The FBI arrested a 21-year-old Florida man this week. The prosecution alleges that he and a number of unnamed associates over the past two years have been using the Steam platform to launch games with malicious software to induce users to download post-installation equipment and further steal encrypted wallet assets.

Game involved and scale of victimization

According to law enforcement documents, games issued by this group include Block Blasters, Dashverse, Lammy, Lunara and PirateFi. The game looks like an ordinary independent game, and the user can install and run it properly, but the horse is embedded in the program. According to the FBI, the case has identified about 800 victims, of whom about 80 were stolen encrypted wallets for at least $220,000.

Promotion through social platforms

Law enforcement stated that suspects and their associates had promoted the games through Discord, LinkedIn and Telegram to expand downloads and attract more users for installation. The FBI publicly stated earlier this March that an investigation was under way into the use of Steam games to disseminate malicious software and steal user assets, and called on users who downloaded the games to submit evidence.

In the past year, Steam Operator Valve has set up several games found to contain malicious software, including PirateFi. According to the case file, these games are not unwieldy disguises, but are designed to be “looks normal and can play”, so as to reduce user vigilance.

The chain of money flows into a breakthrough.

Prosecution documents show that the FBI questioned another person involved after they had locked him up. The individual claimed that he had been involved in raising funds for the start-up and promotion of these malicious games in return for a share of the stolen and encrypted currency. The investigators then identified a case-related encrypted account and traced the funds to that account.

Investigators found that the account used encrypted assets to purchase several gift cards, including UberEats. Following summonses from federal law enforcement officials to Uber, it was discovered that the gift cards were linked to an account that had delivered delivery to Wilkins' address. The prosecution documents state that the suspect used the nickname “Sibel.eth” online.

Seizure of equipment and digital wallets during search

After obtaining a search warrant, federal law enforcement officers searched his house and seized a MacBook laptop, mobile phones, other electronic devices and digital wallets. According to the indictment, Wilkins refused to answer questions during the search.

The case shows once again that the malicious software transmission path is extending from traditional fishing mail and disguise applications to game distribution platforms. For users of encrypted assets, the targets of the attackers are no longer limited to exchange accounts, and personal equipment is the same as local wallets.