# Gaming Community Malware Distribution: Defensive Threat Intelligence Report **Date:** March 2026 **Scope:** 2025-2026 threat landscape **Classification:** Defensive Threat Intelligence --- ## Executive Summary Gaming communities have become the single largest attack surface for infostealer malware distribution. Research by Flare analyzing 50,000+ infected devices found that **41.47% of all infostealer infections originated from gaming-related files**, making gaming the #1 lure category for threat actors in 2025. The first half of 2025 saw an **800% increase in credential theft via infostealers**, with 1.8 billion credentials stolen. Gaming-specific lures (cheats, mod menus, aimbots, skin changers) accounted for over 50% of gaming-related infections. The dominant malware families are operated as **Malware-as-a-Service (MaaS)** — Lumma Stealer, StealC, RedLine, Raccoon, and Vidar — responsible for 75%+ of infections. The attack chain is industrialized: developers sell subscriptions, affiliates ("traffers") distribute via gaming communities, and stolen credentials are sold on dark markets. --- ## 1. Distribution Methods and Platforms ### 1.1 YouTube — "Ghost Network" Campaign The single largest documented gaming malware operation in 2025. Check Point Research identified a campaign that **hijacked legitimate YouTube accounts** to post tutorial videos promising free game cheats, cracked software, and Roblox hacks. - **Scale:** 3,000+ malicious videos identified; output tripled in 2025 vs. prior years - **Structure:** Three-tier operation — some accounts posted videos, others flooded comments with fake praise, a third set posted community links with download URLs and passwords - **Lures:** Roblox hacks (380M monthly active players), Fortnite cheats, cracked software (Photoshop, FL Studio) - **Delivery:** Viewers instructed to disable antivirus, then download archives from Dropbox, Google Drive, or MediaFire - **Payloads:** Rhadamanthys and Lumma infostealers - **Takedown:** Google and Check Point collaborated to remove the network in October 2025 ### 1.2 Discord — Invite Hijacking and Fake Beta Testing Discord is abused through multiple vectors: **Expired Invite Link Hijacking:** - Check Point Research discovered attackers re-registering expired vanity invite links - Users clicking trusted links from legitimate sources were silently redirected to malicious servers - Payloads: AsyncRAT, Skuld Stealer, ChromeKatz **"Try My Game" / Fake Beta Testing Scam:** - Victims receive DMs from compromised accounts asking if they want to beta test a "new game" - Download links provided via Dropbox, Catbox, or Discord CDN - Archives contain NSIS or MSI installers delivering Nova Stealer, Ageo Stealer, or Hexon Stealer - Targets: Discord tokens, browser credentials, cryptocurrency wallets - Notable case: An NFT artist lost $170,000 in crypto and NFTs within hours - Download counts from hosting repos exceeded 1,300 per campaign **Discord CDN Abuse:** - Malware hosted directly on Discord's CDN using compromised accounts - Links appear more trustworthy because they originate from discord.com domains ### 1.3 Steam — Malicious Games and Workshop Mods **PirateFi Incident (February 2025):** - Free-to-play survival game on Steam Store for ~1 week (Feb 6-12, 2025) - Built by modifying the "Easy Survival RPG" template — was never a legitimate game - Contained Vidar infostealer packed in InnoSetup installer (Pirate.exe -> Howard.exe) - ~1,500 downloads before removal - Vidar used Dead Drop Resolvers on Telegram, Mastodon, and Steam profiles for C2 - Stolen browser cookies enabled session hijacking without passwords/2FA - Victims' accounts then used to send phishing to contacts on Steam, Discord, email - **FBI opened investigation** and sought victims publicly - Valve responded reactively; sent notifications to affected users **Steam Workshop — People Playground Worm (February 2026):** - Malicious mod "FPS++" uploaded to People Playground's Steam Workshop - Functioned as a worm: when activated, it replaced existing mods with infected copies - Destroyed save files and Steam achievements - Developer disabled Workshop entirely (Feb 1), released security update, re-enabled (Feb 6) - Highlighted that **Valve does not perform universal antivirus vetting** of Workshop uploads **Systemic Gaps:** - Valve has only ~79 employees assigned to Steam (as of last public data) — small for a platform serving tens of millions - Moderation is largely reactive; action taken after malware reaches users - External links to Discord servers allowed in game listings create additional attack surface ### 1.4 GitHub and Code Repositories **Webrat (2025):** - Initially distributed as cheats for Rust, Counter-Strike, and Roblox - Later expanded to target security researchers via fake PoC exploits - Capabilities: credential theft, crypto wallet access, webcam/microphone spying, keylogging, Steam/Discord/Telegram data theft **Blitz (2025):** - Distributed through backdoored game cheats on Telegram channel (@sw1zzx_dev) - Targeted players of mobile game Standoff 2 - C2 infrastructure hosted on Hugging Face Spaces (AI code repository) **Vidar 2.0:** - Distributed via fake game cheats on GitHub and Reddit - Operated by Acronis-tracked campaign using both platforms for distribution ### 1.5 Mod Distribution Platforms (CurseForge, Modrinth) **Fractureiser (June 2023 — legacy but foundational):** - Multiple CurseForge and Bukkit accounts compromised - Malicious code injected into popular mods/plugins, picked up by modpacks like "Better Minecraft" (4.6M downloads) - Multi-stage, multi-platform (Windows + Linux) infostealer - Capabilities: clipboard crypto-address swapping, Minecraft/Discord token theft, browser credential theft - Led to creation of community detection tools and improved platform security - CurseForge and Modrinth both enhanced their scanning post-incident ### 1.6 Fake Client/Launcher Websites **Lunar Client Impersonation:** - Fake websites mimicking lunarclient.com distribute malware or credential phishing - Fake Discord bots with altered Lunar Client logos send links to phishing sites - Scam pages prompt Microsoft email entry, then use verification codes to hijack accounts - Legitimate domains: lunarclient.com, moonsworth.com, overwolf.com only ### 1.7 Telegram Channels - Used by Blitz developer to distribute backdoored cheats - CS2 skin scams increasingly spread through Telegram and Discord bots - Fake giveaways, phishing links, and fake investment offers --- ## 2. Malware Families Targeting Gamers | Family | Type | Distribution | Notable Traits | |--------|------|-------------|----------------| | **Lumma Stealer** | MaaS Infostealer | YouTube, Discord, fake cheats | 394K+ PCs infected (Mar-May 2025); tracked as Storm-2477 by Microsoft | | **Vidar** | Infostealer | Steam games (PirateFi), GitHub, fake cheats | Dead Drop Resolvers on Telegram/Steam profiles; Vidar 2.0 emerged after Lumma disruption | | **RedLine** | Infostealer | Fake cheats ("Cheat Lab"), GitHub | Self-propagating variant asked victims to recruit friends | | **StealC** | Infostealer | Gaming cheats | $135K+ stolen assets via gaming infection chains | | **Raccoon** | Infostealer | Roblox mods, game cracks | Common in Roblox ecosystem | | **Rhadamanthys** | Infostealer | YouTube Ghost Network | Delivered via GachiLoader with novel VEH-based PE injection | | **Webrat** | RAT/Backdoor | GitHub repos, fake game cheats | Evolved from gaming cheats to fake security PoCs | | **Blitz** | Malware | Telegram, game cheats | Hosted C2 on Hugging Face Spaces | | **AsyncRAT** | RAT | Discord invite hijacking | Full remote access capability | | **Skuld Stealer** | Infostealer | Discord campaigns | Targets credentials and Discord tokens | | **GodLoader** | Loader | Godot engine abuse | Undetected by nearly all AV engines on VirusTotal | | **RenEngine** | Loader | Pirated game installers | 400K+ systems compromised; 30K+ in US alone | | **Stealka** | Infostealer | Roblox executors, game cracks | Kaspersky-discovered; targets younger users | | **Myth Stealer** | Infostealer | Fake gaming sites | Rust-based; targets Chrome/Firefox | --- ## 3. Infection Chain — End-to-End ### Typical Flow: ``` 1. LURE CREATION - Threat actor creates YouTube video / Discord message / GitHub repo - Content promises: free cheats, game cracks, skin changers, Robux generators - Social proof manufactured: fake comments, likes, download counts 2. TRAFFIC ROUTING - Victim clicks link in video description / Discord DM / GitHub README - Routed through Linkvertise or similar ad-gate services (monetization + obfuscation) - May pass through Prometheus TDS (Traffic Distribution System) on compromised sites - Final landing: MediaFire, Mega.nz, Dropbox, Google Drive, Discord CDN 3. SOCIAL ENGINEERING - Instructions to disable antivirus ("required for the cheat to work") - Password-protected archives (evades automated scanning) - Sometimes partially functional tools included to build trust 4. INITIAL EXECUTION - Archive contains installer (NSIS, MSI, InnoSetup) or direct executable - May use game engines as loaders (Godot/GDScript, Ren'Py, Lua runtime) - GachiLoader uses Node.js with Vectored Exception Handler abuse - Batch files, Lua scripts, or compiled binaries serve as first stage 5. PAYLOAD DELIVERY - Loader contacts C2 via Dead Drop Resolvers (Telegram, Steam profiles, Mastodon) - Downloads final payload: Lumma, Vidar, RedLine, Rhadamanthys, etc. - Modular architecture allows payload swaps without changing initial vector 6. DATA EXFILTRATION - Browser passwords, cookies, session tokens - Discord tokens, Steam sessions - Cryptocurrency wallet data - Clipboard monitoring for crypto address swapping - Screenshots, keylogging, webcam access (Webrat) 7. PROPAGATION - Stolen accounts used to send malicious links to victim's contacts - Self-spreading variants (RedLine "Cheat Lab") incentivize victims to recruit - Steam Workshop worms replicate by replacing existing mods ``` --- ## 4. Trust-Building and Social Engineering Tactics 1. **Manufactured social proof:** Fake YouTube comments, likes, and community posts create illusion of legitimacy 2. **Hijacked legitimate accounts:** Compromised YouTube channels with existing subscriber bases used to post malware videos 3. **Partially functional tools:** Cheats that actually work (at least initially) while silently running malware 4. **Friend-to-friend spreading:** Stolen accounts send links that appear to come from trusted friends 5. **Recruitment incentives:** RedLine variant promised "free cheat copy if you get friends to install" 6. **Professional presentation:** Fake games like PirateFi built using real game templates with store pages, screenshots 7. **Targeting young users:** Roblox-focused campaigns exploit children who are less security-aware; promise free Robux 8. **Impersonation of legitimate tools:** Fake Lunar Client, fake mod loaders, fake game launchers mimicking real products 9. **Urgency and exclusivity:** "Limited beta test" invitations, time-limited offers 10. **Anti-AV normalization:** Gaming community culture where disabling antivirus for cheats is common and expected --- ## 5. Games and Communities Most Targeted **Tier 1 — Highest Targeting:** - **Roblox** — 380M monthly active players, younger demographic, executor/mod culture - **Minecraft** — Massive modding ecosystem, CurseForge/Modrinth supply chain - **Counter-Strike 2** — Skin trading economy worth billions, cheat culture - **Fortnite** — Huge player base, active cheat-seeking community - **Grand Theft Auto** — Mod menus, cracked versions, GTA Online cheats **Tier 2 — Significant Targeting:** - **Valorant** — Anti-cheat (Vanguard) drives users to seek external cheats - **Rust** — Active cheat market - **Roblox (mobile games)** — Standoff 2 specifically targeted by Blitz - **People Playground** — Steam Workshop worm incident **Why These Games:** - Large player bases = larger victim pools - Active modding/cheating cultures = users accustomed to downloading external tools - Virtual economies (skins, Robux, V-Bucks) = direct monetization of stolen accounts - Young demographics = less security awareness --- ## 6. Scale and Success Metrics | Metric | Value | Source | |--------|-------|--------| | Gaming-related infection share | 41.47% of all infostealer infections | Flare Research | | Credentials stolen H1 2025 | 1.8 billion | Multiple sources | | Lumma infections (Mar-May 2025) | 394,000+ Windows PCs | Microsoft | | RenEngine compromises | 400,000+ globally; 30,000+ in US | Cyderes | | YouTube Ghost Network videos | 3,000+ malicious videos | Check Point | | PirateFi downloads | ~1,500 | Valve/Steam | | Credential theft increase | 800% in H1 2025 | Flare Research | | StealC gaming-related theft | $135,000+ in stolen assets | Industry reports | | Top MaaS market share | Lumma + StealC + RedLine = 75%+ of infections | KELA | --- ## 7. Platform Defenses and Gaps ### Steam/Valve - **Defenses:** Community reporting/flagging, ML-based anomalous code detection, trade protection (7-day lock on traded skins), post-incident user notifications - **Gaps:** Tiny moderation team (~79 for all of Steam), reactive not proactive, no universal antivirus scanning of Workshop uploads, external links in game listings exploitable, Easy Survival RPG-style template abuse not caught ### Discord - **Defenses:** Content moderation, link scanning, CDN abuse reporting - **Gaps:** Expired vanity invite links can be re-registered by attackers, CDN still abused for malware hosting, DM-based scams difficult to moderate at scale ### YouTube/Google - **Defenses:** Automated content moderation, account security measures, collaborated with Check Point to remove Ghost Network - **Gaps:** Hijacked legitimate accounts bypass trust signals, comment manipulation creates false credibility, download links in descriptions route to external hosting ### CurseForge/Modrinth - **Defenses:** Enhanced scanning post-Fractureiser, detection tools released, infected files removed - **Gaps:** Account compromise of mod authors can bypass content scanning, supply chain attacks through popular modpacks ### GitHub - **Defenses:** Community reporting, some automated scanning - **Gaps:** Fake PoCs and game cheats hosted freely, minimal vetting of repository contents, stars/forks can be manipulated --- ## 8. Emerging Trends for 2026 1. **Post-Lumma vacuum:** After Microsoft's disruption of Lumma infrastructure and developer doxxing (Aug-Oct 2025), Vidar 2.0 has emerged to fill the gap 2. **Game engine abuse:** GodLoader (Godot), RenEngine (Ren'Py), and Node.js-based loaders evade traditional AV by using legitimate game runtime environments 3. **AI-hosted infrastructure:** Blitz malware hosting C2 on Hugging Face Spaces — legitimate AI platforms as blind spots 4. **Convergence of gaming and crypto:** Fake blockchain games deliver both gaming and crypto-focused malware simultaneously 5. **Mobile gaming expansion:** Standoff 2 targeting shows shift toward mobile game communities 6. **Infostealer consolidation:** The entire attack chain is converging around infostealers as the primary payload, with gaming as the primary distribution channel 7. **Session hijacking over credential theft:** Cookie/token theft enables account access without passwords or 2FA, making traditional authentication defenses less effective --- ## Sources - [DDoS, data theft, and malware storming gaming industry — Help Net Security](https://www.helpnetsecurity.com/2025/10/27/gaming-industry-cyber-threats-risks/) - [Cyber Threats the Gaming Industry Faced in 2025 — Guarding Pear Software](https://www.guardingpearsoftware.com/blog/cyber-threats-the-gaming-industry-faced-in-2025-and-wha-15919) - [Flare Research: Gaming Rising Target for Infostealer Malware](https://flare.io/company/press/gaming-rising-target-infostealer-malware-41-infections-gaming-related-file) - [Fake cheat lures gamers into spreading infostealer malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/) - [Vidar 2.0 Infostealer via Fake Game Cheats on GitHub, Reddit — Hackread](https://hackread.com/vidar-2-0-infostealer-fake-game-cheats-github-reddit/) - [YouTube Ghost Network Spreads Infostealer via 3,000 Fake Videos — Hackread](https://hackread.com/youtube-ghost-network-infostealer-fake-videos/) - [From cheats to exploits: Webrat spreading via GitHub — Securelist/Kaspersky](https://securelist.com/webrat-distributed-via-github/118555/) - [Blitz Malware: A Tale of Game Cheats and Code Repositories — Unit42/Palo Alto](https://unit42.paloaltonetworks.com/blitz-malware-2025/) - [The Discord Invite Loop Hole Hijacked for Attacks — Check Point Research](https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/) - ["Can you try a game I made?" Fake game sites lead to infostealers — Malwarebytes](https://www.malwarebytes.com/blog/news/2025/01/can-you-try-a-game-i-made-fake-game-sites-lead-to-information-stealers) - [New Infostealer Campaign Uses Discord Videogame Lure — Infosecurity Magazine](https://www.infosecurity-magazine.com/news/infostealer-campaign-discord/) - [Steam game People Playground hit by malware via Workshop — GamingOnLinux](https://www.gamingonlinux.com/2026/02/steam-game-people-playground-hit-by-malware-via-the-steam-workshop/) - [PirateFi game on Steam caught installing password-stealing malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/) - [Vidar Stealer: Infostealer malware discovered in Steam game — G DATA](https://blog.gdatasoftware.com/2025/04/38169-vidar-stealer) - [Infostealer Malware Vidar distributed via Steam store — SECUINFRA](https://www.secuinfra.com/en/techtalk/infostealer-malware-vidar-spread-via-the-steam-store/) - [FBI seeks victims of Steam games used to spread malware — BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/) - [Steam games abused to deliver malware once again — Malwarebytes](https://www.malwarebytes.com/blog/news/2025/07/steam-games-abused-to-deliver-malware-once-again) - [Lumma Stealer: Breaking down delivery techniques — Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/) - [Microsoft Dismantles Lumma Stealer Malware Infecting 400K PCs — Xcitium](https://threatlabsnews.xcitium.com/blog/microsoft-lumma-stealer-infects-400000-windows-pcs/) - [GachiLoader: Defeating Node.js Malware — Check Point Research](https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing/) - [RenEngine Loader and HijackLoader Attack Chain — Cyderes](https://www.cyderes.com/howler-cell/renengine-loader-hijackloader-attack-chain) - [Gaming Engines: An Undetected Playground for Malware Loaders — Check Point Research](https://research.checkpoint.com/2024/gaming-engines-an-undetected-playground-for-malware-loaders/) - [Malware Targeting Roblox Players Steals Crypto Wallets — CryptoTimes](https://www.cryptotimes.io/2025/12/21/malware-targeting-roblox-players-steals-crypto-wallets/) - [Not a Kids Game: From Roblox Mod to Compromising Your Company — BleepingComputer](https://www.bleepingcomputer.com/news/security/not-a-kids-game-from-roblox-mod-to-compromising-your-company/) - [Stealka stealer hijacks accounts via pirated software — Kaspersky](https://www.kaspersky.com/blog/windows-stealer-stealka/55058/) - [Infostealer Malware in 2025: Credential Theft at Scale — DeepStrike](https://deepstrike.io/blog/infostealer-malware-credential-theft-2025) - [Infostealers stole 1.8B credentials in 2025 — Vectra](https://www.vectra.ai/topics/infostealers) - [CS2 Scam Avoidance Guide 2026 — SkinsMonkey](https://skinsmonkey.com/blog/how-to-avoid-cs2-scams-ultimate-2026-guide) - [Lunar Client Safety Guide — Lunar Client](https://www.lunarclient.com/news/lunar-client-safety-guide) - [Fake Minecraft, Roblox Hacks on YouTube Hide Malware — McAfee](https://www.mcafee.com/blogs/internet-security/scam-alert-fake-minecraft-roblox-hacks-on-youtube-hide-malware-target-kids/) - [From Cracks to Crooks: YouTube as a Vector for Malware Distribution — arXiv](https://arxiv.org/html/2507.16996v1) - [Steam Faces New Malware Crisis — WinBuzzer](https://winbuzzer.com/2025/03/24/steam-faces-new-malware-crisis-as-game-demo-infects-users-xcxwbn/) - [Rust-based Myth Stealer via Fake Gaming Sites — The Hacker News](https://thehackernews.com/2025/06/rust-based-myth-stealer-malware-spread.html) - [Cracked Software and YouTube Videos Spread CountLoader and GachiLoader — The Hacker News](https://thehackernews.com/2025/12/cracked-software-and-youtube-videos.html)