
Fake Web3 Job Interviews Push “ClickFix” Malware
Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During…
Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft from cryptocurrency wallets. The games were promoted through social platforms and direct messages aimed at people believed to hold significant crypto, convincing them to install the infected titles.
A group allegedly financed and promoted malware hidden inside playable video games, affecting about 8,000 devices and stealing at least $220,000 in cryptocurrency. Named titles tied to the campaign include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova. Rather than relying on a single delivery method, the operators spread these games across Discord, Telegram, X and LinkedIn, using bots to locate people believed to hold substantial amounts of cryptocurrency and send them direct messages encouraging installation.
Once a target installed the game, the malware collected passwords, browser cookies, saved form data, account tokens, and other private information from the device. The stolen data was then searched for access to cryptocurrency accounts, and any wallets the attackers could enter were drained.
The lure worked because it blended into normal online behavior for the target audience. Gamers and crypto holders regularly receive links to new titles from communities, streamers, and social platforms, so an unsolicited but plausible-looking game recommendation did not immediately stand out. Using bots to specifically target people who appeared to hold significant crypto also increased the odds that a successful infection would yield a meaningful payout, rather than spreading malware indiscriminately.
Treat unsolicited messages urging software installation as high-risk, even when they arrive on platforms you normally trust for work or networking, such as LinkedIn or Discord. Assume that any "free game" install could expose saved passwords, browser cookies, and session tokens, and avoid storing crypto seed phrases or private keys on everyday computers used for browsing or gaming.
If a suspicious title has already been installed, treat it as an active incident: isolate the device, avoid reusing it to reset credentials, and instead change exposed passwords from a separate, known-clean device. If seed phrases or private keys were stored on the infected machine, move remaining funds to a new wallet as soon as possible. Organizations should extend awareness training beyond phishing emails to cover gaming and social platform lures, since employees who hold or discuss cryptocurrency personally can become entry points even when the compromise happens on a personal device.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Once installed, the malware collected passwords, browser cookies, saved form data, and account tokens, which attackers then used to search for and drain accessible crypto wallets.
The games were promoted through Discord, Telegram, X and LinkedIn, with bots used to identify and message people believed to hold substantial cryptocurrency.
Victims should change exposed passwords from a clean device and transfer remaining crypto funds to a new wallet if their seed phrase or private keys were stored on the infected computer.
Named games linked to the campaign include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova.
Imagine a Discord DM: “Hey, saw you’re into crypto and gaming, try this new title, BlockBlasters.” That’s exactly how malware games like BlockBlasters, Chemia, Dashverse, Lampy, Lunara, PirateFi and Tokenova helped steal over two hundred twenty thousand dollars in crypto. Once you install, the “game” quietly grabs your passwords, browser cookies, saved forms, and account tokens, then uses them to drain any crypto wallets it can reach. If you get an unsolicited Discord or LinkedIn message pushing a game install, don’t click, report it and only download software from platforms you already trust.

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…