|
|
- Modular architecture allows payload swaps without changing initial vector
|
||
|
|
|
||
|
|
6. DATA EXFILTRATION
|
||
|
|
- Browser passwords, cookies, session tokens
|
||
|
|
- Discord tokens, Steam sessions
|
||
|
|
- Cryptocurrency wallet data
|
||
|
|
- Clipboard monitoring for crypto address swapping
|
||
|
|
- Screenshots, keylogging, webcam access (Webrat)
|
||
|
|
|
||
|
|
7. PROPAGATION
|
||
|
|
- Stolen accounts used to send malicious links to victim's contacts
|
||
|
|
- Self-spreading variants (RedLine "Cheat Lab") incentivize victims to recruit
|
||
|
|
- Steam Workshop worms replicate by replacing existing mods
|
||
|
|
```
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 4. Trust-Building and Social Engineering Tactics
|
||
|
|
|
||
|
|
1. **Manufactured social proof:** Fake YouTube comments, likes, and community posts create illusion of legitimacy
|
||
|
|
2. **Hijacked legitimate accounts:** Compromised YouTube channels with existing subscriber bases used to post malware videos
|
||
|
|
3. **Partially functional tools:** Cheats that actually work (at least initially) while silently running malware
|
||
|
|
4. **Friend-to-friend spreading:** Stolen accounts send links that appear to come from trusted friends
|
||
|
|
5. **Recruitment incentives:** RedLine variant promised "free cheat copy if you get friends to install"
|
||
|
|
6. **Professional presentation:** Fake games like PirateFi built using real game templates with store pages, screenshots
|
||
|
|
7. **Targeting young users:** Roblox-focused campaigns exploit children who are less security-aware; promise free Robux
|
||
|
|
8. **Impersonation of legitimate tools:** Fake Lunar Client, fake mod loaders, fake game launchers mimicking real products
|
||
|
|
9. **Urgency and exclusivity:** "Limited beta test" invitations, time-limited offers
|
||
|
|
10. **Anti-AV normalization:** Gaming community culture where disabling antivirus for cheats is common and expected
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 5. Games and Communities Most Targeted
|
||
|
|
|
||
|
|
**Tier 1 — Highest Targeting:**
|
||
|
|
- **Roblox** — 380M monthly active players, younger demographic, executor/mod culture
|
||
|
|
- **Minecraft** — Massive modding ecosystem, CurseForge/Modrinth supply chain
|
||
|
|
- **Counter-Strike 2** — Skin trading economy worth billions, cheat culture
|
||
|
|
- **Fortnite** — Huge player base, active cheat-seeking community
|
||
|
|
- **Grand Theft Auto** — Mod menus, cracked versions, GTA Online cheats
|
||
|
|
|
||
|
|
**Tier 2 — Significant Targeting:**
|
||
|
|
- **Valorant** — Anti-cheat (Vanguard) drives users to seek external cheats
|
||
|
|
- **Rust** — Active cheat market
|
||
|
|
- **Roblox (mobile games)** — Standoff 2 specifically targeted by Blitz
|
||
|
|
- **People Playground** — Steam Workshop worm incident
|
||
|
|
|
||
|
|
**Why These Games:**
|
||
|
|
- Large player bases = larger victim pools
|
||
|
|
- Active modding/cheating cultures = users accustomed to downloading external tools
|
||
|
|
- Virtual economies (skins, Robux, V-Bucks) = direct monetization of stolen accounts
|
||
|
|
- Young demographics = less security awareness
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 6. Scale and Success Metrics
|
||
|
|
|
||
|
|
| Metric | Value | Source |
|
||
|
|
|--------|-------|--------|
|
||
|
|
| Gaming-related infection share | 41.47% of all infostealer infections | Flare Research |
|
||
|
|
| Credentials stolen H1 2025 | 1.8 billion | Multiple sources |
|
||
|
|
| Lumma infections (Mar-May 2025) | 394,000+ Windows PCs | Microsoft |
|
||
|
|
| RenEngine compromises | 400,000+ globally; 30,000+ in US | Cyderes |
|
||
|
|
| YouTube Ghost Network videos | 3,000+ malicious videos | Check Point |
|
||
|
|
| PirateFi downloads | ~1,500 | Valve/Steam |
|
||
|
|
| Credential theft increase | 800% in H1 2025 | Flare Research |
|
||
|
|
| StealC gaming-related theft | $135,000+ in stolen assets | Industry reports |
|
||
|
|
| Top MaaS market share | Lumma + StealC + RedLine = 75%+ of infections | KELA |
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 7. Platform Defenses and Gaps
|
||
|
|
|
||
|
|
### Steam/Valve
|
||
|
|
- **Defenses:** Community reporting/flagging, ML-based anomalous code detection, trade protection (7-day lock on traded skins), post-incident user notifications
|
||
|
|
- **Gaps:** Tiny moderation team (~79 for all of Steam), reactive not proactive, no universal antivirus scanning of Workshop uploads, external links in game listings exploitable, Easy Survival RPG-style template abuse not caught
|
||
|
|
|
||
|
|
### Discord
|
||
|
|
- **Defenses:** Content moderation, link scanning, CDN abuse reporting
|
||
|
|
- **Gaps:** Expired vanity invite links can be re-registered by attackers, CDN still abused for malware hosting, DM-based scams difficult to moderate at scale
|
||
|
|
|
||
|
|
### YouTube/Google
|
||
|
|
- **Defenses:** Automated content moderation, account security measures, collaborated with Check Point to remove Ghost Network
|
||
|
|
- **Gaps:** Hijacked legitimate accounts bypass trust signals, comment manipulation creates false credibility, download links in descriptions route to external hosting
|
||
|
|
|
||
|
|
### CurseForge/Modrinth
|
||
|
|
- **Defenses:** Enhanced scanning post-Fractureiser, detection tools released, infected files removed
|
||
|
|
- **Gaps:** Account compromise of mod authors can bypass content scanning, supply chain attacks through popular modpacks
|
||
|
|
|
||
|
|
### GitHub
|
||
|
|
- **Defenses:** Community reporting, some automated scanning
|
||
|
|
- **Gaps:** Fake PoCs and game cheats hosted freely, minimal vetting of repository contents, stars/forks can be manipulated
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## 8. Emerging Trends for 2026
|
||
|
|
|
||
|
|
1. **Post-Lumma vacuum:** After Microsoft's disruption of Lumma infrastructure and developer doxxing (Aug-Oct 2025), Vidar 2.0 has emerged to fill the gap
|
||
|
|
2. **Game engine abuse:** GodLoader (Godot), RenEngine (Ren'Py), and Node.js-based loaders evade traditional AV by using legitimate game runtime environments
|
||
|
|
3. **AI-hosted infrastructure:** Blitz malware hosting C2 on Hugging Face Spaces — legitimate AI platforms as blind spots
|
||
|
|
4. **Convergence of gaming and crypto:** Fake blockchain games deliver both gaming and crypto-focused malware simultaneously
|
||
|
|
5. **Mobile gaming expansion:** Standoff 2 targeting shows shift toward mobile game communities
|
||
|
|
6. **Infostealer consolidation:** The entire attack chain is converging around infostealers as the primary payload, with gaming as the primary distribution channel
|
||
|
|
7. **Session hijacking over credential theft:** Cookie/token theft enables account access without passwords or 2FA, making traditional authentication defenses less effective
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## Sources
|
||
|
|
|
||
|
|
- [DDoS, data theft, and malware storming gaming industry — Help Net Security](https://www.helpnetsecurity.com/2025/10/27/gaming-industry-cyber-threats-risks/)
|
||
|
|
- [Cyber Threats the Gaming Industry Faced in 2025 — Guarding Pear Software](https://www.guardingpearsoftware.com/blog/cyber-threats-the-gaming-industry-faced-in-2025-and-wha-15919)
|
||
|
|
- [Flare Research: Gaming Rising Target for Infostealer Malware](https://flare.io/company/press/gaming-rising-target-infostealer-malware-41-infections-gaming-related-file)
|
||
|
|
- [Fake cheat lures gamers into spreading infostealer malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/)
|
||
|
|
- [Vidar 2.0 Infostealer via Fake Game Cheats on GitHub, Reddit — Hackread](https://hackread.com/vidar-2-0-infostealer-fake-game-cheats-github-reddit/)
|
||
|
|
- [YouTube Ghost Network Spreads Infostealer via 3,000 Fake Videos — Hackread](https://hackread.com/youtube-ghost-network-infostealer-fake-videos/)
|
||
|
|
- [From cheats to exploits: Webrat spreading via GitHub — Securelist/Kaspersky](https://securelist.com/webrat-distributed-via-github/118555/)
|
||
|
|
- [Blitz Malware: A Tale of Game Cheats and Code Repositories — Unit42/Palo Alto](https://unit42.paloaltonetworks.com/blitz-malware-2025/)
|
||
|
|
- [The Discord Invite Loop Hole Hijacked for Attacks — Check Point Research](https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/)
|
||
|
|
- ["Can you try a game I made?" Fake game sites lead to infostealers — Malwarebytes](https://www.malwarebytes.com/blog/news/2025/01/can-you-try-a-game-i-made-fake-game-sites-lead-to-information-stealers)
|
||
|
|
- [New Infostealer Campaign Uses Discord Videogame Lure — Infosecurity Magazine](https://www.infosecurity-magazine.com/news/infostealer-campaign-discord/)
|
||
|
|
- [Steam game People Playground hit by malware via Workshop — GamingOnLinux](https://www.gamingonlinux.com/2026/02/steam-game-people-playground-hit-by-malware-via-the-steam-workshop/)
|
||
|
|
- [PirateFi game on Steam caught installing password-stealing malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/)
|
||
|
|
- [Vidar Stealer: Infostealer malware discovered in Steam game — G DATA](https://blog.gdatasoftware.com/2025/04/38169-vidar-stealer)
|
||
|
|
- [Infostealer Malware Vidar distributed via Steam store — SECUINFRA](https://www.secuinfra.com/en/techtalk/infostealer-malware-vidar-spread-via-the-steam-store/)
|
||
|
|
- [FBI seeks victims of Steam games used to spread malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/)
|
||
|
|
- [Steam games abused to deliver malware once again — Malwarebytes](https://www.malwarebytes.com/blog/news/2025/07/steam-games-abused-to-deliver-malware-once-again)
|
||
|
|
- [Lumma Stealer: Breaking down delivery techniques — Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/)
|
||
|
|
- [Microsoft Dismantles Lumma Stealer Malware Infecting 400K PCs — Xcitium](https://threatlabsnews.xcitium.com/blog/microsoft-lumma-stealer-infects-400000-windows-pcs/)
|
||
|
|
- [GachiLoader: Defeating Node.js Malware — Check Point Research](https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing/)
|
||
|
|
- [RenEngine Loader and HijackLoader Attack Chain — Cyderes](https://www.cyderes.com/howler-cell/renengine-loader-hijackloader-attack-chain)
|
||
|
|
- [Gaming Engines: An Undetected Playground for Malware Loaders — Check Point Research](https://research.checkpoint.com/2024/gaming-engines-an-undetected-playground-for-malware-loaders/)
|
||
|
|
- [Malware Targeting Roblox Players Steals Crypto Wallets — CryptoTimes](https://www.cryptotimes.io/2025/12/21/malware-targeting-roblox-players-steals-crypto-wallets/)
|
||
|
|
- [Not a Kids Game: From Roblox Mod to Compromising Your Company — BleepingComputer](https://www.bleepingcomputer.com/news/security/not-a-kids-game-from-roblox-mod-to-compromising-your-company/)
|
||
|
|
- [Stealka stealer hijacks accounts via pirated software — Kaspersky](https://www.kaspersky.com/blog/windows-stealer-stealka/55058/)
|
||
|
|
- [Infostealer Malware in 2025: Credential Theft at Scale — DeepStrike](https://deepstrike.io/blog/infostealer-malware-credential-theft-2025)
|
||
|
|
- [Infostealers stole 1.8B credentials in 2025 — Vectra](https://www.vectra.ai/topics/infostealers)
|
||
|
|
- [CS2 Scam Avoidance Guide 2026 — SkinsMonkey](https://skinsmonkey.com/blog/how-to-avoid-cs2-scams-ultimate-2026-guide)
|
||
|
|
- [Lunar Client Safety Guide — Lunar Client](https://www.lunarclient.com/news/lunar-client-safety-guide)
|
||
|
|
- [Fake Minecraft, Roblox Hacks on YouTube Hide Malware — McAfee](https://www.mcafee.com/blogs/internet-security/scam-alert-fake-minecraft-roblox-hacks-on-youtube-hide-malware-target-kids/)
|
||
|
|
- [From Cracks to Crooks: YouTube as a Vector for Malware Distribution — arXiv](https://arxiv.org/html/2507.16996v1)
|
||
|
|
- [Steam Faces New Malware Crisis — WinBuzzer](https://winbuzzer.com/2025/03/24/steam-faces-new-malware-crisis-as-game-demo-infects-users-xcxwbn/)
|
||
|
|
- [Rust-based Myth Stealer via Fake Gaming Sites — The Hacker News](https://thehackernews.com/2025/06/rust-based-myth-stealer-malware-spread.html)
|
||
|
|
- [Cracked Software and YouTube Videos Spread CountLoader and GachiLoader — The Hacker News](https://thehackernews.com/2025/12/cracked-software-and-youtube-videos.html)
|