Gaming with Malware on Steam, FBI Arrests 21-Year-Old: Allegedly Infected 8,000 PCs
Gaming with Malware on Steam, FBI Arrests 21-Year-Old: Allegedly Infected 8,000 PCs
The FBI has arrested a 21-year-old citizen from Florida on charges of orchestrating a campaign to distribute malware hidden within video games that, according to investigators, has led to the theft of over $220,000 in cryptocurrency. The operation, which is believed to have been active for nearly two years, compromised approximately 8,000 computers and targeted at least 80 digital wallets between May 2024 and February 2026.
The main suspect is Zyaire Dontaevious Zamarion Wilkins, who, according to the FBI, acted alongside other unidentified accomplices. The charges include several cyber crimes, including conspiracy aimed at distributing malware. The indictment does not explicitly state which platform hosted the infected games but mentions several titles that were available on Steam until a few months ago.
Among the involved video games are BlockBlasters, Dashverse, Lunara, and PirateFi. The FBI had already raised attention to these software at the beginning of the year, urging users who had downloaded them to cooperate with investigations after detecting malicious code.
According to investigators, the group promoted the games through platforms like Discord, Telegram, X, and LinkedIn, leveraging the visibility offered by social networks and messaging services. However, the activity was not limited to distributing video games: the accused reportedly used bots to identify users with substantial cryptocurrency holdings, contacting them directly in an attempt to persuade them to download the infected titles.
Once executed on the victim's computer, the malware was designed to steal passwords and other sensitive information. The collected data was then used to access digital wallets and authorize the transfer of cryptocurrencies to addresses controlled by the attackers.
The FBI's investigation succeeded in tracing part of the money flow by following Bitcoin transactions. Investigators linked the stolen cryptocurrencies to the purchase of over 150 Bitrefill gift cards, which were primarily used to pay for orders made through Uber Eats. This element contributed to identifying the alleged masterminds behind the operation.
Further details emerge from the analyses of cryptocurrency forensic researcher ZachXBT and the malware database vx-underground. According to their reconstructions, the game BlockBlasters alone is estimated to have caused the theft of about $150,000 in cryptocurrencies, with the number of victims estimated between 261 and 478 users.
Among the most notable incidents is that of Twitch streamer RastalandTV, from whom approximately $32,000 was reportedly stolen in September 2025. According to reports, the money largely came from donations received by viewers to support medical expenses during cancer treatment.
The FBI also believes that Wilkins financed the entire operation and marketed the malware within cybercrime circles. During the investigation, a search was conducted against the alleged developer of the malicious code, whose identity has not been made public and who is currently not formally charged.
According to U.S. broadcaster WPLG Local 10, conversations on Signal linking Wilkins to the organization emerged from the seized smartphones and devices. The messages also indicate that the 21-year-old, known on the dark web by the alias Sibel.eth, purchased a remote access Trojan worth about $10,000 and discussed strategies to induce victims to authorize fraudulent cryptocurrency transactions.
The investigation remains open, and U.S. authorities are continuing inquiries to identify any other members of the group and reconstruct the entire malware distribution network.