Quickpost: SteamStealers via Github
ID: 033e25d8-b0ed-59ea-bae5-c93c33eb981e
STIX ID: report--033e25d8-b0ed-59ea-bae5-c93c33eb981e
Feed Name: Blaze's Security Blog
Threat Score
This advisory reports renewed SteamStealer activity and related infostealers (e.g., Evrial) abusing GitHub to host payloads and replace Steam trade offer links via clipboard hijacking, including an example redirect from a lure image to a malicious .scr file on GitHub and debug-path artifacts tying samples to the original SteamStealer codebase; it urges users to follow prior prevention tips.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
