The post Scammers are using new malware to steal crypto login appeared on BitcoinEthereumNews.com. Crypto scammers are now using a new malware to steal crypto loginsThe post Scammers are using new malware to steal crypto login appeared on BitcoinEthereumNews.com. Crypto scammers are now using a new malware to steal crypto logins

Scammers are using new malware to steal crypto login

Crypto scammers are now using a new malware to steal crypto logins from traders and investors in the crypto gaming industry. According to research from cybersecurity firm Kaspersky, the scammers are inserting malware into pirate mods for Roblox and other games to steal crypto login credentials from users.

According to a post from Kaspersky, there is now a new variety of infostealer called Stealka, which it has so far encountered on distribution platforms like GitHub, SourceForge, Softpedia, and sites.google.com. The malware is disguised as unofficial mods, cheats, and cracks for Windows-based games and other apps. Stealka is used by scammers to exfiltrate sensitive login and browser information, which they in turn use to steal digital assets.

Scammers deploy new malware to steal digital assets

The malware primarily targets data contained in browsers such as Chrome, Opera, Firefox, Edge, Yandex, Brave, as well as the settings and databases of over 100 browser extensions. The extensions include digital asset wallets from Binance, Crypto.com, MetaMask, and Trust Wallet. It also targets password managers like LastPass, NordPass, and 1Password, and 2FA apps like Google Authenticator, Authy, and Bitwarden.

In addition, Kaspersky noted that Stealka doesn’t stop with browser extensions, noting that it can also lift encrypted private keys, seed phrase data, and wallet file paths from standalone cryptocurrency wallet apps. This includes applications like MyCrypto, MyMonero, Binance, Exodus, as well as other applications for Bitcoin, Ethereum, Solar, Novacoin, Monero, Dogecoin, and BitcoinABC.

Kaspersky cybersecurity expert Artem Ushkov explained that the new malware was detected by the company’s endpoint solutions for Windows machines in November. The Stealka malware can also steal data and authentication tokens for messaging apps like Discord and Telegram, password managers, email clients like Mailbird and Outlook, note taking applications like StickyNotes on Microsoft, Notezilla, NoteFly, and VPN clients like Windscribe, OpenVPN, and ProtonVPN.

Ushkov details the activities of the malware

According to Ushkov, the malware is based in Russia, targeting mainly users from that region. However, attacks by the malware have also been detected in other countries, including Türkiye, Brazil, Germany, and India,” he added. In view of this threat, Kaspersky has advised users to stay away from ploys by scammers trying to use this malware and others to steal their credentials. They have urged users to stay away from unofficial or pirated mods, noting the need to use antivirus software from reputable companies.

The blog also advised users against storing important and sensitive information in browsers, asking them to employ the use of two-factor authentication wherever available. In addition, they are asked to use backup codes in most situations, urging them not to store these codes on browsers or in text documents. In addition, users are enjoined to be watchful of where they download games and other files from, noting that these scammers play on users’ need to download free files from unofficial sources.

In a popular case mentioned by authorities this week, an entrepreneur based in Singapore lost his entire crypto portfolio after downloading a fake game. The entrepreneur said he came across a beta testing opportunity for Telegram in an online game called MetaToy. He noted that he felt the game was genuine because of some metrics, including the appearance of its website and the activity of its Discord. However, after downloading the game launcher, he unknowingly installed malware, which wiped more than $14,189 in crypto from his system.

While scammers can use Stealka to steal personal info and digital assets, there is no indication that it has done any huge damage, the cybersecurity expert noted. “We are not aware of the amount of crypto that has been stolen using it,” said Ushkov. “Our solutions protect against this threat: all detected Stealka malware was blocked by our solutions.” This means that it remains unknown if scammers have used the malware to steal digital assets and the scale of their theft.

Get $50 free to trade crypto when you sign up to Bybit now

Source: https://www.cryptopolitan.com/scammers-new-malware-to-steal-crypto-login/

Market Opportunity
Nowchain Logo
Nowchain Price(NOW)
$0.00201
$0.00201$0.00201
-4.28%
USD
Nowchain (NOW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Stijgt de Solana koers naar $150 door institutioneel treasury gebruik?

Stijgt de Solana koers naar $150 door institutioneel treasury gebruik?

Solana staat centraal in een nieuwe ontwikkeling binnen corporate treasury management. Mangocueticals heeft samen met Cube Group een formele SOL treasury strategie
Share
Coinstats2025/12/20 23:16
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
ViaHonest Introduces a Next-Generation RWA Marketplace for Authentic Physical Goods.

ViaHonest Introduces a Next-Generation RWA Marketplace for Authentic Physical Goods.

Summary: ViaHonest, a top-notch platform, has unleashed digital certificates of authenticity, tamper-proof item identifiers, and a transparent 2.5% commission,
Share
Techbullion2025/12/20 23:46