SteamStealer is malware targeting Steam users, intended to steal Steam account credentials and/or valuable Steam inventory items. The provided content links SteamStealer activity to fake and trojanized versions of Steam Desktop Authenticator (SDA). One malicious SDA build was distributed via steamdesktopauthenticator[.]com and used a modified "Steam Desktop Authenticator.exe" (MD5: 872abdc5cf5063098c87d30a8fcd8414; claimed version v1.0.9.1) that appeared to exfiltrate credentials to steamdesktopauthenticator[.]com and steamdesktop[.]com. A second malicious SDA sample, found in a GitHub fork, appeared to intercept Steam trades or market actions and communicated with lightalex[.]ru. Associated infrastructure included lightalex[.]ru hosted on 91.227.16[.]31; that IP had also hosted other SteamStealer-related domains including cs-strike[.]ru and csgo-knives[.]net. The domains were associated in the reporting with the email address mark.korolev.1990@bk[.]ru. The content states that neither fake SDA variant appeared to implement persistence. High-confidence remediation mentioned in the source includes deleting the fake SDA files, scanning the system with antivirus tools, deauthorizing other Steam devices, changing the Steam password, and enabling Steam Guard.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Figure 2 - Sending credentials to steamdesktopauthenticator[.]com Figure 3 - Sending credentials to steamdesktop[.]com
PureCrypter [[URL_8e7af978_5]], a loader and obfuscator for all different kinds of malware such as Agent Tesla and RedLine... co-authored a presentation ... on hunting SteamStealer malware, which was surging exponentially at the time (the malware intended to steal your Steam inventory items and/or your account).
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealer focused on stealing Steam inventory items and/or Steam accounts.
Credential-stealing malware targeting Steam users; the post describes fake Steam Desktop Authenticator versions that attempt to steal Steam credentials and intercept trades/market actions, and references prior SteamStealer malware hosted on related infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.