The US Federal Bureau of Investigation (FBI) announced the arrest of a 21-year-old Florida resident accused of orchestrating a scheme to distribute malicious software through video games. According to the investigation, the perpetrators managed to steal approximately $220,000 in cryptocurrency.
According to the indictment, the suspect acted with several accomplices for about two years. During this time, they embedded malicious code into eight computer games. Once installed, these projects covertly collected saved passwords from users' computers, which were then used to gain access to cryptocurrency wallets.
Investigators claim that the criminal group actively promoted the infected games through social media. Additionally, the perpetrators used bots to identify potential victims with significant amounts of cryptocurrency. The FBI was able to identify the suspect by tracking stolen bitcoins – some of the funds were spent on purchasing gift cards, which were mainly used to pay for Uber Eats orders.
Among the games containing malware were Lunara, PirateFi, BlockBlasters, and Lampy. In the latter case, the malicious code was added after one of the updates. All listed projects were removed from Steam earlier this year after the FBI announced an investigation into the spread of malware through the platform.
Although the case materials do not explicitly state that Steam was used as the primary platform for distributing all infected games, the listed projects were available in the Valve store until recently.