#CryptoStealer
Steam game removed after cryptostealer takes over $150K
Steam game removed after cryptostealer takes over $150K
A phishing campaign targeted streamers to get them to download it.
buff.ly
September 22, 2025 at 8:30 PM
With cryptocurrencies reaching record values in H2 2024, cryptocurrency wallet data was one of the prime targets of cybercriminals. In ESET telemetry, this was reflected in a rise in #cryptostealer detections across multiple platforms, specifically 🪟 Windows, 🍎 macOS, and 🤖 Android. 🧵 1/3
January 8, 2025 at 8:33 PM
A cluster of 26 malicious iOS apps have been uploaded on the Chinese version of the Apple App Store

The apps redirected users to phishing pages posing as legitimate cryptocurrency services

securelist.com/fakewallet-c...
FakeWallet cryptostealer propagating via iOS App Store applications
In March 2026, we uncovered more than twenty phishing apps in the Apple App Store masquerading as popular crypto wallets.
securelist.com
April 21, 2026 at 11:37 AM
Meanwhile, Lumma Stealer had a busy period: its numbers skyrocketed by almost 400% between H1 and H2 2024, it made for about 75% of cryptostealer detections, and even reared its ugly head in a campaign targeting players of Hamster Kombat 🐹⚔️, a mobile clicker game. 4/5
February 1, 2025 at 4:41 AM
📰 Infiltrasi via File LNK, Worm USB Sebarkan Clipper Pencuri Kripto Lewat Jaringan Tor

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/19/worm-usb-sebar-malware-pencuri-kripto-via-shortcut/

#bit
co#bitcoinp#clipperMalwaret#cryptoStealerr#ethereuma#keamananSiberi#lnkFileo#microsoft href="/hashtag/on" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#on
June 19, 2026 at 7:50 AM
A fake CAPTCHA leads to credential theft, EDR take-down, and crypto theft—ClearFake’s latest is dangerously advanced. #SecurityNews #ClearFake #CryptoStealer #EDR #Malware #ThreatIntel thedailytechfeed.com/clearfakes-n...
September 9, 2026 at 4:05 PM
August 7, 2026 at 6:56 PM
Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware
https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest
July 27, 2026 at 10:35 PM
Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware

https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest
July 27, 2026 at 10:00 PM
📰 Federal authorities have arrested 21-year-old Zyaire Wilkins and co-conspirators for allegedly stealing at least $220,000 in cryptocurrency through malware-infected Steam games.

🔗 https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest

#Tech #Gadgets
Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malware
The alleged thieves infected 8,000 devices.
www.theverge.com
July 19, 2026 at 8:38 PM
📰 Framework Malware OkoBot Sebarkan Lebih dari 20 Payload untuk Curi Data dan Aset Kripto

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/17/okobot-malware-framework-curi-data-crypto/

#cry
pt#cryptoStealert#cryptoWallett#cryptocurrencyr#cybersecuritya#keamananSibera#malwareo#rf="/hashtag/okobot" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#okobot
July 17, 2026 at 9:53 AM
Inside the DigitalOcean Cryptostealer: A Turkish-Linked Infostealer and Clipper Campaign with Five-Layer Persistence + Video

Introduction A sophisticated, Turkish-speaking threat actor has been running an active infostealer and cryptocurrency clipper campaign since at least June 23, 2026, with the…
Inside the DigitalOcean Cryptostealer: A Turkish-Linked Infostealer and Clipper Campaign with Five-Layer Persistence + Video
Introduction A sophisticated, Turkish-speaking threat actor has been running an active infostealer and cryptocurrency clipper campaign since at least June 23, 2026, with the latest payload update occurring on July 6. What sets this operation apart from typical commodity malware is its entire toolkit sitting in an open directory on a DigitalOcean node (46.101.111.120:8080) with anonymous read-write access, version-stamped backups showing rapid iteration from early builds to v5 in under two weeks.
undercodetesting.com
July 10, 2026 at 7:08 AM
#OpSec #CryptoStealer
The battle to beat #cyber crime is being lost as it can't keep up. Of course the Trump admin is encouraging it by hobbling #NCET & gutted #CISA
Theft as a job, lead by a felon as a way to make money, or join #Ice.
Trump USA reality show.
#Scamerica
youtube.com/post/UgkxMge...
Post from Cybernews - YouTube
It seems that antivirus developers will need to ramp up their efforts. Researchers have discovered new malware that went undetected by top antivirus programs...
youtube.com
September 14, 2025 at 7:00 AM
📰 Malware Perbankan TrickMo 'Pindah' ke Blockchain TON: Makin Sulit Dilacak dan Ditumbangkan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/11/malware-perbankan-android-trickmo-gunakan-blockchain-ton/

#and
ro#androidBankert#beritaTeknologit#cryptoStealera#keamananSibera#malwareAndroi
May 11, 2026 at 9:58 AM
A cryptostealer malware was pushed to a number of npm packages including debug, chalk , and a number of utility packages as a result of the compromise of a single contributor.

We published guidance for customers and non-customers for how to detect if you were affected:
semgrep.dev/blog/2025/ch...
September 8, 2025 at 5:21 PM
TrapDoor supply chain attack hit 34+ packages across npm, PyPI, and Crates.io, stealing wallets, SSH keys, cloud creds, browser data, and env vars via AI tool files for hidden persistence. #TrapDoor #SupplyChain #CryptoStealer
TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages...
Socket identified TrapDoor, an active cross-ecosystem crypto stealer campaign spanning npm, PyPI, and Crates.io that uses malicious developer tools to steal wallets, SSH keys, cloud credentials, browser data, and environment variables. The operation is tied to the GitHub account ddjidd564, uses the marker P-2024-001, and abuses AI-facing files like .cursorrules and CLAUDE.md for persistence and hidden prompt injection. #TrapDoor #ddjidd564 #P-2024-001 #eth-security-auditor #trap-core.js
www.hendryadrian.com
May 24, 2026 at 4:30 PM
December 31, 2025 at 1:00 AM
Steam removed BlockBlasters on Sep 21, 2025 after it was found to contain a cryptostealer that stole over $150,000, including $32,000 from streamer Raivo Plavnieks. Read more: https://getnews.me/steam-removes-blockblasters-game-after-150k-crypto-theft/ #steam #cryptodrainer #blockblasters
September 23, 2025 at 4:17 AM
Feed: "The Verge"
By: Emma Roth on Monday, September 22, 2025
Steam game removed after cryptostealer takes over $150K
A phishing campaign targeted streamers to get them to download it.
www.theverge.com
September 23, 2025 at 11:32 AM
Steam game removed after cryptostealer takes over $150K

Steam has taken down a game containing malware that drained the cryptocurrency wallets belonging to hundreds of players, as reported earlier by Bleeping Computer. The free-to-play 2D platformer, titled BlockBlasters, took more than $150,000…
Steam game removed after cryptostealer takes over $150K
Steam has taken down a game containing malware that drained the cryptocurrency wallets belonging to hundreds of players, as reported earlier by Bleeping Computer. The free-to-play 2D platformer, titled BlockBlasters, took more than $150,000 from victims, including $32,000 from a streamer raising funds for their cancer treatment. In a post on X, malware tracker vx-underground revealed that bad actors targeted some streamers with a spearphishing campaign that attempted to lure victims into promoting the game in exchange for compensation. “Unfortunately, the Steam game was actually a cryptodrainer masquerading as a legitimate video game,” vx-underground wrote in a post on X.
n24usa.com
September 22, 2025 at 9:13 PM
I just love that the npm thing was a cryptostealer and most ppl were like "who tf cares?"
September 18, 2025 at 8:46 PM
Steam game removed after cryptostealer takes over $150K https://thever.ge/Dzk4 #PCGaming #Security #Gaming #News #Tech
September 22, 2025 at 8:34 PM
Hier had ik dus nog nooit over nagedacht: als een app toegang tot je foto's heeft, kan die ook de tekst in eventuele screenshots lezen (met OCR). Gaat nu om om stelen van crypto, maar iets als WhatsApp met toegang tot de fotobibliotheek zou dat dus ook kunnen.

tweakers.net/nieuws/23158...
Kaspersky treft voor het eerst iOS-app met cryptostealer in App Store aan
Beveiligingsonderzoekers van Kaspersky hebben een nieuwe malwarecampagne aangetroffen, waarbij aanvallers via apps proberen cryptovaluta te stelen. Het is volgens de onderzoekers voor het eerst dat ee...
tweakers.net
February 18, 2025 at 8:20 AM