|

FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries

A 15-page federal felony criticism particulars how investigators mixed a Bitcoin path with Google cookies, telephone data, and greater than 500 Uber Eats deliveries to identify Zyaire Dontaevious Zamarion Wilkins because the alleged financier and marketer of a Steam malware marketing campaign. A later search uncovered a Monero seed phrase tied to roughly $382,000 in cumulative transaction exercise.

Federal brokers arrested Wilkins, 21, in Florida on July 14. The complaint, entered the next day, fees him with one rely of conspiracy to get hold of data by laptop for personal monetary achieve.

The allegations concern the identical eight-game marketing campaign CryptoSlate reported on July 19. The FBI and the criticism allege that the marketing campaign contaminated roughly 8,000 gadgets, accessed about 80 cryptocurrency wallets and stole no less than $220,000.

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries
Related Reading

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries

Investigators reportedly followed Bitcoin-funded gift cards to Uber Eats deliveries, showing both sides of software-mediated wallet risk.
Jul 19, 2026
·
Liam ‘Akiba’ Wright

The criticism additionally lays out how investigators linked marketing campaign funding to Wilkins and what they discovered after acquiring a residential search warrant.

Messages describe Wilkins’ alleged financing function

Prosecutors allege that one other participant created the developer accounts and launched the video games, whereas Wilkins equipped funding and helped market them.

The video games have been promoted by Discord, Telegram, X and LinkedIn, whereas bots allegedly recognized folks with giant crypto holdings for focused messages.

Messages cited within the criticism embody discussions about spending $10,000 on a remote-access trojan, embedding malware in video games and persuading extra folks to obtain them.

Subject #1 allegedly instructed investigators that Wilkins offered launch and advertising funds in change for a share of stolen cryptocurrency and entry to victims’ non-public data.

Bitcoin funds opened a wider id path

Investigators discovered the Bitcoin tackle in messages seized from an unnamed alleged co-conspirator recognized as “Subject #1,” in accordance to the criticism.

Wilkins allegedly equipped the tackle to obtain funding for a cryptocurrency-draining marketing campaign, and investigators verified that the tackle acquired an roughly $10,000 cost on the day it was equipped.

The criticism says investigators subsequently recognized funds from the identical tackle to Bitrefill, which permits prospects to buy reward playing cards and different digital merchandise with cryptocurrency.

Bitrefill data linked the funds to one account that had bought greater than 150 reward playing cards, together with Uber Eats playing cards. The account was registered utilizing an electronic mail tackle that investigators then examined by data obtained from Google.

Google data allegedly linked that tackle by browser cookies to different accounts. One appeared to use Wilkins’ initials and was related to a University of West Florida pupil, whereas one other listed a telephone quantity as its restoration quantity.

Investigators additionally linked that quantity to an electronic mail tackle containing Wilkins’ identify, a Snapchat account that beforehand displayed his identify, and a T-Mobile account registered at an tackle related together with his household.

More than 500 food orders narrowed the path to three addresses

Uber recognized one account related to the Uber Eats reward playing cards, in accordance to the criticism. That account was registered with the identical telephone quantity discovered within the different data.

Further Uber data confirmed that the account positioned greater than 500 food-delivery orders between March 2024 and May 2026, spending over $9,000. Every order went to one in every of three areas: two addresses related to the University of West Florida and Wilkins’ North Lauderdale tackle.

The timing additionally adopted an alleged sample. Deliveries to the college addresses largely occurred whereas lessons have been in session, whereas orders exterior these durations went to Wilkins’ household tackle. The criticism says roughly 15 deliveries went to the North Lauderdale tackle between May 6 and May 17, 2026.

The Uber data fashioned one a part of a wider id chain that included Bitrefill account knowledge, Google cookies, electronic mail addresses, telephone data, Snapchat knowledge, and mobile-location data.

The criticism doesn’t set up that each cost or food order concerned stolen funds.

Search uncovered a Monero seed phrase tied to $382,000 in exercise

FBI brokers searched Wilkins’ North Lauderdale residence on July 8 and seized laptops, telephones, different digital gadgets, and three cryptocurrency pockets seed phrases, in accordance to the criticism.

One seed phrase was related to a Monero pockets containing eight addresses. Investigators stated the pockets’s transaction historical past confirmed that Wilkins had despatched or acquired roughly 1,233 XMR, valued at roughly $382,000.

The $382,000 determine displays cumulative transaction exercise described within the criticism. It is separate from the alleged victim-loss estimate of no less than $220,000, and the submitting doesn’t characterize all 1,233 XMR as stolen funds or as Wilkins’ pockets steadiness.

The criticism’s identification narrative depends on the Bitcoin tackle and data from Bitrefill, Google, Uber, Snap, T-Mobile, and different suppliers. Investigators obtained the Monero proof after executing the residential search warrant, utilizing a seized seed phrase somewhat than tracing Wilkins by Monero’s public transaction historical past.

Wilkins is presumed harmless except confirmed responsible. TechCrunch reported that his legal professional didn’t reply to a request for remark. Local 10 reported that Valve had not responded to its questions concerning the case and Steam’s safety measures by publication.

The submit FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder appeared first on CryptoSlate.

Similar Posts