The Containment Era is here. →Explore

Executive Summary

Between July and September 2025, multiple games on the Steam platform, including 'BlockBlasters' and 'PirateFi,' were found to contain malware designed to steal users' cryptocurrency and personal data. These games, initially appearing legitimate, were later updated to include malicious code that compromised the security of players' systems. The malware led to significant financial losses, with reports indicating over $150,000 stolen from affected users. Notably, Twitch streamer Raivo 'RastalandTV' Plavnieks lost $32,000 in donations intended for his cancer treatment after installing 'BlockBlasters.' Valve Corporation, the operator of Steam, removed the malicious games from the platform and advised affected users to perform full system resets to eliminate potential threats. This incident underscores the evolving tactics of cybercriminals targeting digital platforms and the importance of vigilant security practices for both platform operators and users.

Why This Matters Now

The incident highlights the increasing sophistication of cyber threats within digital distribution platforms, emphasizing the need for enhanced security measures and user awareness to prevent similar attacks in the future.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Valve removed the malicious games from Steam and advised affected users to perform full system resets to eliminate potential threats.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the malware's ability to escalate privileges, move laterally, establish command and control channels, and exfiltrate sensitive data, thereby reducing the attack's overall impact.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial execution of malware from downloaded applications, it could limit the malware's ability to communicate with other systems, reducing its effectiveness.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could likely limit the malware's ability to exploit system vulnerabilities by enforcing strict access controls, thereby reducing the scope of privilege escalation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could likely constrain the malware's lateral movement by monitoring and controlling internal traffic, thereby reducing the risk of unauthorized access to sensitive data.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized outbound communications to attacker-controlled servers, thereby disrupting command and control channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could likely restrict unauthorized data exfiltration by enforcing strict outbound traffic policies, thereby reducing the risk of sensitive data loss.

Impact (Mitigations)

While Aviatrix Zero Trust CNSF could not fully prevent financial losses, it could likely reduce the overall impact by limiting the malware's ability to access and exfiltrate sensitive data.

Impact at a Glance

Affected Business Functions

  • Digital Game Distribution
  • User Account Management
  • Online Gaming Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $150,000

Data Exposure

User credentials, cryptocurrency wallets, and personal information

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement of malware within systems.
  • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities in real-time.
  • Apply Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.
  • Ensure Encrypted Traffic (HPE) to protect data in transit and prevent packet sniffing.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image