logo

Gamers, get ready: scammers disguise cryptocurrency and password-stealing Scavenger trojans as cheats and mods

ID: ebae3956-278d-5714-b0e2-f82d9516aede

STIX ID: report--ebae3956-278d-5714-b0e2-f82d9516aede

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2025-07-24

Date Updated: 2026-04-27

...
...

Doctor Web researchers describe Trojan.Scavenger, a multi-stage Windows malware family distributed via fake game patches and plugins that exploits DLL Search Order Hijacking to load malicious DLLs into Chromium-based browsers and crypto wallet applications; the malware disables sandboxing and extension verification, modifies/serves tampered extensions from ServiceWorkerCache, hooks V8 and file APIs to harvest mnemonic phrases, private keys, cookies and passwords, and exfiltrates these to C2 servers—Doctor Web added protections and published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.