Tue. Jul 21st, 2026

A recent fork fishing using a fake Steam game Fish activity has led to the loss of over $32,000 in encrypted currency by a late cancer player. The scheme, implemented through the Block Blasters game and with a total profit of US$ 150,000, made use of the loopholes of V’s independent game review to survive on the Steam platform for almost a month and functioned as a complete encrypted currency stealr.

On 21 September 2025, RastaLandTV, the author of Twitch and Steam content, who was fighting the fourth stage of carcasses, was unfortunately introduced on the air. The fraudster used the payment as a bait to demand a live presentation of Block Blasters. The anchor downloads and runs the game live and carries out a series of attacks without its knowledge, resulting in the emptiness of encrypted wallets containing funds for cancer treatment.

The GDATA security researcher Carlsten Hahn and the VX-Underground independent analyst and the encrypted monetary investigation community acted quickly to parse malware and track its infrastructure. The malware game (ID 3872350) was found to contain multiple confusion payloads, with core components including: batch-based theft program game.bat (at least 16 variants) The PyInstaller backdoor program StealC binary files multiple VBScript and ZIP compressions encrypted with “121” passwords for the Telegram machine for data transfer People

The malicious software avoids detection by testing the anti-virus process, and if only Windows Defender is found to perform the Block1.exe or MegaActionPlatformer.exe secondary payload in the v1.zip and v2.zip compression packages. The stolen documents, Steam account data and encryption wallet details are uploaded to an uncertified server http://203.188.171.156:30815/upload.

The evidence report prepared by the research team in charge of the attack on Block Blasters showed that they had access to the command and control servers used in the attack. The team took advantage of the missing security controls to extract victim logs from 478 users, a list of selected Steam encrypted users and malicious software documents and scripts for detection, retrieval and execution.

Through SteamDB logs, malicious binary files have been downloadable for nearly a month. Despite multiple information thefts of malicious software compressors, the game passed internal audit by V. Even worse, such incidents are not isolated: In March 2025, Valve set up the “Sniper:Phantom’s Resolution ” , a “demonstration” guide users to download external implementable documents containing malicious software; in February 2025, PirateFi was removed as a direct embedding of malicious software.

Safety experts recommended that independent game presentations that did not validate the developer ‘ s reputation be avoided and that encrypted currency be stored in hard (cold) wallets.