Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
VGSources
Blog

Hamster Kombat’s 250 Million-User Audience Was Targeted by Malware and Phishing Scams

Cybercriminals exploited Hamster Kombat’s reported 250 million-user audience with Android spyware, malicious Windows bots, fake apps, and Telegram phishing. Here’s what happened and how to recover safely.
Length7 min Posted Quest giverVGSources Team
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The threat was real, but the headline needs context: security researchers documented malware and phishing campaigns exploiting Hamster Kombat’s popularity in July 2024. The evidence does not show that all 250 million reported players were infected, or that they were victims of one coordinated attack.

Instead, criminals used the Telegram game’s name, promised crypto rewards, and demand for faster progress to distribute Android spyware, malicious Windows tools, fake apps, and Telegram-account phishing pages.

What actually happened?

Hamster Kombat became an unusually attractive lure because it combined a huge reported audience with crypto expectations. Players interacted with the game through Telegram and were interested in a future token or airdrop. That created several opportunities for criminals to impersonate the game, sell fake automation tools, or promise to convert in-game balances into cash.

The documented activity was not one malware strain or one unified operation. It consisted of different campaigns that abused the Hamster Kombat brand:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Android spyware disguised as the game.
  • Fake Android storefronts and copycat applications.
  • Windows farming bots and auto-clickers carrying an infostealer.
  • Fake withdrawal services designed to steal Telegram accounts.

ESET published its research on July 23, 2024, while Kaspersky reported a related Telegram phishing campaign on July 17, 2024. The available reporting describes those 2024 campaigns; it does not establish that a new, coordinated Hamster Kombat malware campaign was active in August 2026.

ESET’s research and Kaspersky’s report are the primary sources for the findings.

Android spyware: the Ratel app

ESET identified an Android spyware application called Ratel that was disguised as Hamster Kombat and distributed through an unofficial Telegram channel.

The application requested two particularly sensitive permissions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Notification access: this can expose notifications, including login codes, private messages, and financial alerts.
  • Default SMS access: this can allow an app to read and send text messages and interfere with SMS-based account recovery.

ESET reported that the operators could use these capabilities to subscribe victims to paid services or otherwise spend money without making the abuse immediately obvious. Control over notifications and SMS can also help attackers intercept one-time codes and monitor activity on the device.

That does not mean every unofficial Hamster Kombat app contained Ratel. ESET also found copycat apps that were primarily deceptive or ad-supported. The important distinction is that an unofficial APK creates substantially more risk than the legitimate Telegram experience, even when a particular copycat has not been proven to contain spyware.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Windows “farm bots” delivered Lumma Stealer

Hamster Kombat was a Telegram mini-app and clicker game, not a conventional PC game that required a Windows executable. That made claims about an “official Windows version,” farming bot, or auto-clicker especially suspicious.

ESET found GitHub repositories advertising tools that promised to automate gameplay or increase earnings. The downloaded files instead contained cryptors associated with Lumma Stealer, an infostealer malware family. Broadcom/Symantec described the same general lure: fake Hamster Kombat automation tools used to deliver Lumma Stealer variants.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Infostealers can search a Windows computer for browser passwords, cookies, session tokens, cryptocurrency-wallet data, and other locally stored secrets. The research does not establish that every infected person lost cryptocurrency, or that every sample stole the same data. But a machine infected with an infostealer should be treated as a serious compromise because changing one password may not invalidate stolen cookies or active sessions.

Fake withdrawal services stole Telegram accounts

Kaspersky documented a different type of attack targeting Russian-speaking Telegram users. Fake services promised to convert Hamster Kombat balances into cash. Victims were told that their payout would arrive after they authorized through Telegram.

The authorization page was fake and designed to capture account credentials or access. This was phishing and account theft, not necessarily malware infection.

A hijacked Telegram account can be used to:

  • Read private chats and enter groups.
  • Send scam messages to contacts.
  • Spread more phishing links.
  • Target connected crypto services or wallets.
  • Change account settings and make recovery harder.

The distinction matters. A player who entered credentials on a fake withdrawal page needs account and session recovery. A player who installed a malicious APK needs device and permission checks as well. The remedies overlap, but they are not identical.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Does “250 million players targeted” mean 250 million victims?

No. The 250 million figure was a reported audience figure used in contemporaneous coverage, not a count of confirmed infections, compromised accounts, or financial losses.

The strongest supported conclusion is that criminals targeted the Hamster Kombat user community as a potential pool of victims. The reviewed sources do not provide verified numbers for:

  • Attempted or successful infections.
  • Compromised Telegram accounts.
  • Stolen wallets or funds.
  • Total financial losses.
  • The global geographic distribution of victims.

Nor does the reporting show that the genuine Hamster Kombat service or its developers distributed Ratel or Lumma Stealer. The documented malware was delivered through unofficial applications, fake storefronts, and third-party Windows tools that abused the game’s identity.

Why Hamster Kombat was such an effective lure

Several factors made the community valuable to scammers:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Scale: a reported audience of hundreds of millions offered criminals a large pool of potential targets.
  • Crypto expectations: the promise of a future token or airdrop made users more willing to click urgent payout and verification links.
  • Telegram distribution: the game was encountered inside a messaging platform where impersonators could contact users directly.
  • Automation demand: players looking for bots, auto-clickers, or faster progress were encouraged to download untrusted software.
  • Mixed technical experience: some users were unfamiliar with sideloading risks, wallet security, Telegram sessions, or infostealers.

An official-looking logo or a link posted inside Telegram does not prove authenticity. Attackers can use lookalike usernames, fake support accounts, cloned websites, paid advertisements, and redirects.

Warning signs to avoid

  • An APK offered through a Telegram channel, file-sharing site, or pop-up app store.
  • An “official” Hamster Kombat PC client, farming bot, or auto-clicker.
  • A promise of guaranteed withdrawals, accelerated airdrops, or limited-time verification.
  • A web page asking for Telegram credentials after an unsolicited message.
  • Any request for a crypto-wallet seed phrase or private key.
  • Software that asks for notification access, default-SMS status, accessibility access, or other powerful permissions without a clear reason.

Use the genuine Telegram experience and verify official links independently. Telegram publishes its official applications at telegram.org/apps/download; however, an official Telegram installation does not make every message, advertisement, bot, or linked website safe.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What Android users should do

If you have not installed anything, do not download unofficial Hamster Kombat APKs or tools. If you installed a suspicious app, take these steps:

  1. Open the Google Play Store.
  2. Tap your profile icon and select Play Protect.
  3. Run a scan and confirm that scanning is enabled.
  4. Review recently installed apps and remove anything suspicious.
  5. Check notification access, default SMS app, Accessibility, Device administrator, and Install unknown apps settings.
  6. Install Android and app updates.

Google says Play Protect can scan apps from Google Play and other sources and may warn about, disable, or remove harmful apps. It is an important defense, not a guarantee that every malicious app will be caught or that a compromised device has been fully cleaned.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you suspect spyware, avoid sensitive logins on the phone while investigating. Change important passwords from a clean device, and contact your bank or mobile carrier if you see unauthorized charges, SMS activity, or paid subscriptions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Windows users should do

If you ran a fake bot, auto-clicker, or other Hamster Kombat utility on Windows:

  1. Disconnect the computer from the internet if active theft is suspected.
  2. Do not use it to access banking, email, exchanges, Telegram, or wallets.
  3. Uninstall the suspicious tool.
  4. Update security intelligence in Windows Security.
  5. Run a full Microsoft Defender scan.
  6. Run Microsoft Defender Offline if detection persists or the infection appears serious.
  7. From a clean device, change passwords and revoke active sessions.
  8. Rotate or invalidate exposed wallet credentials where possible.
  9. Consider reinstalling Windows after a confirmed infostealer infection.

Microsoft provides guidance on unwanted software, potentially unwanted applications, and reputation-based protection and SmartScreen.

A password change alone may be insufficient. Lumma Stealer-type malware may have copied browser cookies, session tokens, or wallet data before removal. Security software cannot retrieve secrets that were already exfiltrated or reverse transactions that were already confirmed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

If your Telegram account may be compromised

In Telegram, open Settings → Privacy and Security → 2-Step Verification. Telegram also recommends an app passcode and reviewing active sessions or devices; see its account-security FAQ.

  • Terminate unfamiliar sessions.
  • Change the Telegram 2-Step Verification password if it may have been exposed.
  • Secure the email account associated with recovery.
  • Warn contacts that the account may have sent fraudulent messages.
  • Review connected wallets and revoke suspicious connections where possible.
  • Contact an exchange or wallet provider promptly if credentials or funds may be at risk.

Two-Step Verification helps protect future sign-ins, but it does not automatically undo an already-authorized malicious session or clean an infected phone or computer.

What the headline proves—and what it does not

The 2024 reporting proves that cybercriminals used Hamster Kombat’s popularity to distribute multiple kinds of malicious or deceptive content. It does not prove that every reported player was attacked, that the legitimate game spread malware, or that all unofficial apps were malicious.

The most accurate description is narrower: Hamster Kombat’s large user community became a lure for Android spyware, Windows infostealers, fake apps, and Telegram phishing scams. Players who stayed inside the genuine Telegram experience and did not install unofficial tools or enter credentials into fake payout pages faced a different risk profile from users who downloaded APKs, ran Windows automation software, or authorized through an untrusted website.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Bottom line: the Hamster Kombat malware story was real, but 250 million is not a confirmed victim count. Avoid unofficial APKs, PC clients, bots, auto-clickers, withdrawal services, and seed-phrase requests. If you installed a suspicious tool or entered Telegram credentials, treat it as a device or account-security incident and recover from a clean device.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More quests from Patch Notes

  1. 5 Best Pixelmon Server Hosting Providers for 2026, ComparedBlog8min
  2. 3 Best RAGE:MP Server Hosts for GTA V in 2026Blog8min
  3. 6 Best RLCraft Server Hosting Providers in 2026 (Ranked)Blog8min
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.