July 24, 2026

FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder

 FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder

A 15-page federal criminal complaint details how investigators combined a Bitcoin trail with Google cookies, phone records, and more than 500 Uber Eats deliveries to identify Zyaire Dontaevious Zamarion Wilkins as the alleged financier and marketer of a Steam malware campaign. A later search uncovered a Monero seed phrase tied to roughly $382,000 in cumulative transaction activity.

Federal agents arrested Wilkins, 21, in Florida on July 14. The complaint, entered the following day, charges him with one count of conspiracy to obtain information by computer for private financial gain.

The allegations concern the same eight-game campaign CryptoSlate reported on July 19. The FBI and the complaint allege that the campaign infected approximately 8,000 devices, accessed about 80 cryptocurrency wallets and stole at least $220,000.

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries
Related Reading

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries

Investigators reportedly followed Bitcoin-funded gift cards to Uber Eats deliveries, showing both sides of software-mediated wallet risk.

Jul 19, 2026 · Liam ‘Akiba’ Wright

The complaint also lays out how investigators connected campaign funding to Wilkins and what they found after obtaining a residential search warrant.

Messages describe Wilkins’ alleged financing role

Prosecutors allege that another participant created the developer accounts and launched the games, while Wilkins supplied funding and helped market them.

The games were promoted through Discord, Telegram, X and LinkedIn, while bots allegedly identified people with large crypto holdings for targeted messages.

Messages cited in the complaint include discussions about spending $10,000 on a remote-access trojan, embedding malware in games and persuading more people to download them.

Subject #1 allegedly told investigators that Wilkins provided launch and marketing funds in exchange for a share of stolen cryptocurrency and access to victims’ private information.

Bitcoin payments opened a wider identity trail

Investigators found the Bitcoin address in messages seized from an unnamed alleged co-conspirator identified as “Subject #1,” according to the complaint.

Wilkins allegedly supplied the address to receive funding for a cryptocurrency-draining campaign, and investigators verified that the address received an approximately $10,000 payment on the day it was supplied.

The complaint says investigators subsequently identified payments from the same address to Bitrefill, which allows customers to purchase gift cards and other digital products with cryptocurrency.

Bitrefill records connected the payments to one account that had purchased more than 150 gift cards, including Uber Eats cards. The account was registered using an email address that investigators then examined through records obtained from Google.

Google records allegedly linked that address through browser cookies to other accounts. One appeared to use Wilkins’ initials and was associated with a University of West Florida student, while another listed a phone number as its recovery number.

Investigators also linked that number to an email address containing Wilkins’ name, a Snapchat account that previously displayed his name, and a T-Mobile account registered at an address associated with his family.

More than 500 food orders narrowed the trail to three addresses

Uber identified one account associated with the Uber Eats gift cards, according to the complaint. That account was registered with the same phone number found in the other records.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.