HomeSecurityDota 2: Malicious game mods infected gamers with malware

Dota 2: Malicious game mods infected gamers with malware

Security researchers have discovered four malicious game mods for the wildly popular online battle royale game Dota 2 , which were used by a threat actor to bypass gamers' systems.

Dota 2 mods

Dota 2 is a MOBA game that was originally released on July 9, 2013. Despite being almost 10 years old (or maybe 20 if we count the original Dota 1), it still attracts a large player base with around 15 million active monthly players.

The attacker created four game mods for Dota 2 and published them on the Steam store to target fans of the game, according to researchers at Avast Threat Labs.

“These mods were called Overdog no annoying heroes (id 2776998052), Custom Hero Brawl (id 2780728794), and Overthrow RTZ Edition X10 XP (id 2780559339),” said Avast researcher Jan Vojtěšek.

See also: Weee! data breach: Customer details exposed

There was also a new file named evil.lua that was used to control server-side Lua execution capabilities. This malicious snippet could be used to log, execute system, create coroutines, and submit HTTP GET requests.

According to Bleeping Computer, detecting the bundled backdoor in the first Dota 2 game mod published on the Steam Store was easy, but the twenty lines of malicious code included in the three newer mods were much harder to detect.

The backdoor allowed the threat to remotely execute commands on the gamers' infected devices, potentially allowing further malware to be installed on the device.

Dota 2: Malicious game mods infected gamers with malware

"This backdoor allows execution of any JavaScript obtained over HTTP, giving the attacker the ability to hide and modify the exploit code at their discretion without undergoing the game mod verification process, which can be dangerous," Vojtěšek said.

See also: SonicWall: Warns of "broken" WCF in Windows 11 22H2

On the players' compromised systems, the backdoor was also used to download a Chrome exploit known to be used by cybercriminals.

The targeted vulnerability is CVE-2021-38003, a serious bug in Google's V8 JavaScript and WebAssembly engine that was patched in October 2021.

“Since V8 was not sandboxed in Dota, the exploit itself allowed remote code execution against other Dota players,” Vojtěšek added.

The JavaScript exploit for CVE-2021-38003 was introduced in a legitimate file that added scoreboard functionality to the game, likely to make it harder to detect.

See also: Nodaria hacking group targets Ukraine with Graphiron

Avast reported its findings to Valve, the developer of Dota 2, and they in turn updated the vulnerable V8 version on January 12, 2023. Before that, Dota 2 was using a version of v8.dll from December 2018. Valve also removed the malicious game mods for Dota 2 and notified all gamers affected by the attack.

Vojtěšek said that according to Valve, less than 200 players were affected.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS