HomeSecurityArcane: New info-stealer malware targets users through game cheats

Arcane: New info-stealer malware targets users through game cheats

Researchers have discovered a new info-stealer malware, dubbed Arcane, that targets YouTube and Discord users and steals a lot of data, including VPN account credentials and information stored in web browsers.

Arcane Info-stealer malware game cheats

According to Kaspersky, this new malware is not related to Arcane Stealer V, which has been circulating on the dark web for the past few years.

The Arcane malware campaign started in November 2024, having gone through many evolutionary stages, including replacements of the main payload.

See also: EncryptHub distributes ransomware and info-stealers via phishing, Trojanized Apps

Kaspersky observed that all chats and public posts of the malware are in Russian , and most infections are located in Russia, Belarus, and Kazakhstan. This is particularly interesting, as most Russian hackers do not target users within the country and other countries of the Commonwealth of Independent States.

Arcane info-stealer malware: Infection chain

Malware operators use YouTube videos promoting game cheats and cracks and trick usersinto following a link to download a password-protected file.

These files contain an obfuscated 'start.bat' script that brings a second file (also password-protected) with malicious executables. The downloaded files add an exception to the Windows Defender SmartScreen filter for all drive root folders. They can also disable it completely via Windows Registry modifications.

Arcane: New info-stealer malware targets users through game cheats

Previously, the attacks used another info-stealer malware named VGS, but it changed to Arcane in November 2024. Kaspersky also found changes in the distribution method, including the use of a fake software downloader, supposedly for downloading popular game cracks and cheats (ArcanaLoader).

See also: Phantom Goblin delivers stealer malware

ArcanaLoader has been heavily promoted on YouTube and Discord, with operators also inviting content creators to promote it on their blogs/videos, for a fee.

Arcane info-stealer malware: Extensive data theft

Arcane initially monitors the infected system and steals hardware and software information, such as operating system version, CPU and GPU details, installed antivirus programs, and browsers.

The current version of the malware targets account data, settings, and configuration files from the following applications:

  • VPN clients: OpenVPN, Mullvad, NordVPN, IPVanish, Surfshark, Proton, hidemy.name, PIA, CyberGhost, ExpressVPN
  • Network tools: ngrok, Playit, Cyberduck, FileZilla, DynDNS
  • Messagers: ICQ, Tox, Skype, Pidgin, Signal, Element, Discord, Telegram, Jabber, Viber
  • Web browsers: Saved logins, passwords, and cookies (for Gmail, Google Drive, Google Photos, Steam, YouTube, Twitter, Roblox) from Chromium-based browsers.
  • Email clients: Outlook
  • Gaming clients: Riot Client, Epic, Steam, Ubisoft Connect (ex-Uplay), Roblox, Battle.net, various Minecraft clients
  • Cryptocurrency wallets: Zcash, Armory, Bytecoin, Jaxx, Exodus, Ethereum, Electrum, Atomic, Guarda, Coinomi

See also: Have I Been Pwned: 284 million accounts stolen via info-stealer malware

The info-stealer malware Arcane also captures screenshots that can reveal sensitive information and retrieves saved Wi-Fi network passwords.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Arcane: New info-stealer malware targets users through game cheats

Protection from info-stealer malware

Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

Avoid downloading tools and game cheats from untrusted sources. Even their appearance on legitimate platforms, such as YouTube and Discord, does not guarantee their safety and reliability.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers (e.g. Arcane).

See also: Poseidon Stealer attacks Macs via fake DeepSeek website

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS