logo

Hacker sneaks infostealer malware into early access Steam game

ID: 163b265d-6f93-50b2-9a17-50de0c949ec0

STIX ID: report--163b265d-6f93-50b2-9a17-50de0c949ec0

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-07-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A threat actor named EncryptHub (Larva-208) injected HijackLoader and Fickle Stealer into the early-access Steam game Chemia to distribute info-stealing malware to players; the campaign uses Telegram for C2 and PowerShell to fetch payloads. Researchers linked the actor to previous large-scale campaigns and noted the malicious binaries run stealthily in the background, leaving the game available on Steam and raising supply-chain and platform-trust concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.