The Acronis Threat Research Unit (TRU) has revealed the details of a highly targeted malware campaign exploiting the rising popularity of online gaming—an industry now valued at over US$7 billion in the Middle East and set to grow significantly, driven by a young, digitally-savvy population.
According to Acronis, Saudi Arabia, Qatar and Türkiye are among the most affected countries globally, highlighting a pressing need for greater cybersecurity awareness among gamers in the region. The attackers are specifically targeting gaming enthusiasts aged between 18 and 35, many of whom are active on community platforms like Discord, which is being widely used to distribute malicious content.
In this campaign, victims are enticed with what appear to be beta versions of indie games—such as Baruda Quest, Warstorm Fire, and Dire Talon. However, the downloads actually contain infostealer malware, including Leet Stealer, RMC Stealer, and Sniffer Stealer. These malicious tools are designed to steal sensitive data such as login details, payment credentials, and cryptocurrency wallets, potentially leading to financial losses, extortion, and unauthorised access to online accounts.
“This campaign stands out for its level of sophistication and its deliberate targeting of a technically proficient demographic,” said Jozsef Gegeny, Senior Researcher at Acronis TRU. “Our team identified the threat by analysing a stream of suspicious files and websites disguised as legitimate game content—many of which went undetected by leading antivirus solutions. While enterprises benefit from dedicated cybersecurity defences, individual consumers remain highly vulnerable.”
The attackers have employed a range of convincing tactics to enhance legitimacy—including the use of stolen branding, counterfeit promotional websites, and even fake YouTube channels. Links to compromised game installers are often circulated via Discord, capitalising on the trust and peer-sharing culture within gaming communities.
Acronis researchers found that the malware is frequently hidden within downloaders that simulate installation errors to obscure their real function. While the campaign initially emerged in Brazil and the United States, it has since gained global traction—with the Middle East identified as a key hotspot due to its youthful and enthusiastic gaming population.
“We strongly advise gamers to exercise caution—only download games or beta content from verified developer sites or official platforms, and enable multi-factor authentication wherever possible,” Gegeny added. “This campaign demonstrates that even knowledgeable users can be deceived, especially when malware evades detection by mainstream antivirus tools. A high level of vigilance remains the most effective protection against these increasingly deceptive threats.”
Acronis is calling for more attention to be paid to consumer-level cybersecurity, noting that as threats continue to evolve, individuals are becoming as much a target as businesses.

