{"id":48292,"date":"2021-08-25T18:00:30","date_gmt":"2021-08-25T15:00:30","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=48292"},"modified":"2025-09-02T01:30:22","modified_gmt":"2025-09-01T22:30:22","slug":"hackers-posing-as-games-stole-bitcoin-wallet-data-in-45-countries","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/hackers-posing-as-games-stole-bitcoin-wallet-data-in-45-countries\/","title":{"rendered":"Hackers posing as games stole Bitcoin wallet data in 45 countries"},"content":{"rendered":"<p>Kaspersky Lab experts discovered the Swarez trojan, which, among other things, stole data from cryptocurrency wallets. The company&#8217;s press service said.<\/p>\n<p>The peak of the malware&#8217;s activity occurred in spring 2021. As bait, the attackers used games Among Us, Battlefield 4, Battlefield V, Control, Counter-Strike: Global Offensive, FIFA 21, Fortnite, GTA V, Minecraft, NBA 2K21, Need for Speed Heat, PUBG, Rust, The Sims 4 and Titanfall 2.<\/p>\n<p>Attempts to download such files were recorded in 45 countries, including Russia.<\/p>\n<p>Swarez is a dropper, whose main task is to launch other malware on a device. It was distributed in an archive containing a password-protected ZIP file and a text document with a key. Running the malware led to the decryption and activation of the Taurus stealer trojan.<\/p>\n<p>The Taurus stealer can steal [simple_tooltip content=&#8221;files that allow a site to remember information about its visits&#8221;]cookies[\/simple_tooltip], saved passwords, text files, data from autofill forms in browsers, and information about cryptocurrency wallets; it can also gather system information and take screenshots of the desktop.<\/p>\n<p>Kaspersky Lab specialists recommended gamers to enable two-factor authentication and to avoid downloading files from questionable sites.<\/p>\n<p>As reported by Avast, the creators of the malware Crackonosh <a href=\"https:\/\/forklog.com\/en\/news\/crackonosh-operator-earned-nearly-2-million-in-monero-from-gta-and-the-sims-fans\">have earned almost $2 million in Monero<\/a> since 2018 through a hidden miner. They distributed their software, among other things, through popular games NBA 2019, GTA V, Far Cry 5, The Sims 4 and Jurassic World Evolution.<\/p>\n<p>Follow ForkLog news on <a href=\\\"https:\/\/twitter.com\/ForkLog\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener\\\">Twitter<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab experts uncovered the Swarez trojan, which, among other things, stole data from cryptocurrency wallets.<\/p>\n","protected":false},"author":1,"featured_media":48293,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1553,57],"class_list":["post-48292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-kaspersky-lab","tag-wallets"],"aioseo_notices":[],"amp_enabled":true,"views":"25","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/48292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=48292"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/48292\/revisions"}],"predecessor-version":[{"id":48294,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/48292\/revisions\/48294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/48293"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=48292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=48292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=48292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}