Cybercriminals Exploit Gen Z's Favorite Games in 19M Attacks

Edward Zhou
Edward Zhou

CEO & Founder

 
July 16, 2025 3 min read

Gen Z’s Favorite Games Used as Bait in Cyberattacks

Kaspersky detected over 19 million attempts to download malicious files disguised as popular games from April 1, 2024, to March 31, 2025. Games like Grand Theft Auto, Minecraft, and Call of Duty were frequently exploited. The surge in attacks emphasizes the vulnerability of Gen Z gamers, who are often targeted due to their gaming habits.

Attempts to attack users through malicious or unwanted files disguised as Gen Z’s favorite games throughout the reported period

Image courtesy of Kaspersky

Kaspersky's report highlights that over 400,000 users were affected worldwide. The analysis included 20 popular game titles, with March 2025 recording the peak of 1,842,370 attack attempts.

Attack Statistics

The following table summarizes the attack attempts for the most exploited games:

TitleNumber of Attack Attempts
Grand Theft Auto4,456,499
Minecraft4,112,493
Call of Duty2,635,330
The Sims2,416,443
Roblox1,548,929
FIFA909,174
Among Us766,055
Assassin’s Creed584,873
CS: Go379,768
Red Dead Redemption349,821

Despite its age, Grand Theft Auto remains a primary target due to its modding community. The upcoming release of GTA VI in 2026 may increase such attacks as cybercriminals capitalize on the game's popularity. Minecraft follows closely due to its extensive modding ecosystem, attracting users seeking custom content that can often carry malware.

Kaspersky also identified various types of malware linked to these exploits. Downloaders, adware, and Trojans were prevalent, with downloaders accounting for over 17.7 million attempts.

Cybercriminal Tactics

Cybercriminals employ a variety of tactics to exploit the gaming community. Fake giveaways, phishing links, and malicious mods have become common methods for stealing credentials and spreading malware. Kaspersky reported that scammers often impersonate popular games, creating fake websites that promise in-game rewards in exchange for login details.

A deceptive giveaway link misleading Valorant online players

Image courtesy of Kaspersky

Kaspersky has launched an interactive game called “Case 404” to help educate Gen Z about these threats. The game aims to teach players how to recognize scams and protect their digital identities while engaging in their favorite activities.

Trojans and Malware Campaigns

A sophisticated malware campaign has been identified where cybercriminals use trojanized versions of popular games. These compromised installers were distributed through torrent trackers and targeted users in various countries. Popular games like BeamNG.drive and Garry's Mod were weaponized to deliver XMRig cryptominers.

Malicious torrent available for download

Image courtesy of Blogger

Attackers used Inno Setup to create trojanized installers that bypass security measures by employing anti-debugging techniques and encrypting malicious payloads. These strategies ensure the malware remains hidden until it can execute, often leading to theft of sensitive data and unauthorized access to gaming accounts.

Recommendations for Gamers

To combat these threats, Kaspersky recommends several safety measures:

  • Download games, mods, and tools only from official sources.
  • Be wary of giveaways that seem too good to be true.
  • Use strong, unique passwords and enable two-factor authentication on gaming accounts.
  • Employ a reliable security solution to detect malicious files.

For gamers, the rise of cyber threats highlights the importance of cybersecurity awareness. Engaging with platforms that offer legitimate services and maintaining updated security solutions can help mitigate risks associated with these attacks.

Explore more about how you can protect your gaming experience at Gopher Security. Engage with us to enhance your digital security.

Edward Zhou
Edward Zhou

CEO & Founder

 

CEO & Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions..

Related Articles

Ransomware Attacks Target Russian Vodka and Healthcare Sectors

The Novabev Group, parent company of the Beluga vodka brand, experienced a ransomware attack on July 14, 2025, causing significant disruptions. The attack affected WineLab, the company's liquor store chain, leading to a three-day closure of over 2,000 locations in Russia. The company reported that the attack crippled its IT infrastructure, particularly point-of-sale systems and online services. Novabev Group stated, "The company maintains a principled position of rejecting any interaction with cybercriminals and refuses to fulfill their demands."

By Alan V Gutnov July 19, 2025 3 min read
Read full article

Retail Sector Faces Surge in Ransomware Attacks: A 2025 Analysis

Publicly disclosed ransomware attacks on the retail sector globally surged by 58% in Q2 2025 compared to Q1, with UK-based firms being particularly targeted, according to a report by BlackFog. This spike in attacks follows high-profile breaches affecting retailers like Marks & Spencer (M&S), The Co-op, and Harrods, attributed to the threat actor known as Scattered Spider.

By Alan V Gutnov July 19, 2025 2 min read
Read full article

AI-Driven Lcryx Ransomware Emerges in Cryptomining Botnet

A cryptomining botnet active since 2019 has incorporated a likely AI-generated ransomware known as Lcryx into its operations. Recent analysis by the FortiCNAPP team at FortiGuard Labs identified the first documented incident linking H2miner and Lcryx ransomware. This investigation focused on a cluster of virtual private servers (VPS) utilized for mining Monero.

By Edward Zhou July 19, 2025 3 min read
Read full article

Preventing ClickFix Attacks: Safeguarding Against Human Error

ClickFix is an emerging social engineering technique utilized by threat actors to exploit human error. This technique involves misleading users into executing malicious commands under the guise of providing "quick fixes" for common computer issues. Threat actors use familiar platforms and deceptive prompts to encourage victims to paste and run harmful scripts.

By Alan V Gutnov July 19, 2025 3 min read
Read full article