October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
VGSources
Blog

Hamster Kombat Malware Scam Explained: Spyware, Fake Downloads and Infostealers

The legitimate Hamster Kombat game was not identified as malware in ESET’s 2024 investigation. The danger came from unofficial APKs, fake download sites and Windows bots carrying spyware or infostealers.
Length8 min Posted Quest giverVGSources Team

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The documented threat was not evidence that the legitimate Hamster Kombat game contained malware. In an investigation published on July 23, 2024, ESET found criminals using Hamster Kombat’s popularity to distribute an Android app containing Ratel spyware, redirect users through fake download pages, and disguise the Windows infostealer Lumma Stealer as bots and autoclickers.

The campaign targeted players seeking easier access, automation, balance boosts or future crypto-related rewards. Anyone who installed one of these unofficial tools should treat the device and accounts as potentially compromised.

As an Amazon Associate I earn from qualifying purchases.

The short answer

ESET said it had not observed malicious activity from the original Hamster Kombat app during its investigation. The abuse came from unofficial Telegram channels, fake app-download websites and third-party Windows tools using the game’s name.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is an important distinction. “Hamster Kombat malware” is a misleading shorthand if it suggests the legitimate game itself was infected. The evidence documents criminal impersonation and malware delivery associated with the game’s popularity, not a confirmed malicious feature in the original app. It is also a historical finding from July 2024, not proof that every later version, link, clone, bot or browser extension is safe.

ESET’s investigation identified three main abuse patterns:

  • An unofficial Telegram channel distributed an Android package posing as Hamster Kombat but containing Ratel spyware.
  • Fake storefront-style pages presented download buttons that instead redirected visitors to unwanted advertisements.
  • GitHub repositories promoted Windows farm bots and autoclickers that concealed Lumma Stealer.

What was Hamster Kombat?

Hamster Kombat was a Telegram-based clicker game launched in March 2024. Players tapped and completed tasks to accumulate fictional in-game currency, partly motivated by the possibility of a future cryptocurrency reward.

In June 2024, the developers claimed the game had 150 million active users. ESET cautioned that the figure should be treated skeptically. Other contemporary coverage reported different numbers, including more than 250 million, so these figures should not be treated as independently verified user counts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The game’s rapid growth created an attractive environment for scammers. Many users were already accustomed to Telegram channels and links, while the crypto angle encouraged people to look for shortcuts such as bots, autoclickers, balance hacks and alternative downloads.

Why criminals targeted Hamster Kombat players

The documented lures relied on social engineering rather than a technical vulnerability in Hamster Kombat. Criminals used the promise of convenience or greater earnings:

  • “Official” alternative APKs.
  • Farm bots and autoclickers.
  • Balance hacks and reward boosters.
  • Download links shared through Telegram.
  • Tools supposedly needed to claim tokens or unlock benefits.

The distinction between the official game, copycat channels, fake websites and third-party tools was easy to blur. A familiar logo and the promise of a financial reward could make an unsafe download appear credible.

Android threat: Ratel spyware

ESET found an unofficial Telegram channel called “HAMSTER EASY” distributing an Android package that impersonated Hamster Kombat. The package reportedly did not provide the game and had little or no meaningful user interface.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Instead, it requested two particularly sensitive permissions:

  • Notification access: This can allow an app to read notifications and hide selected notifications.
  • Default SMS-app status: This can give an app access to and control over SMS messages.

The package contained Ratel, Android spyware that ESET said could:

  • Read and send SMS messages.
  • Make phone calls.
  • Receive operator commands through SMS.
  • Hide notifications from a hardcoded list of more than 200 applications.
  • Potentially facilitate unauthorized subscriptions or paid services.
  • Check a Sberbank Russia account balance through an SMS command.

The Sberbank behavior was geographically specific. It described a capability observed by ESET, not proof that every infected device was used to steal money or that the malware targeted every bank.

Why notification and SMS access are dangerous

These permissions can expose more than ordinary text messages. Notifications may contain one-time passcodes, password-reset links, banking alerts, cryptocurrency exchange notices, subscription confirmations and private-message previews.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ratel’s reported ability to hide notifications could delay discovery of fraudulent activity. ESET said the malware concealed notifications from apps including Telegram, WhatsApp, SMS applications and other commonly installed software. Revoking access can stop a capability, but it does not prove that previously exposed data or the malware itself has been eliminated.

Fake Hamster Kombat download websites

ESET also found fake app-store-style pages claiming to offer Hamster Kombat. Their Install or Open buttons redirected visitors to unwanted advertisements instead of supplying the game.

Not every fake page necessarily installed spyware. Some may have been designed for advertising, traffic generation or other scams. But an ad redirect is still a security warning: it can lead to further deceptive pages, unwanted downloads, notification spam or attempts to obtain personal information.

Do not visit or test historical malicious domains from security reports. Domains can be abandoned, recycled or still dangerous.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows threat: fake bots and autoclickers

Although Hamster Kombat was primarily a mobile and Telegram experience, criminals also targeted Windows users searching for automation. GitHub repositories advertised:

  • Farm bots.
  • Autoclickers.
  • Automation tools.
  • Balance hacks and similar game advantages.

ESET found that these repositories concealed Lumma Stealer cryptors. Some hosted malicious release files directly, while others redirected users to external file-sharing services.

Here, “cryptor” did not mean a legitimate encryption utility that protected the player. It referred to a loader or wrapper designed to conceal and execute the Lumma payload. A repository being hosted on GitHub does not validate its binaries: repositories can be copied, abandoned, newly created or used as delivery mechanisms for malware.

What Lumma Stealer can expose

ESET described Lumma Stealer as a malware-as-a-service infostealer first observed in 2022. Its targets included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Browser-stored credentials.
  • Cryptocurrency wallets.
  • Two-factor-authentication browser extensions.
  • Other sensitive information stored or accessible on the computer.

Capabilities vary by Lumma version, configuration and operator. It would be inaccurate to say that every sample stole every category of data, or that every infected player lost cryptocurrency. The risk is that a single fake utility can expose enough browser and wallet data to enable later account takeover or financial theft.

How the Windows samples operated

ESET reported several implementation patterns:

  • C++ samples: Embedded the Lumma payload, used RC4 encryption and, in one case, injected it into RegAsm.exe.
  • Go samples: Used AES-GCM and process hollowing.
  • Python samples: Were packaged with PyInstaller or Nuitka, displayed a fake installer and downloaded a password-protected archive from FTP. ESET identified the archive password as crypto123.

This technical detail is useful to defenders and researchers, but ordinary users should not download or execute samples to test them.

How to recognize a Hamster Kombat-themed scam

  • A Telegram channel is not clearly linked from a verified official source.
  • An APK arrives through a chat message or random website.
  • A game asks to become the default SMS application.
  • A game requests notification access without a clear, necessary reason.
  • A Windows “autoclicker,” “farm bot,” “balance hack” or “profit booster” requires an executable.
  • A GitHub repository has little meaningful source code but offers a downloadable binary.
  • The download moves to an unrelated file-sharing domain.
  • A fake installer asks you to click I agree before the supposed tool works.
  • The offer promises tokens, cryptocurrency or special rewards.
  • The instructions demand urgency, secrecy or antivirus deactivation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you installed the Android app

  1. Stop using the device for banking, payments, cryptocurrency and password resets.
  2. From a clean device, contact your bank or payment provider if you notice suspicious charges, subscriptions, SMS activity or missing notifications.
  3. Review Android settings for unfamiliar apps with notification access, default SMS status, accessibility access or device-administrator privileges. Menu names vary by manufacturer and Android version.
  4. Revoke suspicious privileges before attempting removal.
  5. Uninstall the suspicious application if possible.
  6. If it cannot be removed, persists or causes unexplained calls or SMS activity, back up essential personal files and consider a factory reset.
  7. From a clean device, change passwords beginning with email, banking, cryptocurrency accounts, Telegram and password-manager accounts.
  8. Revoke active sessions and regenerate important recovery codes or authentication tokens.
  9. Review bank, carrier, email and crypto-account activity for unauthorized changes.

If you used the phone for two-factor authentication, assume that messages and notification previews may have been exposed. Do not rely on a permission change alone as proof of recovery.

What to do if you ran a Windows bot or autoclicker

  1. Disconnect the computer from the internet if active compromise is suspected.
  2. Do not sign in to banking, email, cryptocurrency or other sensitive accounts from that computer.
  3. Run a reputable, fully updated security scanner or the built-in Windows security tools.
  4. Using a separate clean device, change passwords and revoke active sessions.
  5. Treat browser-stored passwords, cookies, wallet credentials and authentication-extension data as potentially exposed.
  6. Check crypto wallets and exchanges for unauthorized transfers, new withdrawal addresses or changed security settings.
  7. Preserve suspicious files and hashes only if professional investigation requires them. Do not casually upload sensitive samples.
  8. If the computer shows persistence, disabled security tools, credential theft or unexplained account activity, reinstalling the operating system may be safer than relying on a routine scan.

A clean scan is helpful but not conclusive. Malware may have already stolen data, been removed after theft, been modified, or evaded a particular scanner.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the ESET report does—and does not—prove

Supported conclusion What not to claim
Unofficial Hamster Kombat-themed campaigns distributed Ratel and Lumma-related malware. The legitimate game itself was proven to be malware.
Ratel could access SMS and notifications and hide selected notifications. Every victim suffered financial loss.
Lumma targeted browser credentials, wallets and related sensitive data. Every infected computer lost cryptocurrency.
Many copycat apps monetized through advertising, while some campaigns were malicious. Every copycat app was malicious.
The cited evidence describes activity investigated in 2024. The same campaign is necessarily active in September 2026.

ESET’s time-qualified conclusion was that it had not observed malicious activity from the original app during the investigation. That is not a blanket certification of every later app, mirror, Telegram link, APK, bot, browser extension or helper tool using the Hamster Kombat name.

Should you install security software?

Security software can provide a useful layer, but it cannot make untrusted tools safe. Android users should start with trusted app distribution, Google Play Protect, permission review and account protection. Windows users can begin with updated Windows Security, while paid products or additional scanners are optional layers.

ESET’s consumer security products, Microsoft Defender, Malwarebytes and Google Play Protect are examples of tools readers may consider. None should be presented as a guarantee against every repackaged or newly compiled sample, and buying software is not a substitute for changing exposed passwords, revoking sessions, notifying financial providers or resetting a compromised device.

Technical reference

ESET’s original report contains indicators of compromise, classifications and additional sample details. Historical file names, hashes and domains should be treated as defensive reference material only and should not be opened or visited casually. See ESET Research’s full report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More quests from Patch Notes

  1. How to Set Up a RedM (RDR2) Server in 2026: License Key, txAdmin and server.cfg, Step by StepBlog11min
  2. Best RedM (RDR2) Server Hosting in 2026: Comparing Four Hosts on Slots, Memory and PriceBlog10min
  3. How to Host a Mindustry Server in 2026: server-release.jar, Port 6567 and the Commands That MatterBlog7min
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.