Executive Summary
In September 2025, a verified Steam game, BlockBlasters, was discovered to have been weaponized to steal cryptocurrency from users, including a content creator raising money for cancer treatment. Initially benign, the game was compromised on August 30 with a cryptodrainer component that harvested Steam credentials, IP addresses, and ultimately drained victims’ digital wallets. Attackers targeted high-value accounts sourced from social media, using a mix of batch scripts, Python backdoors, and StealC payloads, leading to an estimated $150,000 in theft across hundreds of accounts. At least one streamer lost $32,000 in funds intended for lifesaving care.
This incident exemplifies the growing threat of supply-chain and platform abuse, with attackers leveraging trusted app marketplaces to deliver infostealers. The BlockBlasters case underscores the urgent need for advanced egress security, anomaly detection, and zero trust controls, as attackers increasingly exploit digital trust and social media to orchestrate high-impact thefts.
Why This Matters Now
With attack surfaces expanding and trust in digital platforms eroding, attackers are exploiting verified channels like Steam to place infostealing malware. The surge in cryptocurrency-based thefts and successful targeting of vulnerable individuals reiterates the need for urgent scrutiny of digital supply chains and improvements in detection and application segmentation.
Attack Path Analysis
The attacker gained initial access by convincing targeted Steam users, particularly those with significant crypto assets, to download a verified-but-trojanized game containing a malicious cryptodrainer payload. Following installation, the malware gathered credentials and wallet information to escalate privileges, while performing basic environment checks. It then potentially attempted lateral movement to access additional user data and accounts within the system or network. The malware established command and control communications by uploading harvested data, including Steam credentials and IPs, to remote servers. Stolen cryptocurrency wallet data and credentials were exfiltrated over the internet to attacker infrastructure. Finally, attackers drained victims' digital assets, causing substantial financial impact.
Kill Chain Progression
Initial Compromise
Description
The victim was lured into downloading and installing a malicious Steam game that had been trojanized with a cryptodrainer payload.
Related CVEs
CVE-2025-XXXX
CVSS 9A malicious update to the Steam game 'BlockBlasters' introduced a cryptodrainer component that allowed attackers to steal cryptocurrency from users' wallets.
Affected Products:
Genesis Interactive BlockBlasters – Build 19799326
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Software Supply Chain: Software Download/Install
Drive-by Compromise
Phishing: Spearphishing via Service
Command and Scripting Interpreter
Exfiltration Over C2 Channel
Credentials from Password Stores
Automated Collection
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication for Access to Systems
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Requirements
Control ID: Art. 9
CISA ZTMM 2.0 – Identity Verification and Credential Hygiene
Control ID: Identity Pillar - Controls: Identity Verification and Credential Protection
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Games
Gaming platforms face critical infostealer threats through verified malicious games, exposing cryptocurrency wallets and requiring enhanced east-west traffic security and egress filtering.
Entertainment/Movie Production
Content creators and streamers vulnerable to targeted cryptocurrency theft through gaming platforms, requiring zero trust segmentation and threat detection for financial protection.
Financial Services
Cryptocurrency wallet drainage attacks targeting high-value individuals demonstrate need for encrypted traffic protection, anomaly detection, and secure hybrid connectivity solutions.
Information Technology/IT
Steam platform security failures enabling verified malware distribution require multicloud visibility, inline IPS protection, and cloud native security fabric implementation.
Sources
- Verified Steam game steals streamer's cancer treatment donationshttps://www.bleepingcomputer.com/news/security/verified-steam-game-steals-streamers-cancer-treatment-donations/Verified
- Gamers Warned as BlockBlasters Patch Installs Malicious Softwarehttps://cyberpress.org/blockblasters-malicious-patch/Verified
- Steam Pulls BlockBlasters After StealC Infostealer Hits 261+ Usershttps://cybersecurefox.com/en/steam-blockblasters-stealc-infostealer-campaign-2025/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic controls, and strong egress policy enforcement would have significantly hindered the malware’s ability to propagate, communicate externally, and exfiltrate sensitive information from affected endpoints or cloud resources. CNSF controls like microsegmentation, egress filtering, and real-time anomaly detection are critical against this type of infostealer supply-chain attack.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of malicious activity initiated by unauthorized software.
Control: Zero Trust Segmentation
Mitigation: Limits unauthorized access to sensitive resources within the cloud or hybrid workloads.
Control: East-West Traffic Security
Mitigation: Blocks lateral movement across workloads, accounts, or internal networks.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized and anomalous outbound communications to known or unknown malicious destinations.
Control: Cloud Firewall (ACF)
Mitigation: Stops unauthorized data exfiltration to external networks.
Enables rapid detection and containment of asset compromise or anomalous transactions.
Impact at a Glance
Affected Business Functions
- Digital Asset Management
- User Account Security
Estimated downtime: 7 days
Estimated loss: $150,000
Unauthorized access to user credentials and cryptocurrency wallets, leading to significant financial losses.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and least-privilege policies for all workloads and sensitive user assets.
- • Enforce egress filtering and cloud firewall policies to block unauthorized outbound network communication.
- • Deploy real-time threat detection and anomaly response for suspicious process and network behaviors at all endpoints.
- • Apply east-west traffic controls and microsegmentation to prevent malware lateral movement within cloud or hybrid environments.
- • Establish multicloud visibility and centralized alerting to accelerate detection and response to credential theft or data exfiltration.



