Malware News Biggest game of year hit with malware attack that let hackers take over users' PCs

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,100
5,759
2,168
Germany
Meccha Chamelon's community maps were infected with viruses
Meccha Chameleon has proven this year’s biggest surprise hit, clearing over 15 million sales in under a month to become the latest viral phenomenon. Unfortunately, the latest news around the game isn’t particularly positive.

Last week, an independent researcher named Feint discovered that hackers had placed viruses inside certain user-created Steam Workshop maps. Once launched, community maps like Laser Tag Neon would open an invisible command prompt window that downloaded malicious software. This style of attack is called a malware dropper. Specifically, it would install a Remote Access Trojan (RAT) on affected systems, giving the attacker the ability to remotely control compromised PCs. The researcher recommended that those who played the affected maps should perform a full malware scan immediately and check their Documents and temporary folders for suspicious .bat files.

The map Laser Tag Neon was removed a few days after Feint’s blog post went up, but additional infected maps, like Chroma Grid Arena, were uploaded in its place. In response, Meccha Chameleon developers lemorion_1224 and Haganeiro put out version 3.1.0, which patched the vulnerability out of the game. However, in the process of removing the hack, the developers’ PC was hit with the virus, which a hacker used to take over Meccha Chameleon’s 100,000-member Discord.

“While fixing the issue of malware embedded in a MOD map, a system engineer’s PC got infected with malware,” an X post from lemorion_1224 reads. “After that, the hacker bypassed the engineer’s two-factor authentication on Discord, altered the server permissions, and banned all the staff members.” The PC in question has since been wiped, so it can’t be used to edit the game’s files or add additional exploits. “The perpetrator who hijacked the Discord is likely to issue various statements moving forward, so please refrain from clicking any suspicious links or following any dubious instructions they provide.”

A few hours ago, the developers were able to get access to the channel back after contacting Discord. “All hackers who had become admins have been fully banned. The server’s highest privilege account has been changed to a different one from the hijacked account, so it is safe.” The game’s developers rolled out update 3.3.1 this morning, which “further strengthened virus protection.”

It’s unknown how many users were affected by the issues, but the exploit may have been in the game for some time. A July 8 Steam review reads: “Game poses a super severe security risk. A friend of mine hosting a game had his computer hacked and someone was trying to take control of his system while we were playing.” The validity of this review hasn’t been confirmed, but the symptoms described match the virus description quite closely.

Although the virus only affected players accessing custom maps, and it appears to have been resolved, this isn’t the first time that Steam games have come loaded with malware. Just two months ago, Valve removed a free horror game, Beyond The Dark, which was stealing users’ data and cryptocurrency. Several other similar cases eventually prompted the Federal Bureau of Investigation to look into the issue, and the organization set up a webpage to collect information.
 
Security advice for players

The claims in this report cannot be independently confirmed from the information provided, so the game, maps, and infection details should not be treated as verified. However, if you downloaded or launched unofficial Workshop content, use standard precautionary steps:

  • Stop launching the affected game and unsubscribe from suspicious Workshop maps. Removing a map does not remove malware that may already have executed.
  • Run a full scan with Microsoft Defender or another reputable, fully updated security product. An additional on-demand scan from a reputable vendor may provide useful second-opinion coverage.
  • Check Discord, Steam, email, and other important accounts for unfamiliar sessions, messages, password changes, or newly added authentication methods.
  • From a known-clean device, change important passwords and revoke active sessions. Do not reuse passwords.
  • If you observed an unknown command window, unexpected remote-control activity, disabled security software, or unexplained account changes, disconnect the PC from the network and preserve relevant evidence before performing a reset or reinstall.
  • Do not run supposedly corrective files or commands posted in an allegedly compromised Discord server. Verify announcements through the game’s official Steam page or other independently confirmed channels.
  • Submit suspicious files or URLs to VirusTotal, while avoiding the upload of private or confidential documents.

A game update can address the original delivery method, but it cannot undo a compromise that already occurred. If malware was executed and scans find anything suspicious, the most reliable recovery option is usually a clean reinstall of the operating system after backing up only personal files that have been checked carefully.
 
So where's the money in this? AREN'T ALL HACKERS SUPPOSED TO GO AFTER THE MONEY ? Just goes to prove that you cannot predict what motivates hackers.
 
  • Like
Reactions: lokamoka820

You may also like...