TechCrunch News 02月19日
Hackers planted a Steam game with malware to steal gamers’ passwords
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Valve在Steam平台下架了一款名为PirateFI的游戏,原因是该游戏被植入了恶意软件。安全研究人员分析发现,该恶意软件试图诱骗玩家安装名为Vidar的信息窃取程序。PirateFI可能是大规模传播Vidar的策略之一,它通过修改现有的游戏模板Easy Survival RPG构建,降低了黑客植入恶意软件的难度。Vidar能够窃取多种数据,包括密码、cookies、浏览器历史、加密货币钱包信息、屏幕截图和双因素验证码等。Vidar已被用于多次黑客活动,并成为最成功的信息窃取程序之一。

⚠️ PirateFI游戏被下架,原因是其内部藏有恶意软件Vidar,该软件专门设计用于窃取用户信息。

🔑 Vidar恶意软件能够窃取多种敏感信息,包括浏览器密码、会话cookies、浏览器历史记录、加密货币钱包详情、屏幕截图以及双因素验证码等,对用户构成严重威胁。

🛡️ PirateFI的开发者利用名为Easy Survival RPG的游戏制作应用,降低了开发成本和技术门槛,使得黑客能够更容易地将恶意软件伪装成正常游戏进行传播。

🌐 Vidar信息窃取程序已被广泛应用于各种黑客活动中,包括窃取Booking.com的酒店凭证、部署勒索软件以及在Google搜索结果中植入恶意广告,显示出其强大的破坏力。

Last week, Valve removed a game from its online store Steam because the product was laced with malware

After the removal of the game, which was called PirateFI, security researchers analyzed the malware and found that whoever planted it modified an existing video game in an attempt to trick gamers into installing an info-stealer called Vidar.

Marius Genheimer, a researcher who analyzed the malware and works at Falcon Team, told TechCrunch that judging by the command and control servers associated with the malware and its configuration, “we suspect that PirateFi was just one of multiple tactics used to distribute Vidar payloads en masse.”

“It is highly likely that it never was a legitimate, running game that was altered after first publication,” said Genheimer. 

In other words, PirateFI was designed to spread malware. 

Genheimer and colleagues also found that PirateFi was built by modifying an existing game template called Easy Survival RPG, which bills itself as a game-making app that “gives you everything you need to develop your own singleplayer or multiplayer” game. The game maker costs between $399 and $1,099 to license. 

This explains how the hackers were able to ship a functioning video game with their malware with little effort. 

According to Genheimer, the Vidar infostealing malware is capable of stealing and exfiltrating several types of data from the computers it infects, including: passwords from the web browser autofill feature, session cookies that can be used to log in as someone without needing their password, web browser history, cryptocurrency wallet details, screenshots, and two-factor codes from certain token generators, as well as other files on the person’s computer. 

Vidar has been used in several hacking campaigns, including one attempting to steal Booking.com’s hotel credentials, others with the goal of deploying ransomware, and another effort to plant malicious advertisements on Google search results. During 2024, the Health Sector Cybersecurity Coordination Center (HC3) reported that Vidar, which was first discovered in 2018, has “grown to be one of the most successful infostealers.”

Infostealers are common types of malware designed to steal information and data from a victim’s computer. Infostealers are often sold in the malware-as-a-service model, meaning the malware can be purchased and used even by hackers with little skill. This also makes identifying who was behind PirateFI “very difficult,” said Genheimer, as Vidar “is widely adopted by many cybercriminals.”

Do you have more information about this malware, or other video games related hacks? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Genheimer said they analyzed several samples of the malware included in PirateFI, one found on the malware online repository VirusTotal, which was apparently uploaded by a gamer in Russia; another one they identified through SteamDB, a website that publishes information about games hosted on Steam. The researchers found another sample in a threat intelligence database they have access to. All three malware samples have the same functionality, according to Genheimer.

Valve did not respond to TechCrunch’s request for comment.

Seaworth Interactive, the purported developers of PirateFI, has no apparent online presence. Until last week, the game had an X account, which has now been removed. The account included a link to the game on Steam.

The owners of the account did not respond to a request to chat via Direct Message before it was removed.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

恶意软件 信息窃取 Vidar Steam 游戏安全
相关文章