What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The documented threat was not evidence that the legitimate Hamster Kombat game contained malware. In an investigation published on July 23, 2024, ESET found criminals using Hamster Kombat’s popularity to distribute an Android app containing Ratel spyware, redirect users through fake download pages, and disguise the Windows infostealer Lumma Stealer as bots and autoclickers.
The campaign targeted players seeking easier access, automation, balance boosts or future crypto-related rewards. Anyone who installed one of these unofficial tools should treat the device and accounts as potentially compromised.
As an Amazon Associate I earn from qualifying purchases.
The short answer
ESET said it had not observed malicious activity from the original Hamster Kombat app during its investigation. The abuse came from unofficial Telegram channels, fake app-download websites and third-party Windows tools using the game’s name.
Free tools Windows power users keep installed
One-click scans. No signup required.
That is an important distinction. “Hamster Kombat malware” is a misleading shorthand if it suggests the legitimate game itself was infected. The evidence documents criminal impersonation and malware delivery associated with the game’s popularity, not a confirmed malicious feature in the original app. It is also a historical finding from July 2024, not proof that every later version, link, clone, bot or browser extension is safe.
#1 Best Overall
ESET’s investigation identified three main abuse patterns:
- An unofficial Telegram channel distributed an Android package posing as Hamster Kombat but containing Ratel spyware.
- Fake storefront-style pages presented download buttons that instead redirected visitors to unwanted advertisements.
- GitHub repositories promoted Windows farm bots and autoclickers that concealed Lumma Stealer.
What was Hamster Kombat?
Hamster Kombat was a Telegram-based clicker game launched in March 2024. Players tapped and completed tasks to accumulate fictional in-game currency, partly motivated by the possibility of a future cryptocurrency reward.
In June 2024, the developers claimed the game had 150 million active users. ESET cautioned that the figure should be treated skeptically. Other contemporary coverage reported different numbers, including more than 250 million, so these figures should not be treated as independently verified user counts.
The game’s rapid growth created an attractive environment for scammers. Many users were already accustomed to Telegram channels and links, while the crypto angle encouraged people to look for shortcuts such as bots, autoclickers, balance hacks and alternative downloads.
Why criminals targeted Hamster Kombat players
The documented lures relied on social engineering rather than a technical vulnerability in Hamster Kombat. Criminals used the promise of convenience or greater earnings:
- “Official” alternative APKs.
- Farm bots and autoclickers.
- Balance hacks and reward boosters.
- Download links shared through Telegram.
- Tools supposedly needed to claim tokens or unlock benefits.
The distinction between the official game, copycat channels, fake websites and third-party tools was easy to blur. A familiar logo and the promise of a financial reward could make an unsafe download appear credible.
Android threat: Ratel spyware
ESET found an unofficial Telegram channel called “HAMSTER EASY” distributing an Android package that impersonated Hamster Kombat. The package reportedly did not provide the game and had little or no meaningful user interface.
Recommended Free Tools
Instead, it requested two particularly sensitive permissions:
- Notification access: This can allow an app to read notifications and hide selected notifications.
- Default SMS-app status: This can give an app access to and control over SMS messages.
The package contained Ratel, Android spyware that ESET said could:
- Read and send SMS messages.
- Make phone calls.
- Receive operator commands through SMS.
- Hide notifications from a hardcoded list of more than 200 applications.
- Potentially facilitate unauthorized subscriptions or paid services.
- Check a Sberbank Russia account balance through an SMS command.
The Sberbank behavior was geographically specific. It described a capability observed by ESET, not proof that every infected device was used to steal money or that the malware targeted every bank.
Rank #3
Why notification and SMS access are dangerous
These permissions can expose more than ordinary text messages. Notifications may contain one-time passcodes, password-reset links, banking alerts, cryptocurrency exchange notices, subscription confirmations and private-message previews.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRatel’s reported ability to hide notifications could delay discovery of fraudulent activity. ESET said the malware concealed notifications from apps including Telegram, WhatsApp, SMS applications and other commonly installed software. Revoking access can stop a capability, but it does not prove that previously exposed data or the malware itself has been eliminated.
Fake Hamster Kombat download websites
ESET also found fake app-store-style pages claiming to offer Hamster Kombat. Their Install or Open buttons redirected visitors to unwanted advertisements instead of supplying the game.
Not every fake page necessarily installed spyware. Some may have been designed for advertising, traffic generation or other scams. But an ad redirect is still a security warning: it can lead to further deceptive pages, unwanted downloads, notification spam or attempts to obtain personal information.
Do not visit or test historical malicious domains from security reports. Domains can be abandoned, recycled or still dangerous.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #4
Windows threat: fake bots and autoclickers
Although Hamster Kombat was primarily a mobile and Telegram experience, criminals also targeted Windows users searching for automation. GitHub repositories advertised:
- Farm bots.
- Autoclickers.
- Automation tools.
- Balance hacks and similar game advantages.
ESET found that these repositories concealed Lumma Stealer cryptors. Some hosted malicious release files directly, while others redirected users to external file-sharing services.
Here, “cryptor” did not mean a legitimate encryption utility that protected the player. It referred to a loader or wrapper designed to conceal and execute the Lumma payload. A repository being hosted on GitHub does not validate its binaries: repositories can be copied, abandoned, newly created or used as delivery mechanisms for malware.
What Lumma Stealer can expose
ESET described Lumma Stealer as a malware-as-a-service infostealer first observed in 2022. Its targets included:
- Browser-stored credentials.
- Cryptocurrency wallets.
- Two-factor-authentication browser extensions.
- Other sensitive information stored or accessible on the computer.
Capabilities vary by Lumma version, configuration and operator. It would be inaccurate to say that every sample stole every category of data, or that every infected player lost cryptocurrency. The risk is that a single fake utility can expose enough browser and wallet data to enable later account takeover or financial theft.
Best Value
How the Windows samples operated
ESET reported several implementation patterns:
- C++ samples: Embedded the Lumma payload, used RC4 encryption and, in one case, injected it into
RegAsm.exe. - Go samples: Used AES-GCM and process hollowing.
- Python samples: Were packaged with PyInstaller or Nuitka, displayed a fake installer and downloaded a password-protected archive from FTP. ESET identified the archive password as
crypto123.
This technical detail is useful to defenders and researchers, but ordinary users should not download or execute samples to test them.
How to recognize a Hamster Kombat-themed scam
- A Telegram channel is not clearly linked from a verified official source.
- An APK arrives through a chat message or random website.
- A game asks to become the default SMS application.
- A game requests notification access without a clear, necessary reason.
- A Windows “autoclicker,” “farm bot,” “balance hack” or “profit booster” requires an executable.
- A GitHub repository has little meaningful source code but offers a downloadable binary.
- The download moves to an unrelated file-sharing domain.
- A fake installer asks you to click I agree before the supposed tool works.
- The offer promises tokens, cryptocurrency or special rewards.
- The instructions demand urgency, secrecy or antivirus deactivation.
What to do if you installed the Android app
- Stop using the device for banking, payments, cryptocurrency and password resets.
- From a clean device, contact your bank or payment provider if you notice suspicious charges, subscriptions, SMS activity or missing notifications.
- Review Android settings for unfamiliar apps with notification access, default SMS status, accessibility access or device-administrator privileges. Menu names vary by manufacturer and Android version.
- Revoke suspicious privileges before attempting removal.
- Uninstall the suspicious application if possible.
- If it cannot be removed, persists or causes unexplained calls or SMS activity, back up essential personal files and consider a factory reset.
- From a clean device, change passwords beginning with email, banking, cryptocurrency accounts, Telegram and password-manager accounts.
- Revoke active sessions and regenerate important recovery codes or authentication tokens.
- Review bank, carrier, email and crypto-account activity for unauthorized changes.
If you used the phone for two-factor authentication, assume that messages and notification previews may have been exposed. Do not rely on a permission change alone as proof of recovery.
What to do if you ran a Windows bot or autoclicker
- Disconnect the computer from the internet if active compromise is suspected.
- Do not sign in to banking, email, cryptocurrency or other sensitive accounts from that computer.
- Run a reputable, fully updated security scanner or the built-in Windows security tools.
- Using a separate clean device, change passwords and revoke active sessions.
- Treat browser-stored passwords, cookies, wallet credentials and authentication-extension data as potentially exposed.
- Check crypto wallets and exchanges for unauthorized transfers, new withdrawal addresses or changed security settings.
- Preserve suspicious files and hashes only if professional investigation requires them. Do not casually upload sensitive samples.
- If the computer shows persistence, disabled security tools, credential theft or unexplained account activity, reinstalling the operating system may be safer than relying on a routine scan.
A clean scan is helpful but not conclusive. Malware may have already stolen data, been removed after theft, been modified, or evaded a particular scanner.
What the ESET report does—and does not—prove
| Supported conclusion | What not to claim |
|---|---|
| Unofficial Hamster Kombat-themed campaigns distributed Ratel and Lumma-related malware. | The legitimate game itself was proven to be malware. |
| Ratel could access SMS and notifications and hide selected notifications. | Every victim suffered financial loss. |
| Lumma targeted browser credentials, wallets and related sensitive data. | Every infected computer lost cryptocurrency. |
| Many copycat apps monetized through advertising, while some campaigns were malicious. | Every copycat app was malicious. |
| The cited evidence describes activity investigated in 2024. | The same campaign is necessarily active in September 2026. |
ESET’s time-qualified conclusion was that it had not observed malicious activity from the original app during the investigation. That is not a blanket certification of every later app, mirror, Telegram link, APK, bot, browser extension or helper tool using the Hamster Kombat name.
Should you install security software?
Security software can provide a useful layer, but it cannot make untrusted tools safe. Android users should start with trusted app distribution, Google Play Protect, permission review and account protection. Windows users can begin with updated Windows Security, while paid products or additional scanners are optional layers.
ESET’s consumer security products, Microsoft Defender, Malwarebytes and Google Play Protect are examples of tools readers may consider. None should be presented as a guarantee against every repackaged or newly compiled sample, and buying software is not a substitute for changing exposed passwords, revoking sessions, notifying financial providers or resetting a compromised device.
Technical reference
ESET’s original report contains indicators of compromise, classifications and additional sample details. Historical file names, hashes and domains should be treated as defensive reference material only and should not be opened or visited casually. See ESET Research’s full report.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




