Files
anydeskrce-something/gaming-malware-threat-intel-report.md
T
2026-08-27 11:22:37 -06:00

21 KiB

Gaming Community Malware Distribution: Defensive Threat Intelligence Report

Date: March 2026 Scope: 2025-2026 threat landscape Classification: Defensive Threat Intelligence


Executive Summary

Gaming communities have become the single largest attack surface for infostealer malware distribution. Research by Flare analyzing 50,000+ infected devices found that 41.47% of all infostealer infections originated from gaming-related files, making gaming the #1 lure category for threat actors in 2025. The first half of 2025 saw an 800% increase in credential theft via infostealers, with 1.8 billion credentials stolen. Gaming-specific lures (cheats, mod menus, aimbots, skin changers) accounted for over 50% of gaming-related infections.

The dominant malware families are operated as Malware-as-a-Service (MaaS) — Lumma Stealer, StealC, RedLine, Raccoon, and Vidar — responsible for 75%+ of infections. The attack chain is industrialized: developers sell subscriptions, affiliates ("traffers") distribute via gaming communities, and stolen credentials are sold on dark markets.


1. Distribution Methods and Platforms

1.1 YouTube — "Ghost Network" Campaign

The single largest documented gaming malware operation in 2025. Check Point Research identified a campaign that hijacked legitimate YouTube accounts to post tutorial videos promising free game cheats, cracked software, and Roblox hacks.

  • Scale: 3,000+ malicious videos identified; output tripled in 2025 vs. prior years
  • Structure: Three-tier operation — some accounts posted videos, others flooded comments with fake praise, a third set posted community links with download URLs and passwords
  • Lures: Roblox hacks (380M monthly active players), Fortnite cheats, cracked software (Photoshop, FL Studio)
  • Delivery: Viewers instructed to disable antivirus, then download archives from Dropbox, Google Drive, or MediaFire
  • Payloads: Rhadamanthys and Lumma infostealers
  • Takedown: Google and Check Point collaborated to remove the network in October 2025

1.2 Discord — Invite Hijacking and Fake Beta Testing

Discord is abused through multiple vectors:

Expired Invite Link Hijacking:

  • Check Point Research discovered attackers re-registering expired vanity invite links
  • Users clicking trusted links from legitimate sources were silently redirected to malicious servers
  • Payloads: AsyncRAT, Skuld Stealer, ChromeKatz

"Try My Game" / Fake Beta Testing Scam:

  • Victims receive DMs from compromised accounts asking if they want to beta test a "new game"
  • Download links provided via Dropbox, Catbox, or Discord CDN
  • Archives contain NSIS or MSI installers delivering Nova Stealer, Ageo Stealer, or Hexon Stealer
  • Targets: Discord tokens, browser credentials, cryptocurrency wallets
  • Notable case: An NFT artist lost $170,000 in crypto and NFTs within hours
  • Download counts from hosting repos exceeded 1,300 per campaign

Discord CDN Abuse:

  • Malware hosted directly on Discord's CDN using compromised accounts
  • Links appear more trustworthy because they originate from discord.com domains

1.3 Steam — Malicious Games and Workshop Mods

PirateFi Incident (February 2025):

  • Free-to-play survival game on Steam Store for ~1 week (Feb 6-12, 2025)
  • Built by modifying the "Easy Survival RPG" template — was never a legitimate game
  • Contained Vidar infostealer packed in InnoSetup installer (Pirate.exe -> Howard.exe)
  • ~1,500 downloads before removal
  • Vidar used Dead Drop Resolvers on Telegram, Mastodon, and Steam profiles for C2
  • Stolen browser cookies enabled session hijacking without passwords/2FA
  • Victims' accounts then used to send phishing to contacts on Steam, Discord, email
  • FBI opened investigation and sought victims publicly
  • Valve responded reactively; sent notifications to affected users

Steam Workshop — People Playground Worm (February 2026):

  • Malicious mod "FPS++" uploaded to People Playground's Steam Workshop
  • Functioned as a worm: when activated, it replaced existing mods with infected copies
  • Destroyed save files and Steam achievements
  • Developer disabled Workshop entirely (Feb 1), released security update, re-enabled (Feb 6)
  • Highlighted that Valve does not perform universal antivirus vetting of Workshop uploads

Systemic Gaps:

  • Valve has only ~79 employees assigned to Steam (as of last public data) — small for a platform serving tens of millions
  • Moderation is largely reactive; action taken after malware reaches users
  • External links to Discord servers allowed in game listings create additional attack surface

1.4 GitHub and Code Repositories

Webrat (2025):

  • Initially distributed as cheats for Rust, Counter-Strike, and Roblox
  • Later expanded to target security researchers via fake PoC exploits
  • Capabilities: credential theft, crypto wallet access, webcam/microphone spying, keylogging, Steam/Discord/Telegram data theft

Blitz (2025):

  • Distributed through backdoored game cheats on Telegram channel (@sw1zzx_dev)
  • Targeted players of mobile game Standoff 2
  • C2 infrastructure hosted on Hugging Face Spaces (AI code repository)

Vidar 2.0:

  • Distributed via fake game cheats on GitHub and Reddit
  • Operated by Acronis-tracked campaign using both platforms for distribution

1.5 Mod Distribution Platforms (CurseForge, Modrinth)

Fractureiser (June 2023 — legacy but foundational):

  • Multiple CurseForge and Bukkit accounts compromised
  • Malicious code injected into popular mods/plugins, picked up by modpacks like "Better Minecraft" (4.6M downloads)
  • Multi-stage, multi-platform (Windows + Linux) infostealer
  • Capabilities: clipboard crypto-address swapping, Minecraft/Discord token theft, browser credential theft
  • Led to creation of community detection tools and improved platform security
  • CurseForge and Modrinth both enhanced their scanning post-incident

1.6 Fake Client/Launcher Websites

Lunar Client Impersonation:

  • Fake websites mimicking lunarclient.com distribute malware or credential phishing
  • Fake Discord bots with altered Lunar Client logos send links to phishing sites
  • Scam pages prompt Microsoft email entry, then use verification codes to hijack accounts
  • Legitimate domains: lunarclient.com, moonsworth.com, overwolf.com only

1.7 Telegram Channels

  • Used by Blitz developer to distribute backdoored cheats
  • CS2 skin scams increasingly spread through Telegram and Discord bots
  • Fake giveaways, phishing links, and fake investment offers

2. Malware Families Targeting Gamers

Family Type Distribution Notable Traits
Lumma Stealer MaaS Infostealer YouTube, Discord, fake cheats 394K+ PCs infected (Mar-May 2025); tracked as Storm-2477 by Microsoft
Vidar Infostealer Steam games (PirateFi), GitHub, fake cheats Dead Drop Resolvers on Telegram/Steam profiles; Vidar 2.0 emerged after Lumma disruption
RedLine Infostealer Fake cheats ("Cheat Lab"), GitHub Self-propagating variant asked victims to recruit friends
StealC Infostealer Gaming cheats $135K+ stolen assets via gaming infection chains
Raccoon Infostealer Roblox mods, game cracks Common in Roblox ecosystem
Rhadamanthys Infostealer YouTube Ghost Network Delivered via GachiLoader with novel VEH-based PE injection
Webrat RAT/Backdoor GitHub repos, fake game cheats Evolved from gaming cheats to fake security PoCs
Blitz Malware Telegram, game cheats Hosted C2 on Hugging Face Spaces
AsyncRAT RAT Discord invite hijacking Full remote access capability
Skuld Stealer Infostealer Discord campaigns Targets credentials and Discord tokens
GodLoader Loader Godot engine abuse Undetected by nearly all AV engines on VirusTotal
RenEngine Loader Pirated game installers 400K+ systems compromised; 30K+ in US alone
Stealka Infostealer Roblox executors, game cracks Kaspersky-discovered; targets younger users
Myth Stealer Infostealer Fake gaming sites Rust-based; targets Chrome/Firefox

3. Infection Chain — End-to-End

Typical Flow:

1. LURE CREATION
   - Threat actor creates YouTube video / Discord message / GitHub repo
   - Content promises: free cheats, game cracks, skin changers, Robux generators
   - Social proof manufactured: fake comments, likes, download counts

2. TRAFFIC ROUTING
   - Victim clicks link in video description / Discord DM / GitHub README
   - Routed through Linkvertise or similar ad-gate services (monetization + obfuscation)
   - May pass through Prometheus TDS (Traffic Distribution System) on compromised sites
   - Final landing: MediaFire, Mega.nz, Dropbox, Google Drive, Discord CDN

3. SOCIAL ENGINEERING
   - Instructions to disable antivirus ("required for the cheat to work")
   - Password-protected archives (evades automated scanning)
   - Sometimes partially functional tools included to build trust

4. INITIAL EXECUTION
   - Archive contains installer (NSIS, MSI, InnoSetup) or direct executable
   - May use game engines as loaders (Godot/GDScript, Ren'Py, Lua runtime)
   - GachiLoader uses Node.js with Vectored Exception Handler abuse
   - Batch files, Lua scripts, or compiled binaries serve as first stage

5. PAYLOAD DELIVERY
   - Loader contacts C2 via Dead Drop Resolvers (Telegram, Steam profiles, Mastodon)
   - Downloads final payload: Lumma, Vidar, RedLine, Rhadamanthys, etc.
   - Modular architecture allows payload swaps without changing initial vector

6. DATA EXFILTRATION
   - Browser passwords, cookies, session tokens
   - Discord tokens, Steam sessions
   - Cryptocurrency wallet data
   - Clipboard monitoring for crypto address swapping
   - Screenshots, keylogging, webcam access (Webrat)

7. PROPAGATION
   - Stolen accounts used to send malicious links to victim's contacts
   - Self-spreading variants (RedLine "Cheat Lab") incentivize victims to recruit
   - Steam Workshop worms replicate by replacing existing mods

4. Trust-Building and Social Engineering Tactics

  1. Manufactured social proof: Fake YouTube comments, likes, and community posts create illusion of legitimacy
  2. Hijacked legitimate accounts: Compromised YouTube channels with existing subscriber bases used to post malware videos
  3. Partially functional tools: Cheats that actually work (at least initially) while silently running malware
  4. Friend-to-friend spreading: Stolen accounts send links that appear to come from trusted friends
  5. Recruitment incentives: RedLine variant promised "free cheat copy if you get friends to install"
  6. Professional presentation: Fake games like PirateFi built using real game templates with store pages, screenshots
  7. Targeting young users: Roblox-focused campaigns exploit children who are less security-aware; promise free Robux
  8. Impersonation of legitimate tools: Fake Lunar Client, fake mod loaders, fake game launchers mimicking real products
  9. Urgency and exclusivity: "Limited beta test" invitations, time-limited offers
  10. Anti-AV normalization: Gaming community culture where disabling antivirus for cheats is common and expected

5. Games and Communities Most Targeted

Tier 1 — Highest Targeting:

  • Roblox — 380M monthly active players, younger demographic, executor/mod culture
  • Minecraft — Massive modding ecosystem, CurseForge/Modrinth supply chain
  • Counter-Strike 2 — Skin trading economy worth billions, cheat culture
  • Fortnite — Huge player base, active cheat-seeking community
  • Grand Theft Auto — Mod menus, cracked versions, GTA Online cheats

Tier 2 — Significant Targeting:

  • Valorant — Anti-cheat (Vanguard) drives users to seek external cheats
  • Rust — Active cheat market
  • Roblox (mobile games) — Standoff 2 specifically targeted by Blitz
  • People Playground — Steam Workshop worm incident

Why These Games:

  • Large player bases = larger victim pools
  • Active modding/cheating cultures = users accustomed to downloading external tools
  • Virtual economies (skins, Robux, V-Bucks) = direct monetization of stolen accounts
  • Young demographics = less security awareness

6. Scale and Success Metrics

Metric Value Source
Gaming-related infection share 41.47% of all infostealer infections Flare Research
Credentials stolen H1 2025 1.8 billion Multiple sources
Lumma infections (Mar-May 2025) 394,000+ Windows PCs Microsoft
RenEngine compromises 400,000+ globally; 30,000+ in US Cyderes
YouTube Ghost Network videos 3,000+ malicious videos Check Point
PirateFi downloads ~1,500 Valve/Steam
Credential theft increase 800% in H1 2025 Flare Research
StealC gaming-related theft $135,000+ in stolen assets Industry reports
Top MaaS market share Lumma + StealC + RedLine = 75%+ of infections KELA

7. Platform Defenses and Gaps

Steam/Valve

  • Defenses: Community reporting/flagging, ML-based anomalous code detection, trade protection (7-day lock on traded skins), post-incident user notifications
  • Gaps: Tiny moderation team (~79 for all of Steam), reactive not proactive, no universal antivirus scanning of Workshop uploads, external links in game listings exploitable, Easy Survival RPG-style template abuse not caught

Discord

  • Defenses: Content moderation, link scanning, CDN abuse reporting
  • Gaps: Expired vanity invite links can be re-registered by attackers, CDN still abused for malware hosting, DM-based scams difficult to moderate at scale

YouTube/Google

  • Defenses: Automated content moderation, account security measures, collaborated with Check Point to remove Ghost Network
  • Gaps: Hijacked legitimate accounts bypass trust signals, comment manipulation creates false credibility, download links in descriptions route to external hosting

CurseForge/Modrinth

  • Defenses: Enhanced scanning post-Fractureiser, detection tools released, infected files removed
  • Gaps: Account compromise of mod authors can bypass content scanning, supply chain attacks through popular modpacks

GitHub

  • Defenses: Community reporting, some automated scanning
  • Gaps: Fake PoCs and game cheats hosted freely, minimal vetting of repository contents, stars/forks can be manipulated

  1. Post-Lumma vacuum: After Microsoft's disruption of Lumma infrastructure and developer doxxing (Aug-Oct 2025), Vidar 2.0 has emerged to fill the gap
  2. Game engine abuse: GodLoader (Godot), RenEngine (Ren'Py), and Node.js-based loaders evade traditional AV by using legitimate game runtime environments
  3. AI-hosted infrastructure: Blitz malware hosting C2 on Hugging Face Spaces — legitimate AI platforms as blind spots
  4. Convergence of gaming and crypto: Fake blockchain games deliver both gaming and crypto-focused malware simultaneously
  5. Mobile gaming expansion: Standoff 2 targeting shows shift toward mobile game communities
  6. Infostealer consolidation: The entire attack chain is converging around infostealers as the primary payload, with gaming as the primary distribution channel
  7. Session hijacking over credential theft: Cookie/token theft enables account access without passwords or 2FA, making traditional authentication defenses less effective

Sources