The FBI is seeking victims as it investigates a suspected cybercriminal who published multiple malware-tainted games on Steam, using seemingly legitimate titles as Trojan horses to infect players' systems. The games named by the agency include BlockBlasters/BlockBasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova, and were reportedly available between 2024 and 2026. Both reports indicate the titles were functional enough to appear legitimate, but were designed to deliver malware and compromise users after installation.
The reported impact includes account compromise, information theft, and crypto-wallet draining, with one cited case involving the theft of $32,000 in cancer donations from a streamer after exposure to one of the malicious games. The investigation suggests the listed titles may have been developed by the same threat actor, and that the number of affected users remains unknown. The case also highlights ongoing weaknesses in marketplace screening, as malicious games were able to reach Steam users before being removed by Valve.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Following disclosure of the investigation, Steam was reported as advising affected users to look for malicious files, run antivirus scans, review installed software, and consider reinstalling their operating system. This guidance reflected the risk of persistent compromise from the malicious game installs.
Reporting on the FBI inquiry identified the games BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova, and linked them to malware including cryptodrainers, HijackLoader, Vidar, and Fickle Stealer. Articles also described promotion via Discord and Telegram and follow-up social engineering to obtain verification codes for deeper account access.
On March 13, 2026, the FBI's Seattle Division announced it was investigating a suspected cybercriminal behind multiple malware-laced Steam games and asked victims or guardians to submit information. The agency said victim identification could support the investigation, restitution, and victim services, and provided a reporting form and Steam_Malware@fbi.gov for submissions.
The FBI said the investigated campaign involved games hosted on Steam through January 2026, indicating the operation continued into early 2026. Some malicious functionality may have been introduced through later updates after initial release.
Valve removed the malware-laced titles from Steam after they were identified as malicious. The exact number of infected users remained unknown, though one title was reported to have up to 1,500 downloads before removal.
The malicious Steam game PirateFi reportedly reached more than 7,000 players before Valve removed it. Valve also advised affected users to reformat their operating systems after the game's removal.
One of the malicious Steam titles, BlockBlasters, was reported to have led to more than $32,000 in cryptocurrency theft from a streamer after a malicious file was injected into the game. Community losses tied to BlockBlasters were later estimated as high as $150,000.
During 2025, separate malicious games were reported on Steam that functioned as basic games while acting as Trojan horses to infect players' computers. This established that malware distribution through Steam had already occurred before the broader FBI-linked investigation was publicized.
A campaign of malicious games started being distributed on Steam in May 2024, with titles later tied to cryptocurrency theft, credential theft, browser-session hijacking, and account compromise. The FBI later said the affected games were available between May 2024 and January 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
bgr.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcepcgamer.com
Open sourcetomshardware.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.