How it works
The email offers a paid sponsorship to play and review an unreleased build: a "closed beta," an "early access client," or a "playtest key." It attaches the build itself as an .exe, or as an .scr, a screensaver file that Windows runs exactly like an .exe. There is no game in the file. It is a loader that installs an information stealer the instant you open it.
Attackers pose as a large publisher such as Plarium or RAID: Shadow Legends because gaming channels are used to receiving genuine review builds, so a client attached to an email feels normal. It is not. The stealer grabs your saved passwords and the YouTube session cookie, and within minutes your channel can be signed into from another machine.
The tell-tale signals
- An .exe or .scr attached directly to a first-contact offer
- "Closed beta," "playtest," or "early access client" framing
- The publisher name paired with a free webmail or newly registered address
- A deadline to record before a set date
- No signed contract and no known agency involved
What to do
No legitimate publisher emails you a raw .exe. Real playtest access comes through a Steam key, an official launcher, or a link on the publisher's own domain, and the paperwork comes before the file. Delete the attachment. Confirm any real deal through the brand's published creator program page. If you ran the file, disconnect the device from the network and treat the Google session as stolen: change the password and revoke sessions and app access from a different, clean device.