FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Heist


The FBI arrested a 21-year-old Florida resident accused of running a cybercrime operation that infected around 8,000 PCs with malware spread through video games.

The operation reportedly stole about $220,000 in cryptocurrency from approximately 80 wallets between May 2024 and February 2026, according to a federal indictment and reports from TechSpot.

The suspect is identified in court documents as Zyaire Dontaevious Zamarion Wilkins. Several of the infected games mentioned in the FBI complaint were listed in Steam until earlier this year, although the indictment does not specify the name of the storefront. Wilkins and other unnamed co-conspirators face multiple charges, including conspiracy to distribute malware.

Infected Steam games and the malware behind them

The FBI complaint names BlockBlasters, Dashverse, Lunara and PirateFi among the infected titles. TechSpot reports that all four games were still available on Steam until earlier this year, when the FBI announced its investigation and urged anyone who had downloaded the malicious games to come forward.

According to cryptocurrency forensic researcher ZachXBT and malware repository vx-underground, BlockBlasters alone is estimated to have stolen around $150,000 in cryptocurrency from between 261 and 478 victims.

This amount includes $32,000 stolen from Twitch streamer RastalandTV in September 2025. The streamer had received these funds as donations from viewers to help with cancer treatment costs.

The FBI claims that the malware was designed to extract passwords and other sensitive data from victims’ computers, which were then used to empty online cryptocurrency wallets.

Investigators allege that Wilkins and his associates promoted the infected games on platforms such as Discord, Telegram, X, and LinkedIn. According to the complaint, they used bots to find users with large cryptocurrency holdings and contacted them directly. The FBI believes Wilkins financed the operation and marketed the malware to other cybercriminals on underground forums.

TechSpot reports that Signal chats recovered from the alleged malware developer’s devices link Wilkins to the operation. Miami news station WPLG Local 10 reports that these messages suggest that Wilkins, operating under the dark web alias Sibel.eth, purchased a $10,000 remote access Trojan and discussed methods to trick victims into approving fraudulent cryptocurrency transactions. The suspected developer has not been publicly identified or formally charged.

How the FBI tracked down the suspects and how to protect your PC and wallet

The FBI reports that it traced the stolen bitcoin to more than 150 Bitrefill gift cards. TechSpot notes that these gift cards were primarily used to pay for Uber Eats orders. This trail of gift cards played a key role in identifying the suspects and linking blockchain activity to real-world purchases.

Investigators also searched the property of the alleged malware developer for additional evidence.

Users who downloaded BlockBlasters, Dashverse, Lunara, or PirateFi on any platform should consider their systems compromised. The malware captured credentials, including those associated with browser sessions and cryptocurrency wallets. Any accounts accessed on the affected machine during the exposure period may now be at risk.

Recommended actions based on malware behavior include:-

  1. Disconnect the affected PC from the Internet before continuing to use it.
  2. Transfer any cryptocurrency to a new wallet created on a clean, secure device, and consider existing seed phrases stored on the compromised PC invalid.
  3. Change passwords for email, Exchange, and Wallet accounts from a trusted device, and enable hardware keys or app-based two-factor authentication when available.
  4. Run a full offline scan with reliable anti-malware software and perform a clean reinstall of the operating system if any credential-stealing components are found.
  5. Review browser session tokens and revoke active sessions on exchanges, wallet services, and email accounts.
  6. If losses have occurred, report the incident to the FBI’s Internet Crime Reporting Center at ic3.gov, including wallet addresses and transaction hashes.

The FBI has asked anyone who downloaded the infected titles to contact investigators to assist with the ongoing investigation.

Where is the case and the remaining unknowns

Wilkins has been charged but not yet convicted, and the indictment names co-conspirators who have not been publicly named. The FBI has not said whether additional arrests are planned or whether the full list of affected titles beyond the four named games will be revealed.

TechSpot notes that the indictment does not specify which store housed the games, and Valve has yet to make a public statement about the four titles mentioned by the FBI.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *