Sniper: Phantom's Resolution Malware: 2026 Status and Steps

- Sniper: Phantom's Resolution in 2026: the short answer
- Timeline: Steam malware games, 2025 to 2026
- What changed since 2025
- Red flags and scams around fake Steam games (our analysis)
- What to do if you ran the Sniper demo
- What is still unknown
- Our original 2025 report
- Unpacking the malware: a sophisticated infostealer
- Steam's ongoing security struggles
- Related guides on 2-Spyware
Sniper: Phantom's Resolution in 2026: the short answer
The game was never real, and it is gone from Steam. Valve removed the Sniper: Phantom's Resolution listing in March 2025 after users reported that its free demo installed an information stealer.[6] The demo was downloaded from the developer's own site and a GitHub project, not from Steam itself.[6][7]
In 2026 Steam malware is under an FBI investigation, but this title is not on the published list. The FBI names BlockBlasters, Chemia, Dashverse or DashFPS, Lampy, Lunara, PirateFi and Tokenova.[8] If you ran the Sniper demo, the risk to your accounts is the same: stolen passwords and sessions.
| Question | Answer |
|---|---|
| What was it? | A Steam listing for a sniper game with a malicious demo[6] |
| Removed | March 2025[6] |
| Where the demo came from | The developer's website and GitHub, outside Steam[6][7] |
| Malware type | Information stealer that targets saved browser data[7] |
| File seen | Windows Defender SmartScreen.exe[7] |
| On the 2026 FBI list? | No, the list names seven other games[8] |
Timeline: Steam malware games, 2025 to 2026

| Date | Event |
|---|---|
| February 2025 | Valve removes PirateFi, another malicious game[6] |
| March 20, 2025 | Bitdefender describes the Sniper demo's stealer behaviour[7] |
| March 21, 2025 | TechCrunch reports that Valve removed the Sniper listing[6] |
| August 30, 2025 | A BlockBlasters patch starts downloading a crypto stealer[9] |
| February 17, 2026 | The FBI publishes a victim form for Steam malware games[8] |
What changed since 2025
In March 2025 the Sniper demo looked like the second case in a row, after PirateFi a month earlier.[6] Since then the pattern grew. G Data reported that BlockBlasters, a game that first worked normally, began downloading a crypto stealer after a patch on August 30, 2025.[9]
In 2026 the FBI Seattle Division asked victims of Steam games embedded with malware to come forward. It says the actor mainly targeted users between May 2024 and January 2026.[8] Sniper: Phantom's Resolution is not on that list, so we cannot say whether the same people were behind it.
The Sniper case also differs in method. Its demo lived outside Steam, which let the files change without any store review.[6][7] The later cases show that even files served by Steam can turn bad through an update.[9]
Red flags and scams around fake Steam games (our analysis)
This list is our own analysis based on the cases above.
- A demo or patch that sends you to an outside website or GitHub instead of Steam's own download button.[6][7]
- A game demo that asks for administrator rights. A normal demo should not need them.[7]
- New studios with no history, few reviews and big promises, as in the Sniper and PirateFi listings.
- Messages on Discord, Telegram or Snapchat asking you to test a new game. The FBI form asks about this contact.[8]
- Re-uploads that use the Sniper: Phantom's Resolution name after the removal. Treat any such file as malware.
What to do if you ran the Sniper demo

1. Delete the demo. Remove the downloaded files and any folder the installer created. Look for a file named Windows Defender SmartScreen.exe outside the normal Windows folders.[7]
2. Check startup tasks. Open Task Scheduler and the Startup tab in Task Manager, and remove entries you do not recognise. Bitdefender says the demo created startup tasks to stay on the system.[7]
3. Run a full scan. Use reputable security software with current definitions. Our malware removal guides cover information stealers in detail.
4. Consider a reinstall. A stealer with administrator rights can hide extra files. A clean Windows install is the surest fix.
5. Reset passwords. From a clean device, change passwords saved in your browser, sign out of all sessions and turn on two-factor sign-in. Check your email with our leak check.
6. Report and watch. Report fake listings to Valve and watch bank, Steam and crypto accounts for activity you did not make.
What is still unknown
- How many people ran the demo. We found no download count.
- Who is behind Sierra Six Studios. No source we read names a person.
- Whether the Sniper case is linked to the seven games in the FBI investigation.[8]
- What phantom_sl.exe is. The sources we read do not mention that file name.
- What Valve changed after the removal. TechCrunch says Valve did not respond to a request for comment.[6]
Our original 2025 report
The text below is our report as first published in 2025. We keep it unchanged for the record; the sections above bring it up to date.
In a troubling development for the gaming community, Valve, the company behind the popular digital distribution platform Steam, has removed a demo for the game Sniper: Phantom's Resolution after it was found to infect users' systems with infostealer malware.[1]
The demo, intended as an early preview of a first-person shooter (FPS) developed by the obscure Sierra Six Studios, was originally listed on Steam with a full release slated for Q2 2025. Described as a tactical sniper experience with "realistic FPS mechanics and dynamic storytelling," the game promised players a chance to step into the shoes of a morally conflicted sniper contractor. However, what players encountered instead was a cybersecurity nightmare.
The demo managed to slip through Steam's vetting process, raising questions about the platform's security protocols for new submissions. Unlike typical Steam demos, which are hosted directly on the platform, Sniper: Phantom's Resolution directed users to an external GitHub repository for download – a red flag that went unnoticed until players began reporting suspicious activity.
Following a swift investigation sparked by community complaints[2] on forums like Reddit,[3] Valve pulled the demo from the Steam store on March 20, 2025, though traces of its listing lingered on the website. The incident underscores the challenges even a major platform like Steam faces in policing third-party content, especially from lesser-known developers.
Unpacking the malware: a sophisticated infostealer
While the specific strain of malware embedded in the Sniper: Phantom's Resolution demo has not been officially named, its behavior aligns with the characteristics of an infostealer – a type of malicious software designed to harvest sensitive data from infected systems.
Once installed, the malware disguised itself as a legitimate executable, with its main file named "Windows Defender SmartScreen.exe" to evade suspicion. Analysis by vigilant Reddit users revealed additional malicious components, including an "elevate.exe" file to gain administrative privileges and tools like a Node.js wrapper and Fiddler, a web debugging proxy capable of intercepting browser cookies.
Upon execution, the infostealer quietly went to work, targeting credentials, session cookies, and other personal data stored on users' computers. Its ability to bypass Windows security measures and remain undetected by some antivirus programs suggests a level of sophistication that cybersecurity experts describe as "new and clever."
The developer, Sierra Six Studios, saw its website (sierrasixstudios[.]dev) taken offline shortly after the reports surfaced, further fueling speculation about the entity's legitimacy. Players who downloaded the demo are urged to run full system scans, uninstall the software, and reset passwords to mitigate potential damage.
Steam's ongoing security struggles
The Sniper: Phantom's Resolution incident is not an isolated case, but part of a disturbing trend affecting Steam. Just a month prior, in February 2025, Valve removed PirateFi,[4] a free-to-play survival simulator, after it was found to distribute the Vidar infostealer[5] malware. That breach impacted up to 1,500 users, prompting Valve to recommend drastic measures like system resets for affected players.
These back-to-back incidents highlight the growing audacity of malicious actors exploiting Steam's open submission process, where a $100 fee and minimal oversight allow questionable titles to reach the storefront.
Valve has responded by tightening developer security, including mandatory two-factor authentication for updates, but gaps remain – particularly with external links, which bypass Steam's hosting safeguards.
For gamers, the takeaway is clear: caution is paramount. Verifying a game's developer, scrutinizing community feedback, and avoiding downloads from untrusted sources are critical steps in staying safe.
The security incidents at Steam demonstrate how trusted platforms face evolving threats from cybercriminals while maintaining accessibility for small studios. The gaming community remains in wait to observe Valve's protective measures for its millions of users against upcoming hidden threats.
Related guides on 2-Spyware
Frequently asked questions
What is Sniper: Phantom's Resolution?
It was a Steam listing for a sniper shooter whose free demo installed malware. Valve removed it in March 2025 after users reported the demo was an information stealer.{6} The demo was hosted outside Steam, on a website and GitHub project linked from the listing.{6}{7} No real game ever shipped as far as we found.
Is Sniper: Phantom's Resolution still on Steam in 2026?
No. Valve removed the listing in March 2025, and we found no sign that it returned.{6} Any download that uses the name today should be treated as malware. The game does not appear on the FBI list of Steam malware games published in 2026, which names seven other titles.{8}
What did the Sniper: Phantom's Resolution demo do?
Bitdefender says the demo asked for administrator rights, opened a web browser and pulled resources from GitHub, including a tool for decrypting saved Windows data.{7} It created startup tasks to stay on the system and used a file named Windows Defender SmartScreen.exe.{7} That is typical behaviour for a password stealer.{7}
Who is Sierra Six Studios?
Sierra Six Studios was the developer name on the Steam listing, according to our original 2025 report. Bitdefender says the GitHub project that hosted the payload was run by the same developers listed on Steam.{7} We found no other games or company records for that name.
What is phantom_sl.exe?
People search for this file name together with the game. The sources we read for this update do not describe a file named phantom_sl.exe, so we cannot confirm what it is. Bitdefender names a file called Windows Defender SmartScreen.exe.{7} Scan any unknown executable from that period with up-to-date security software.
What should I do if I ran the demo?
Assume your saved passwords and browser sessions were stolen. Scan the PC, remove startup tasks the demo created, and consider a clean Windows reinstall.{7} Then change passwords from a clean device, sign out of all sessions and turn on two-factor sign-in for Steam, email and banking.
Log in to comment
No comments yet. Be the first.