🚨ALERT: NEW WINDOWS CRYPTO MALWARE
Kaspersky has identified "Stealka", a new Windows infostealer targeting crypto wallets and passwords, spreading via fake software on GitHub and SourceForge.
A newly discovered Windows infostealer malware named Stealka has been identified by cybersecurity firm Kaspersky, posing a significant threat to cryptocurrency users by targeting digital wallets, browser credentials, and sensitive system data.
The malware is being distributed through deceptive repositories on trusted platforms like GitHub and SourceForge, often disguised as pirated software, game mods, or cracked applications, including for popular titles like Roblox and tools such as Microsoft Visio.
As of December 24, 2025, the campaign is actively spreading, with attackers using sophisticated techniques—including AI-generated fake websites—to mimic legitimate software distribution pages and evade detection.
Stealka is designed to silently harvest data from over 100 Chromium- and Gecko-based browsers, including Chrome, Firefox, Edge, and Brave, as well as extract information from 115 browser extensions related to cryptocurrency wallets, password managers, and two-factor authentication services.
It specifically targets major crypto wallets such as MetaMask, Trust Wallet, Binance, Coinbase, Crypto.com, and Exodus, enabling attackers to hijack accounts and drain funds.
The malware spreads by masquerading as game cheats, mods, and software cracks, with malicious files hosted on platforms like GitHub, SourceForge, Google Sites, and Softpedia, which increases its credibility and likelihood of being downloaded.
Once installed, Stealka remains undetected by traditional antivirus software due to advanced obfuscation techniques and low system impact, allowing it to operate in the background for extended periods.
It also deploys crypto miners on infected machines and collects system fingerprints, including device names, OS versions, and installed software, to refine future attacks.
Kaspersky warns that the rise in password-stealer detections—nearly 60% higher this year—signals a more aggressive phase in digital financial crime, underscoring the urgency of protective measures.