Sunday, May 18, 2025
LBNN
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • Documentaries
No Result
View All Result
LBNN

Hackers planted a Steam game with malware to steal gamers’ passwords

Simon Osuji by Simon Osuji
February 19, 2025
in Creator Economy
0
Hackers planted a Steam game with malware to steal gamers’ passwords
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

Last week, Valve removed a game from its online store Steam because the product was laced with malware. 

After the removal of the game, which was called PirateFi, security researchers analyzed the malware and found that whoever planted it modified an existing video game in an attempt to trick gamers into installing an info-stealer called Vidar.

Marius Genheimer, a researcher who analyzed the malware and works at SECUINFRA Falcon Team, told TechCrunch that judging by the command and control servers associated with the malware and its configuration, “we suspect that PirateFi was just one of multiple tactics used to distribute Vidar payloads en masse.”

“It is highly likely that it never was a legitimate, running game that was altered after first publication,” said Genheimer. 

In other words, PirateFi was designed to spread malware. 

Genheimer and colleagues also found that PirateFi was built by modifying an existing game template called Easy Survival RPG, which bills itself as a game-making app that “gives you everything you need to develop your own singleplayer or multiplayer” game. The game maker costs between $399 and $1,099 to license. 

This explains how the hackers were able to ship a functioning video game with their malware with little effort. 

According to Genheimer, the Vidar infostealing malware is capable of stealing and exfiltrating several types of data from the computers it infects, including: passwords from the web browser autofill feature, session cookies that can be used to log in as someone without needing their password, web browser history, cryptocurrency wallet details, screenshots, and two-factor codes from certain token generators, as well as other files on the person’s computer. 

Vidar has been used in several hacking campaigns, including one attempting to steal Booking.com’s hotel credentials, others with the goal of deploying ransomware, and another effort to plant malicious advertisements on Google search results. During 2024, the Health Sector Cybersecurity Coordination Center (HC3) reported that Vidar, which was first discovered in 2018, has “grown to be one of the most successful infostealers.”

Infostealers are common types of malware designed to steal information and data from a victim’s computer. Infostealers are often sold in the malware-as-a-service model, meaning the malware can be purchased and used even by hackers with little skill. This also makes identifying who was behind PirateFi “very difficult,” said Genheimer, as Vidar “is widely adopted by many cybercriminals.”

Contact Us

Do you have more information about this malware, or other video games related hacks? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Genheimer said they analyzed several samples of the malware included in PirateFi, one found on the malware online repository VirusTotal, which was apparently uploaded by a gamer in Russia; another one they identified through SteamDB, a website that publishes information about games hosted on Steam. The researchers found another sample in a threat intelligence database they have access to. All three malware samples have the same functionality, according to Genheimer.

Valve did not respond to TechCrunch’s request for comment.

Seaworth Interactive, the purported developers of PirateFi, has no apparent online presence. Until last week, the game had an X account, which has now been removed. The account included a link to the game on Steam.

The owners of the account did not respond to a request to chat via Direct Message before it was removed.

Source link

Related posts

Heybike’s Alpha step-through e-bike is an affordable, all-terrain dreamboat

Heybike’s Alpha step-through e-bike is an affordable, all-terrain dreamboat

May 18, 2025
TechCrunch Week in Review: Coinbase gets hacked

TechCrunch Week in Review: Coinbase gets hacked

May 17, 2025
Previous Post

The Ketamine-Fueled ‘Psychedelic Slumber Parties’ That Get Tech Execs Back on Track

Next Post

Djibouti’s Mahmoud Ali Youssouf Elected New AU Commission Chair

Next Post
Djibouti’s Mahmoud Ali Youssouf Elected New AU Commission Chair

Djibouti’s Mahmoud Ali Youssouf Elected New AU Commission Chair

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Chinese firm expresses support for $20b Ogidigben gas project – EnviroNews

Chinese firm expresses support for $20b Ogidigben gas project – EnviroNews

4 months ago
J&J to buy psychiatric drug developer Intra-Cellular for $14.6B

J&J scraps depression testing for potential blockbuster drug

2 months ago
Robinhood’s Crypto Earnings Decreased $9 Million in Q2 2023

Robinhood’s Crypto Earnings Decreased $9 Million in Q2 2023

2 years ago
Sudan Mutual Aid Networks Offer a New Model for Aid Distribution

Sudan Mutual Aid Networks Offer a New Model for Aid Distribution

3 months ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0
  • Matthew Slater, son of Jackson State great, happy to see HBCUs back at the forefront

    0 shares
    Share 0 Tweet 0
  • Dolly Varden Focuses on Adding Ounces the Remainder of 2023

    0 shares
    Share 0 Tweet 0
  • US Dollar Might Fall To 96-97 Range in March 2024

    0 shares
    Share 0 Tweet 0
  • Privacy Policy
  • Contact

© 2023 LBNN - All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • Documentaries
  • Quizzes
    • Enneagram quiz
  • Newsletters
    • LBNN Newsletter
    • Divergent Capitalist

© 2023 LBNN - All rights reserved.