Malicious Steam Game Caught Spreading Vidar Infostealer
Valve has purged a title from the Steam storefront following the discovery that the game was being used as a distribution vector for dangerous infostealing malware. The game, titled PirateFi, was identified by security researchers as a malicious package designed specifically to infect players with Vidar.
Marius Genheimer, a researcher with the SECUINFRA Falcon Team, led the analysis of the threat. His findings suggest that the developers behind PirateFi likely never intended to release a legitimate game. Instead, the software was constructed by modifying an existing game template known as Easy Survival RPG, allowing the attackers to ship a functional-looking application with minimal effort.

How the Vidar Malware Operates
Once executed on a victim’s machine, the Vidar payload is designed to harvest a wide range of sensitive personal information. According to Genheimer, the malware’s capabilities include the exfiltration of:
- Stored passwords captured via browser autofill features.
- Session cookies, which allow attackers to bypass authentication and access accounts.
- Web browser history logs.
- Cryptocurrency wallet data.
- System screenshots and files.
- Two-factor authentication codes from specific token generators.
“We suspect that PirateFi was just one of multiple tactics used to distribute Vidar payloads en masse,” Genheimer stated, noting that the command and control infrastructure points to a broader, coordinated effort rather than an isolated incident.
A Persistent Cybersecurity Threat
Vidar has established itself as a highly successful tool in the cybercrime ecosystem since its initial discovery in 2018. The malware is frequently distributed under the “malware-as-a-service” model, which lowers the barrier to entry for attackers with limited technical expertise. Its history includes high-profile campaigns targeting Booking.com credentials, ransomware deployments, and malicious Google search advertisements.
The researchers confirmed the malicious nature of PirateFi by analyzing samples from multiple sources, including the VirusTotal repository and SteamDB. All analyzed samples shared identical functional characteristics.
The entities behind the game, operating under the name Seaworth Interactive, have left little trace. Their social media presence, including an X account that linked directly to the Steam store page, was deactivated shortly after the game’s removal. Valve has not provided a comment regarding the incident.