FBI Links Steam Malware Funder via 500 Uber Orders and Monero
Key Takeaways
Federal complaint reveals investigators traced Zyaire Wilkins to Steam malware operations using Bitcoin trails, Google data, and 500+ Uber Eats orders. A subsequent search uncovered a Monero seed phrase linked to $382,000 in transaction activity.
Woofun AI reports that a 15-page federal criminal complaint has identified Zyaire Dontaevious Zamarion Wilkins as the alleged financier and marketer behind a coordinated Steam malware campaign. The filing details how investigators constructed a multi-layered evidence chain, combining Bitcoin transaction trails with digital footprints from Google cookies, phone records, and more than 500 Uber Eats deliveries to attribute the illicit activities to Wilkins.
Following the initial identification, a residential search executed by authorities uncovered a Monero seed phrase, which was subsequently linked to approximately $382,000 in cumulative transaction activity. The document further outlines the specific methodology used to connect campaign funding to Wilkins and enumerates the digital assets seized after the execution of a residential search warrant. Prosecutors allege that the operational structure involved a clear division of labor, with another participant creating the developer accounts and launching the malicious games, while Wilkins supplied the necessary capital and assisted in marketing efforts.
The games were promoted across multiple platforms, including Discord, Telegram, X, and LinkedIn, leveraging bots that allegedly identified users with large crypto holdings for targeted messaging. Messages cited in the complaint include discussions about spending $10,000 on a remote-access trojan, embedding malware in games, and persuading more people to download them. Subject 1 allegedly told investigators that Wilkins provided launch and marketing funds in exchange for a share of stolen cryptocurrency and access to victims’ private information.
Investigators found the Bitcoin address in messages seized from an unnamed alleged co-conspirator identified as "Subject 1", according to the complaint. Wilkins allegedly supplied the address to receive funding for a cryptocurrency-draining campaign, and investigators verified that the address received an approximately $10,000 payment on the day it was supplied. The complaint says investigators subsequently identified payments from the same address to Bitrefill, which allows customers to purchase gift cards and other digital products with cryptocurrency.
Bitrefill records connected the payments to one account that had purchased more than 150 gift cards, including Uber Eats cards. The account was registered using an email address that investigators then examined through records obtained from Google. Google records allegedly linked that address through browser cookies to other accounts. One appeared to use Wilkins’ initials and was associated with a University of West Florida student, while another listed a phone number as its recovery number.
Investigators also linked that number to an email address containing Wilkins’ name, a Snapchat account that previously displayed his name, and a T-Mobile account registered at an address associated with his family. Uber identified one account associated with the Uber Eats gift cards, according to the complaint. That account was registered with the same phone number found in the other records. Further Uber records showed that the account placed more than 500 food-delivery orders between March 2024 and May 2026, spending over $9,000.
Every order went to one of three locations: two addresses associated with the University of West Florida and Wilkins’ North Lauderdale address. The timing also followed an alleged pattern. Deliveries to the university addresses largely occurred while classes were in session, while orders outside those periods went to Wilkins’ family address. The complaint says approximately 15 deliveries went to the North Lauderdale address between May 6 and May 17, 2026. The Uber records formed one part of a wider identity chain that included Bitrefill account data, Google cookies, email addresses, phone records, Snapchat data, and mobile-location information.
The complaint does not establish that every payment or food order involved stolen funds. FBI agents searched Wilkins’ North Lauderdale residence on July 8 and seized laptops, phones, other digital devices, and three cryptocurrency wallet seed phrases, according to the complaint. One seed phrase was associated with a Monero wallet containing eight addresses. Investigators said the wallet’s transaction history showed that Wilkins had sent or received approximately 1,233 XMR, valued at roughly $382,000. The $382,000 figure reflects cumulative transaction activity described in the complaint.
It is separate from the alleged victim-loss estimate of at least $220,000, and the filing does not characterize all 1,233 XMR as stolen funds or as Wilkins’ wallet balance. The complaint’s identification narrative relies on the Bitcoin address and records from Bitrefill, Google, Uber, Snap, T-Mobile, and other providers. Investigators obtained the Monero evidence after executing the residential search warrant, using a seized seed phrase rather than tracing Wilkins through Monero’s public transaction history.
Comments
No comments yet.