Tuesday, June 6, 2023
Meta Games News
No Result
View All Result
  • Home
  • Featured News
  • Gaming Platforms
    • Playstation
    • Mobile
    • PC
    • Xbox
  • Metaverse
  • Gaming Reviews
  • Popular Games
  • New Released
  • Videos
  • Home
  • Featured News
  • Gaming Platforms
    • Playstation
    • Mobile
    • PC
    • Xbox
  • Metaverse
  • Gaming Reviews
  • Popular Games
  • New Released
  • Videos
No Result
View All Result
Meta Games News
No Result
View All Result
Home Popular Games

Malicious Game Mods Target Dota 2 Game Users

by Meta Games News
10/02/2023
in Popular Games
Reading Time: 4 mins read
0 0
A A
0
Malicious Game Mods Target Dota 2 Game Users
Share on FacebookShare on Twitter


A threat actor recently uploaded four “mods” containing malicious code into the catalog in the official Steam store that players of the popular Dota 2 online game use for downloading community-developed game additions and other custom items.

Mods, short for “modifications,” offer in-game content that players create rather than the developers.

Users who installed the mods ended up with a backdoor on their systems that the threat actor used to download an exploit for a vulnerability (CVE-2021-38003) in the V8 open source JavaScript engine version present in a framework called Panorama that players use to develop custom items in Dota 2.

Avast researchers found the issue and reported it directly to Valve, Valve’s game developer. Valve immediately updated the game’s code to a new (patched) version of V8, and took down the rogue game mods from its Steam online store. The gaming company — whose portfolio includes Counter-Strike, Left 4 Dead, and Day of Defeat — also notified the small handful of users who downloaded the backdoor about the issue and implemented unspecified “other measures” to reduce Dota 2’s attack surface, Avast said.

Valve did not respond immediately to Dark Reading requests for comment.

Dota 2’s Customization Features: How to Take Advantage

Avast’s attack is similar to other instances where threat actors have uploaded malicious applications to Google Play or Apple’s App Store.

The code was uploaded to Valve’s Steam Store. This took advantage of Dota 2’s flexibility to allow players to personalize the game in many different ways. Dota’s game engine gives anyone with even basic programming skills the ability to develop custom items such as wearables, loading screens, chat emojis, and even entire custom game modes — or new games, Avast said. They can then upload those custom items to the Steam store, which vets the offerings for unsuitable content, and then publishes them for other players to download and use. 

The researchers cautioned that because Steam’s security vetting process focuses more on moderation than security bad actors may be able to sneak malicious code into the store. “We believe the verification process exists mostly for moderation reasons to prevent inappropriate content from getting published,” according to Avast’s blog post. “There are many ways of hiding a backdoor in a game mode. It would be extremely time-consuming to try and detect them all during verification.”

Boris Larin, lead security researcher at Kaspersky’s global research and analysis team, says that while game companies are not directly responsible for malicious code embedded into third-party modifications, incidents like these still harm the company’s reputation. This is especially true when modifications are distributed through special repositories owned by the game developer that may contain vulnerabilities.

Larin states that “in this particular case, timely updating third-party components would help to protect the players.” “JavaScript engines, built-in Web browsers and other vulnerabilities can often be exploited to execute remote code. This is why special attention must be paid.”

Gaming Industry remains a huge target

The incident at Valve is the latest in a string of attacks that have targeted online gaming companies and players in recent years — and especially since the COVID-19 outbreak, when social distance mandates drove a surge in online gaming. Riot Games’ systems were hacked by attackers who stole the source code to its League of Legends (and Teamfight Tactics) games. In exchange for not leaking the source code publicly, the attackers demanded Riot Games pay $10 million. An attacker also broke into Rockstar Games systems last year and obtained early footage from the next version Grand Theft Auto.

Akamai’s last-year report showed that there was a 167% rise in Web application attacks against gaming companies and player accounts. A plurality of these Web application attacks — 38% — involved local file inclusion attacks; 34% were SQL injection attacks, and 24% involved cross-site scripting. Akamai’s survey revealed that 37% of all distributed attacks on service (DDoS), was attributed to the gaming industry, twice that of the second-most targeted sector.

Like others, Akamai attributed the large attacker interest in gaming to both the lucrative nature of the entire industry and the billions of dollars users spend on microtransactions in-game while playing games. In 2022 PwC The gaming industry’s revenues were estimated at $235.7 billion in the current year. According to the consultancy firm, industry revenues are expected to grow by at least 8.4% over 2026.

Gaming companies have been under increasing pressure to increase their security measures in response to the attacks. Industry experts have noted that major security incidents can lead to lost player trust and decreased engagement.

Larin states that gaming companies need to regularly scan and update their systems. They also need to use a comprehensive defense concept that guides, equips and informs their team against the most sophisticated and targeted cyberattacks.

“All repositories – whether an app store or an open source package repository – should be automatically checked to ensure that there is no malicious content,” he states. He notes that this should include static checks for dangerous or obfuscated functionality, and scanning with an anti-virus engine SDK.

Larin says that open source code repository poisoning is becoming more common in recent years. Early detection can help prevent bigger incidents.



Source link

Tags: DotaGamemaliciousModsTargetUsers
Previous Post

8 minutes of new Atomic Heart Gameplay

Next Post

How tech is shaping Super Bowl LVII’s Chiefs-Eagles game

Related Posts

PS Plus Premium Add-Ons Trial for the Best Game of 2023
Popular Games

PS Plus Premium Add-Ons Trial for the Best Game of 2023

05/06/2023
Comets, Kings win district championships
Popular Games

Comets, Kings win district championships

03/06/2023
An athlete’s guide to exploring the host country of the 2023 ISA World Surfing Games
Popular Games

An athlete’s guide to exploring the host country of the 2023 ISA World Surfing Games

01/06/2023
Now Is the Perfect Time to Role-Play a Pandemic
Popular Games

Now Is the Perfect Time to Role-Play a Pandemic

30/05/2023
In college, I stopped using social media. My life has changed dramatically.
Popular Games

In college, I stopped using social media. My life has changed dramatically.

28/05/2023
HBO Max and Disney+: The Death of Streaming
Popular Games

HBO Max and Disney+: The Death of Streaming

26/05/2023
Next Post
How tech is shaping Super Bowl LVII’s Chiefs-Eagles game

How tech is shaping Super Bowl LVII's Chiefs-Eagles game

Take-Two Interactive Stock (TTWO), Despite the tough holiday sales, it’s not a value trap

Take-Two Interactive Stock (TTWO), Despite the tough holiday sales, it's not a value trap

New mobile game turns retro Sega games into sexy anime girls

New mobile game turns retro Sega games into sexy anime girls

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Today’s Wordle Review: June 3, 2023

Today’s Wordle Review: June 3, 2023

03/06/2023
M80 Raises 3 Million Dollars to Expand the ‘Web3’-enabled Esports Organization

M80 Raises 3 Million Dollars to Expand the ‘Web3’-enabled Esports Organization

31/05/2023
Day by day Offers: Get Three Free Months of Xbox Sport Go When You Purchase the Spine Controller

Day by day Offers: Get Three Free Months of Xbox Sport Go When You Purchase the Spine Controller

03/06/2023
Now Is the Perfect Time to Role-Play a Pandemic

Now Is the Perfect Time to Role-Play a Pandemic

30/05/2023
Counter-Strike 2 will apparently include “pets”

Counter-Strike 2 will apparently include “pets”

30/05/2023
MarTech’s Metaverse Marketing Experts to Follow

MarTech’s Metaverse Marketing Experts to Follow

30/05/2023
Greatest Armor For Poise Stat 

Greatest Armor For Poise Stat 

19/05/2022
NetEase launches new studio PinCool led by former Dragon Quest producer; will work on console games

NetEase launches new studio PinCool led by former Dragon Quest producer; will work on console games

29/05/2023
Rockay City is coming to Xbox in a week’s time, and achievements are now available

Rockay City is coming to Xbox in a week’s time, and achievements are now available

06/06/2023
Diablo 4 is already 10,000 years old

Diablo 4 is already 10,000 years old

06/06/2023
Final Fantasy XVI Release Date, PlayStation Exclusive and Pre-Order Price Confirmed

Final Fantasy XVI Release Date, PlayStation Exclusive and Pre-Order Price Confirmed

06/06/2023
The ability of one horrifying villain could make enemies fearful.

The ability of one horrifying villain could make enemies fearful.

06/06/2023
Children of Bannerlord

Children of Bannerlord

06/06/2023
Starfield Limited Edition Xbox Controller Seen At Target

Starfield Limited Edition Xbox Controller Seen At Target

05/06/2023
Trailers and release date for The Texas Chain Saw Massacre video game

Trailers and release date for The Texas Chain Saw Massacre video game

05/06/2023
Teamgroup Claims That Its AL1 Heatsink Can Dramatically Lower Your PlayStation 5’s SSD Temperature

Teamgroup Claims That Its AL1 Heatsink Can Dramatically Lower Your PlayStation 5’s SSD Temperature

05/06/2023
Facebook Twitter LinkedIn Tumblr RSS
Meta Games News

Meta Games News is a professional video game news and editorial site dedicated to bringing readers the most interesting and entertaining stories related to the world of video games.

CATEGORIES

  • Featured News
  • Gaming Reviews
  • Metaverse
  • Mobile
  • New Released
  • PC
  • Playstation
  • Popular Games
  • Videos
  • Xbox
No Result
View All Result

SITE MAP

  • Home
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 Meta Games News.
Meta Games News is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Featured News
  • Gaming Platforms
    • Playstation
    • Mobile
    • PC
    • Xbox
  • Metaverse
  • Gaming Reviews
  • Popular Games
  • New Released
  • Videos

Copyright © 2023 Meta Games News.
Meta Games News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In