The post New Malware Poses as Roblox Mods to Steal Crypto Credentials appeared on BitcoinEthereumNews.com. In brief Cybersecurity experts at Kaspersky have discoveredThe post New Malware Poses as Roblox Mods to Steal Crypto Credentials appeared on BitcoinEthereumNews.com. In brief Cybersecurity experts at Kaspersky have discovered

New Malware Poses as Roblox Mods to Steal Crypto Credentials

In brief

  • Cybersecurity experts at Kaspersky have discovered a new type of infostealer that has the ability to steal sensitive info from a wide variety of Windows-based browsers and apps.
  • Hackers are inserting the malware in unofficial mods for games such as Roblox, as well as various Windows apps.
  • Kaspersky tells Decrypt that it has no data on the amount of crypto stolen using the infostealer.

Hackers are inserting infostealer malware into pirated mods for Roblox and other games, according to research from cybersecurity company Kaspersky.

A blog post from Kaspersky reveals that it has identified a new variety of infostealer called Stealka, which it has so far encountered on distribution platforms such as GitHub, SourceForge, Softpedia and sites.google.com.

Disguised as unofficial mods, cheats and cracks for Windows-based games and other apps, Stealka exfiltrates sensitive login and browser information, which its operators can use to steal crypto.

Crypto wallets targeted

The malware primarily targets data contained by browsers such as Chrome, Firefox, Opera, Yandex Browser, Edge, Brave, as well as the settings and databases of over 100 browser extensions.

Such extensions include cryptocurrency wallets from Binance, Coinbase, MetaMask, Crypto.com and Trust Wallet, as well as password managers (1Password, NordPass, LastPass) and 2FA apps (Google Authenticator, Authy, Bitwarden).

In fact, Stealka’s reach doesn’t stop with browser extensions, since it can also lift (encrypted) private keys, seed phrase data and wallet file paths from standalone cryptocurrency wallet apps.

This includes apps from Binance, Exodus, MyCrypto and MyMonero, as well as wallet apps for Bitcoin, BitcoinABC, Dogecoin, Ethereum, Monero, Novacoin and Solar.

Away from crypto, the Stealka malware has the ability to steal data and authentication tokens for messaging apps (e.g. Discord and Telegram), password manager apps (e.g. 1Password, Bitward, LastPass), email clients (e.g. Gmail Notifier Pro, Mailbird, Outlook), notetaking apps (NoteFly, Notezilla, Microsoft StickyNotes), and VPN clients (e.g. OpenVPN, ProtonVPN, WindscribeVPN).

Speaking to Decrypt, Kaspersky cybersecurity expert Artem Ushkov explained that the new malware “was detected by Kaspersky endpoint protection solutions on Windows machines in November 2025.”

As is the case with similar malware, Ushkov reports that most of the users targeted by Stealka are based in Russia.

“However, attacks by the malware have also been detected in other countries, including Türkiye, Brazil, Germany and India,” he added.

How to stay safe

In view of the threat Stealka, Kaspersky advises in its blog that, aside from using reputable antivirus software, users should steer clear of unofficial and pirated mods.

The blog also advises against storing important info in browsers, and urges users to employ two-factor authentication wherever available, while also making use of backup codes (but without storing them on browsers or in text documents).

While Stealka’s potential for stealing info and, by extension, crypto seems intimidating, there’s currently no indication that it has resulted in significant losses.

“We are not aware of the amount of crypto that has been stolen using it,” said Ushkov. “Our solutions protect against this threat: all detected Stealka malware was blocked by our solutions.”

GG Newsletter

Get the latest web3 gaming news, hear directly from gaming studios and influencers covering the space, and receive power-ups from our partners.

Source: https://decrypt.co/353072/new-malware-poses-as-roblox-mods-to-steal-crypto-credentials

Market Opportunity
Farcana Logo
Farcana Price(FAR)
$0.00071
$0.00071$0.00071
-11.36%
USD
Farcana (FAR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Yarm Explained: Turning Trust and Tweets into Yield

Yarm Explained: Turning Trust and Tweets into Yield

tl;dr: Yarm is a new platform by Mitosis and Kaito AI that turns social influence into onchain yield. Yappers earn Mindshare by posting…Continue reading on Coinmonks »
Share
Medium2025/09/18 14:43
Crossmint Partners with MoneyGram for USDC Remittances in Colombia

Crossmint Partners with MoneyGram for USDC Remittances in Colombia

TLDR Crossmint enables MoneyGram’s new stablecoin payment app for cross-border transfers. The new app allows USDC transfers from the US to Colombia, boosting financial inclusion. MoneyGram offers USDC savings and Visa-linked spending for Colombian users. The collaboration simplifies cross-border payments with enterprise-grade blockchain tech. MoneyGram, a global leader in remittance services, launched its stablecoin-powered cross-border [...] The post Crossmint Partners with MoneyGram for USDC Remittances in Colombia appeared first on CoinCentral.
Share
Coincentral2025/09/18 21:02
US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

PANews reported on September 30th that the U.S. Securities and Exchange Commission (SEC) has suspended trading in QMMM Holdings Ltd.'s stock after its share price surged nearly 1,000% in less than three weeks, according to Bloomberg. The SEC stated on Monday that recommendations to buy QMMM stock posted on social media by "unidentified individuals" may have manipulated its share price. Since QMMM announced earlier this month that it would establish a "diversified cryptocurrency treasury" with an initial investment of $100 million, targeting investments in Bitcoin, Ethereum, and Solana, its share price has surged 959%. The SEC stated that the trading suspension is a temporary measure and will end at 11:59 PM EST on October 10th. On Monday, the SEC also suspended trading in Smart Digital Group Ltd.'s shares for similar reasons. The suspension will also expire at 11:59 PM ET on October 10. The company announced last week that it would establish a "diversified cryptocurrency asset pool," focusing on digital assets like Bitcoin and Ethereum. Since the announcement, its stock price has fallen significantly.
Share
PANews2025/09/30 08:32