logo

Web3 Game Developers Targeted in Crypto Theft Scheme

ID: deccc148-9e84-5287-8e09-3297ff00304a

STIX ID: report--deccc148-9e84-5287-8e09-3297ff00304a

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-04-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Recorded Future's Insikt Group reports a Russian-language trap-phishing campaign that impersonates legitimate Web3 gaming projects and lures developers to download malicious installers that deploy infostealers (Atomic macOS Stealer, Rhadamanthys, RisePro) on macOS and Windows, with the primary objective of stealing cryptocurrency wallets and credentials. The actor uses cloned social-media accounts, fake job/NFT lures, and resilient infrastructure sharing C2 servers across multiple fake projects; victims have reported wallet drains. The report includes IOCs and mitigation guidance such as user training, verifying sources before installing software, multi-platform endpoint protections, and EDR/antivirus updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.