Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

They got the guy behind the Steam Malware attacks

0
Medium
Published: 07/17/2026 (07/17/2026, 17:47:34 UTC)
Source: Reddit Malware

Description

A 21-year-old man from Florida was arrested for allegedly orchestrating a malware campaign that infected approximately 8,000 devices via eight video games distributed on a popular digital distribution platform. The malware targeted cryptocurrency wallets, stealing at least $220,000 from around 80 wallets between May 2024 and February 2026. The stolen funds were traced through gift card purchases, primarily Uber Eats cards. The accused financed and marketed the malware but did not develop it. This case is notable as the first public arrest related to these Steam malware attacks.

Reddit Discussion

r/Malware·posted by u/Lolligoanima
00

A man from Florida got arrested, allegedly behind the PirateFI and Blockblasters Crypto stealer attacks. The second Game stole 150k from a cancer Patient.

https://www.tomshardware.com/tech-industry/cyber-security/fbi-arrests-florida-man-in-steam-malware-investigaton-after-tracing-stolen-bitcoin-to-uber-eats-gift-cards

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/19/2026, 12:42:03 UTC

Technical Analysis

The FBI arrested Zyaire Dontaevious Zamarion Wilkins for conspiracy to obtain information by computer for private financial gain. Wilkins allegedly helped run an operation embedding malware in eight video games, infecting roughly 8,000 devices and stealing over $220,000 from about 80 cryptocurrency wallets over nearly two years. The malware was distributed via a popular digital distribution platform (implied to be Steam) and promoted on social media platforms. The investigation traced stolen Bitcoin to over 150 gift cards, mostly Uber Eats, linking the funds back to Wilkins. Wilkins financed and marketed the malware, purchasing a remote access trojan from an unnamed developer. The malware targeted users with large cryptocurrency holdings, achieving a roughly 1% success rate in draining wallets. The case is prosecuted near Valve's headquarters, marking a significant development in combating malware spread through gaming platforms.

Potential Impact

The malware infected approximately 8,000 devices and successfully stole at least $220,000 from about 80 cryptocurrency wallets. Victims included individuals with significant cryptocurrency holdings, and notably, $32,000 in donated cancer treatment funds were stolen from a Twitch streamer. The financial impact is substantial for the targeted victims, and the malware campaign exploited trusted gaming distribution channels to reach users. The arrest disrupts the operation and may deter similar future campaigns.

Mitigation Recommendations

No specific patch or remediation is applicable as this is a malware campaign rather than a software vulnerability. The arrest of the alleged perpetrator is a significant step in mitigating this threat. Users should remain vigilant about the source of downloaded games and avoid unofficial or suspicious titles. Monitoring official communications from the digital distribution platform for security advisories is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
Malware
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":35,"reasons":["external_link","newsworthy_keywords:malware","established_author"],"isNewsworthy":true,"foundNewsworthy":["malware"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a5cc6122a4a8d598998c2b4

Added to database: 07/19/2026, 12:41:54 UTC

Last enriched: 07/19/2026, 12:42:03 UTC

Last updated: 07/20/2026, 11:26:46 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses