The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →In a campaign documented in 2024, threat actors posed as Web3 game studios, recruiters and NFT promoters to persuade developers to download fake game software. Recorded Future’s Insikt Group assessed that the malware’s likely objective was to steal cryptocurrency wallets, while also harvesting credentials that could unlock other accounts.
How the fake-game operation worked
The operation combined impersonation with a software download. Attackers used slightly altered project names, copied branding, fake social-media accounts and project pages that offered a game, an alpha build or a job-related test. The Astration project was a prominent example described by Dark Reading: attackers copied accounts and social content associated with the legitimate Alteration project, created a copy of its Discord server, and used fake job openings and NFT offers to approach developers.
The supposed game files were malware rather than launchers. A polished website, familiar-looking contacts or an active Discord community therefore provided no proof that the download was safe.
Projects identified in the 2024 reporting
After investigating Astration, Insikt reportedly found five additional fraudulent projects. The following status reflects what the 2024 report found, not the projects’ status today.
#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
| Project name | Status in the 2024 findings | Reported tactic or context |
|---|---|---|
| Astration | Investigated fraudulent project | Impersonated Alteration through copied social accounts, content and Discord infrastructure; used job offers and NFT promotions. |
| ArgonGame | Active in the reported findings | Named among the additional fraudulent projects identified by Insikt. |
| DustFighter | Active in the reported findings | Named among the additional fraudulent projects identified by Insikt. |
| CosmicWay Reboot | Active in the reported findings | Named among the additional fraudulent projects identified by Insikt. |
| Crypterium World | Inactive in the reported findings | Named among the additional fraudulent projects identified by Insikt. |
| Myth Island | Inactive in the reported findings | Named among the additional fraudulent projects identified by Insikt. |
Malware reported in the campaign
Coverage identified several infostealer families, with the exact list varying by source and case. Reported families included:
- Atomic macOS Stealer: reported for both Intel- and ARM-based Mac devices.
- Rhadamanthys: a reported malware family associated with some Windows infections.
- RisePro: another reported infostealer named in the coverage.
- Stealc: listed in Infoblox’s later analysis.
These should be read as families reported across the operation’s coverage, not as a claim that every victim received every family. The campaign targeted both macOS and Windows, so protecting only one platform leaves a gap for a cross-platform development team.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Why cryptocurrency wallets were the likely target
Insikt assessed wallet compromise as the likely end goal. Its warning, quoted by Dark Reading, says: “As wallet compromise continues to be the biggest threat in both Web3 and cryptocurrency security … we assess that wallet compromise is likely the end goal of this campaign.”
Infostealers can also collect browser data, credentials and other secrets. A compromised developer account may expose source repositories, project administration panels, email, Discord and cloud services in addition to wallet-related material. Dark Reading reported social-media accounts from developers who said their wallets were drained; one victim reportedly lost about 2.5 ETH, valued in that April 2024 article at about $8,000. That is an individual historical example, not a campaign-wide loss estimate or a current dollar valuation.
Rank #3
- Secure element (EAL6+ certified) and passphrase protection for bullet-proof physical security
- Two-button pad device interface, designed for user-friendly operation
- Bright OLED display for easy & secure hands-on verification
- PIN & passphrase enabled for on-device protection
- Fully open-source design for transparent security
Warning signs developers should treat as high risk
- A “game launcher,” alpha build or test file sent by an account that you have not independently verified.
- A job offer or NFT invitation that requires installing software before the employer or project can be confirmed.
- A project name that differs slightly from a known studio or game.
- Social accounts, websites or Discord servers that appear established but have no independently confirmed connection to the real project.
- Pressure to act quickly, keep the opportunity confidential or bypass normal software-review procedures.
Insikt specifically advised developers to “scrutinize the legitimacy of Web3 projects advertised on social media.” The safest interpretation is to verify the operator through a separately sourced channel, rather than trusting links or contact details supplied by the invitation itself.
Layered defenses for Web3 development teams
Verify the opportunity before downloading
- Find the project’s official site and accounts independently; do not use only the URLs or profiles in the message.
- Confirm the recruiter, studio and Discord administrators through a second, trusted channel.
- Ask why an installer is necessary and obtain a cryptographically verifiable release or a known, controlled distribution process.
- Decline downloads from an unverified project, even when the request is framed as hiring, testing or an NFT promotion.
Protect both operating systems
Keep current endpoint protection on every Windows and macOS device used by developers, including Apple silicon and Intel Macs. Insikt’s mitigations also include firewalls, intrusion detection and endpoint detection and response. These controls should be managed as complementary layers: training addresses the social-engineering approach, while endpoint and network controls address a malicious file that is opened anyway.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
Limit what a compromised workstation can reach
- Keep wallet seed phrases and signing keys off general-purpose browsing systems.
- Use hardware-backed or otherwise isolated signing workflows for valuable wallets.
- Separate development credentials from production and treasury access.
- Require multi-factor authentication and review unusual account, repository and wallet activity.
- Use DNS or domain-threat controls to block known suspicious infrastructure where those controls are available.
If a suspicious installer was opened
- Disconnect the device from networks without deleting evidence.
- From a separate trusted device, revoke active sessions and rotate credentials that may have been stored in the browser or on the computer.
- Move assets from potentially exposed wallets using a clean signing environment, where appropriate.
- Notify the organization’s security team, exchange or wallet provider, and preserve the file, messages and relevant logs for investigation.
- Rebuild or professionally examine the affected system before returning it to development work.
What the available domain data does—and does not—show
Infoblox’s May 29, 2024 analysis reported that 71.43% of the campaign domains it examined were identified as suspicious before they became available in open-source intelligence as malicious, with an average lead time of 115.4 days. It also reported that the analyzed domains were flagged an average of 3.6 days after WHOIS registration; one domain, blastl2[.]net, was flagged on its registration date.
Those figures describe Infoblox’s selected domain set and detection method. They are not a general benchmark for all DNS products, nor proof that a domain control will stop every social-engineering or malware incident. No reviewed reporting establishes the present-day status of the named domains or projects.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsQuick Recap
Best Value
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




