Fake Game Downloads Push Amatera Password Stealer

Malwarebytes · High sophistication
Last updated July 30, 2026

Researchers found real-world campaigns that trick people into downloading fake games, mods, cracks, or software installers. The download looks legitimate and shows an installer screen, but it silently runs a multi-stage infection that ultimately installs the Amatera Stealer to steal passwords and other sensitive data. The lures are delivered through fake download sites, itch.io pages, and common file-sharing services.

How the attack worked

This campaign relies on fake downloads of games, mods, cracks, and software to get victims to run malware. The lure is delivered through fake download websites, itch.io pages, and common file-sharing services such as Wormhole, GoFile, Google Drive, and MEGA. Once a victim downloads the archive, it contains a file named Setup.exe. Opening that file starts a multi-stage infection chain. The victim typically sees what looks like a normal installer or loading screen while malicious code runs silently in the background, eventually deploying Amatera Stealer to collect passwords, wallet data, browser data, and other sensitive information.

In several observed cases, clicking a download link redirected the user through another fake download website before the final file was served, adding extra layers meant to obscure the true source of the malware. The infection chain also used techniques such as MSBuild abuse and EtherHiding, a method of retrieving command-and-control details from a public blockchain, to help the malware evade detection.

Why it succeeded

The attack works because it exploits normal user behavior around downloading free or unofficial software. People searching for game mods, cracks, or free versions of paid software are often willing to bypass official sources, and a convincing installer screen reinforces the illusion that the download is legitimate. The use of well-known, generally trusted file-sharing platforms for hosting the malicious files adds a false sense of safety, since the platform itself is not inherently suspicious, even though the file it hosts is malicious.

What to watch for

  • Downloads that arrive from unfamiliar or unofficial sites, particularly for cracked software, mods, or free versions of paid games
  • Archives that contain an executable installer, such as Setup.exe, instead of the expected game or software files
  • Download links that redirect through multiple unfamiliar websites or file-sharing services before reaching the final file
  • Installer or loading screens that appear normal but follow an unusual or roundabout download path

How to build resistance

Employees and personal device users should be encouraged to download games and software only from official websites, trusted app stores, or established distribution platforms, and to treat cracked software, unofficial mods, and free versions of paid games with caution. Redirect-heavy download flows should be treated as a stopping point rather than something to click through. Before running any installer, it helps to check the contents of a downloaded archive for unexpected executables like Setup.exe. Finally, it is worth reinforcing that neither a professional-looking installer nor a familiar file-sharing service guarantees that a download is safe, since both appearances can be used to mask a malicious payload running in the background.

Key findings

  • Attackers use fake downloads of “games, mods, cracks, and software” to trick users into running malware.
  • Victims may see a normal-looking installer while malware runs silently and eventually deploys “Amatera Stealer” to steal passwords, wallet data, browser data, and more.
  • Distribution was observed via “Fake download websites,” “itch.io pages,” and file-sharing services including “Wormhole, GoFile, Google Drive, and MEGA.”
  • The infection chain involves multiple stages and techniques to evade detection, including MSBuild abuse and “EtherHiding” to retrieve C2 details from a public blockchain.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Developers, Helpdesk, Security awareness trainees.
  • Affected industries: All industries (end users downloading games/software on work devices), Consumers / personal computing.
  • Attack channels: website.
  • Impersonated: Fake game/software download website, Legitimate file-sharing service used as a distribution channel.

Red flags to watch for

  • Download comes from an unfamiliar or unofficial site (often for cracks/mods)
  • Archive contains an executable installer (Setup.exe) instead of expected content
  • Multiple redirects before the final download
  • A familiar hosting service is used but the file source/owner is unknown
  • The download is for cracked/unofficial software
  • Redirects through several sites/services before the file appears
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake game download attack work?

A user downloads what looks like a game, mod, crack, or software installer, often from a fake download site, itch.io page, or file-sharing service. Opening the archive runs a file named Setup.exe, which starts a multi-stage infection that eventually deploys Amatera Stealer while the victim sees a normal-looking installer screen.

What does Amatera Stealer steal?

According to the findings, Amatera Stealer is used to steal passwords, wallet data, browser data, and other sensitive information after the infection chain completes.

What are red flags that a game download is malicious?

Warning signs include downloads from unofficial or unfamiliar sites, an archive that contains an unexpected executable like Setup.exe, and multiple redirects through different websites or file-sharing services before the file appears.

Are trusted file-sharing services like Google Drive or MEGA safe for downloads?

A familiar hosting service does not guarantee safety. The malicious files were distributed through services such as Wormhole, GoFile, Google Drive, and MEGA, so the source and legitimacy of the file itself still matter.

Read the video transcript

You search for a free game mod, click a download, and get a file called Setup.exe. Looks normal, right? Behind that Setup.exe, a multi-stage infection quietly drops Amatera Stealer. You see a legit-looking installer; in the background it abuses MSBuild and even uses EtherHiding on a public blockchain to fetch its command server. These campaigns use fake download sites, itch.io pages, and links that bounce through Wormhole, GoFile, Google Drive, or MEGA. A polished installer or familiar file-sharing logo does NOT mean the download is safe. If a download for a game, mod, or crack comes from unofficial sites or redirect-heavy links and drops a random Setup.exe, stop. Close it and get the software only from the official site or trusted store.

Similar attacks

Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

July 31, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

July 29, 2026