×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Acronis
  • New malware campaign discovered by Acronis: indie games used as a vector for infostealers

Customer Press Room

New malware campaign discovered by Acronis: indie games used as a vector for infostealers

by Grandangolo Communications / Wednesday, 23 July 2025 / Published in Acronis

Behind titles like Baruda Quest and Warstorm Fire lie Leet Stealer, RMC Stealer and Sniffer Stealer: a family of malware designed to steal data and spread by exploiting the interest in gaming

Acronis, global leader in the cybersecurity and in the data protection, announces that the Acronis Threat Research Unit (TRU) team has identified a new malware campaign in which a family of infostealers is distributed in the form of indie video games and spread mainly through Discord with the support of promotional sites and content specifically created to mislead users.

The malware involved – Leet Stealer, RMC Stealer (a variant) and Sniffer Stealer – present themselves as unreleased or soon-to-be-released video games, with catchy names such as Baruda Quest, Warstorm Fire and Dire Talon. The files are shared within online communities, where users, attracted by the possibility of trying "preview" games, unknowingly download malicious software.

To make the deception more credible, cybercriminals create dedicated websites, YouTube videos and graphic materials copied from real titles. Once executed, fraudulent installers collect sensitive information such as login credentials, cookies, Discord tokens, cryptocurrency data, and private messages.

Thanks to a mistake by the malware author, Acronis analysts were able to access the unobfuscated source code of one of the variants – RMC Stealer – gaining in-depth insight into how it works. The malware employs advanced techniques to avoid sandboxes, collects data from all major browsers, and is capable of downloading other malicious payloads.

Many of the analyzed samples contained references in Portuguese or Turkish, indicating a probable origin in Brazil or Türkiye. However, the number of infections recorded in the United States confirms a now widespread global distribution, favored by international platforms such as Discord.

Acronis Cyber ​​Protect Cloud detects and blocks these threats, providing effective protection against data theft, extortion, and account compromise, while preventing the spread of malware to other users.

About Grandangolo Communications

What you can read next

Acronis TRU identifies a new espionage campaign targeting India's startup ecosystem
Acronis TRU identifies JanaWare, a new ransomware targeting Turkey via Adwind RAT
Acronis and Intel are alleged to provide a Threat Detection solution for Endpoints efficient and based on AI

Customer Press Room

  • ESET releases SMB IT Readiness Index 2026, highlighting growing confidence but also concerns about AI technologies

    The majority of SMEs declare themselves optimistic...
  • ESET discovers the new arsenal of Webworm, a pro-Chinese APT active against European governments

    ESET Research analyzed recent activity…
  • Arrow Electronics expands distribution agreement with Veeam in EMEA

    Arrow Electronics, a global supplier of technology...
  • ESET Research APT Report: China-aligned groups spy on Venezuela and Gulf, targeting AI robotics in South Korea

    L’ultimo APT Activity Report di ESET Research t...
  • ESET accelerates AI innovation with investments aimed at managing a rapidly expanding attack surface

    ESET announces a 40 million investment ...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP