How it works

The email offers a paid sponsorship to play and review an unreleased build: a "closed beta," an "early access client," or a "playtest key." It attaches the build itself as an .exe, or as an .scr, a screensaver file that Windows runs exactly like an .exe. There is no game in the file. It is a loader that installs an information stealer the instant you open it.

Attackers pose as a large publisher such as Plarium or RAID: Shadow Legends because gaming channels are used to receiving genuine review builds, so a client attached to an email feels normal. It is not. The stealer grabs your saved passwords and the YouTube session cookie, and within minutes your channel can be signed into from another machine.

The tell-tale signals

What to do

No legitimate publisher emails you a raw .exe. Real playtest access comes through a Steam key, an official launcher, or a link on the publisher's own domain, and the paperwork comes before the file. Delete the attachment. Confirm any real deal through the brand's published creator program page. If you ran the file, disconnect the device from the network and treat the Google session as stolen: change the password and revoke sessions and app access from a different, clean device.