AntiMalwareJuly 22, 2026🇷🇺Translated from Russian

From Free Game Cheats to Arson: Cybercriminals Recruit Children for Espionage and Violent Crimes

Cybercriminals are increasingly viewing children not merely as gateways to their parents' finances but as direct perpetrators of high-risk operations. During extended school breaks, teenagers spend significantly more time immersed in online games and messaging apps, where fraudsters infiltrate with offers of free in-game currency, custom mods, cheats, and cracked game versions.

After establishing initial trust, attackers pressure young users to share SMS verification codes, banking card information, or grant remote access to a parent's smartphone. When persuasion fails, the criminals escalate to intimidation and blackmail using previously obtained personal data.

According to Kaspersky Lab, more than 19 million attempts to spread malicious and unwanted files disguised as popular games were detected from April 2024 to April 2025. These files install spyware and RAT trojans capable of reading private conversations, logging keystrokes, and secretly controlling cameras and microphones.

The danger intensifies when children use a parent's device containing corporate email and business applications, potentially exposing entire organizations to compromise through a single downloaded cheat.

Beyond account theft, adolescents are deceived into thinking they are assisting law enforcement agencies. Criminals threaten the arrest of parents or leverage compromising material to coerce compliance, ultimately demanding that children photograph their homes, surrender keys, set fire to property, or physically attack individuals.

In July, a 12-year-old boy from Leningrad Oblast was forced to assault a police officer, while a 13-year-old from Podolsk was ordered to ignite a gas column at a filling station.

Warning signs include a child suddenly hiding their screen, deleting chat histories, becoming anxious after calls, experiencing sleep disturbances, or receiving unusual instructions. Punishment only strengthens the criminal's hold, as the teenager becomes even more reluctant to confess.

Parents and guardians must reinforce that no unknown contact has the right to request codes, funds, documents, or secret assignments. Any such interaction should be immediately terminated, the conversation preserved, and shown to adults. Genuine law enforcement never recruits minors through gaming chats, as noted in reporting by Izvestia.

Related articles

AntiMalwareFraud & Social Engineering

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud

Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.

SecuritylabFraud & Social Engineering

Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia

Russians often discover fraudulent loans taken out in their name only when banks reject their applications, revealing unknown debts in their credit reports. The article explains how to obtain a list of credit bureaus via Gosuslugi or the Central Bank of Russia, download free reports twice a year from each BKI, and thoroughly review contracts, applications, and creditor inquiries rather than focusing solely on credit scores. It details the new self-ban mechanism available from March 2025 on Gosuslugi and September 2025 via MFC, which blocks remote lending while allowing exceptions for mortgages and education loans. Practical advice covers pre-travel preparations, immediate actions after losing documents or phones, and the step-by-step process of disputing fraudulent entries with creditors, police, and the Central Bank. The guide also includes a table of common red flags and a checklist of ongoing security habits to prevent identity theft and financial fraud.

SecuritylabFraud & Social Engineering

Aurorium Anti-Detect Browser Uses AI Fingerprinting Linked to Real Hardware and User Profiles to Evade Modern Anti-Fraud Systems

Aurorium is an anti-detect browser that differentiates itself from competitors by embedding spoofing directly into the browser kernel rather than relying on JavaScript patches. The product generates fingerprints using AI that analyzes the operator’s actual device hardware and matches it to a realistic social profile including age, income, occupation, and geography. Network routing is handled at the kernel level so that WebRTC and DNS traffic is forced through proxies without disabling features that anti-fraud systems flag. The company also published a detailed Cure53 security audit that identified and subsequently fixed four critical vulnerabilities. Team-oriented features include built-in CRM, task management, multi-team support, and a mobile application. The review highlights that Aurorium’s approach reduces the common mismatch between generated fingerprints and the supposed user’s real-world context that often triggers detection.

嘶吼Fraud & Social Engineering

CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps

CACTER has released an updated version of its PhishSim anti-phishing drill system designed to replace traditional theoretical training with realistic, immersive phishing simulations. The platform can replicate common attack vectors including fake links, malicious attachments, and disguised QR codes while impersonating legitimate senders and official domains to mimic both APT and spear-phishing campaigns. Organizations using the system have reportedly lowered their average employee click rate from 23.88% to 4.16% through regular, customized exercises. Key features include a continuously updated template library tailored to specific industries and business scenarios, automated visual reports that rank departments and classify employee risk levels, and actionable remediation recommendations. The entire workflow is completed in just four steps—selecting templates, grouping employees, launching drills, and reviewing reports—allowing companies to run ongoing training without dedicated security specialists. The solution emphasizes measurable results and a closed-loop process of simulation, analysis, and improvement to strengthen email security posture.