Federal agents arrested 21-year-old Florida resident Zyaire Dontaevious Zamarion Wilkins in connection with a malware operation that allegedly hid malicious code inside multiple games distributed on Steam, infecting about 8,000 devices and stealing at least $220,000 from roughly 80 cryptocurrency wallets. Prosecutors said the games—including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi—were used to steal credentials and other data and to drain victims’ crypto holdings, while Valve removed several of the titles after they were identified as malicious.
According to the criminal complaint, Wilkins allegedly financed and marketed the scheme under the handle Sibel.eth, while an unidentified developer created the malware and the games were promoted through Discord, LinkedIn, and Telegram. Investigators linked the stolen cryptocurrency to Wilkins by tracing Bitcoin used to buy more than 150 gift cards, including purchases redeemed through Uber Eats deliveries tied to his home and university addresses; the FBI had previously issued a public request for victim information as part of its Steam malware investigation and later seized devices and digital wallets during a search of his residence.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Investigators linked the alleged proceeds of the scheme to more than 150 gift cards purchased with stolen Bitcoin, including redemptions associated with Uber Eats deliveries tied to Wilkins' home and university addresses. Authorities said this tracing helped identify the suspect behind the handle Sibel.eth.
Federal agents arrested Zyaire Dontaevious Zamarion Wilkins of North Lauderdale, Florida, accusing him of helping run the malware scheme that used Steam games to infect victims and steal cryptocurrency. U.S. prosecutors said Wilkins and unnamed co-conspirators uploaded fake games containing malware and promoted them on Discord, LinkedIn, and Telegram.
Federal authorities later executed a search warrant at Wilkins' residence and seized devices and digital wallets. The seizure was part of the investigation into the Steam malware and cryptocurrency theft scheme.
Valve removed several games from Steam after they were found to contain malware. The removed titles matched games later cited in the criminal complaint about the crypto-theft scheme.
The FBI published a victim-information request tied to its Steam malware investigation. The notice indicates the bureau was actively seeking information from affected users.
By February 2026, investigators said the malware operation had infected about 8,000 devices and stolen at least $220,000 from roughly 80 cryptocurrency wallets. This marked the reported scope of the campaign described in the complaint.
According to the criminal complaint, a scheme involving malware embedded in Steam-distributed games infected devices between May 2024 and February 2026. The operation allegedly used titles including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi to steal credentials, data, and cryptocurrency.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceghacks.net
Open sourcemalware.news
Open sourcetomshardware.com
Open sourcetechcrunch.com
Open sourceforms.fbi.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.