HomeSecurityTrojan in the official versions of League of Legends & Path of Exile

Trojan in the official versions of League of Legends & Path of Exile

Gamers in some Asian countries have been targeted by cybercriminals who planted a Trojan (RAT) in the official versions of the online games League of Legends (LoL) and Path of Exile (PoE).

League of Legends & Path of Exile Trojan

A malware known as PlugX was observed to install itself when users attempted to install or upgrade one of the two games.

The threat is designed to extract information from the user's computer and upload it to a remote server. Another feature of PlugX is that it can download other malicious files.

According to security researchers at Trend Micro, the corrupted versions of the games were detected on Asian provider Garena.

Garena confirmed that all installation files for LoL and PoE were infected, as their systems, including patch servers, have been compromised by unknown attackers and infected with malware .

The provider also stated that, as soon as they were informed of the situation, they immediately carried out an audit and their systems have now been cleaned.

Trend Micro reports that when a malicious game launcher is installed on a user's computer, it will actually transfer three files. One is the legitimate game installer, the second is a malicious file that adds PlugX to the system, while a third is responsible for removing traces of the breach by replacing the infected launcher with the legitimate one.

By relying on this method, cybercriminals would conceal the infection, since a local scan of the computer would show a clean game launcher.

The security researchers noticed something important during their analysis. “While checking the certificate, we noticed that the hash value applied to the suspicious file was valid, which means that the ‘ signing tool ’ was used to concatenate it with the binary hash of the infected file. The clean game launcher , on the other hand, has an invalid digital signature,” wrote Benson Sy , an analyst at Trend Micro , in a blog post .

According to telemetry data from the antivirus software vendor, the most affected country is Taiwan, accounting for 82.59% of infections. Users in Singapore, Thailand, Malaysia, and Hong Kong were also affected, but to a much lesser extent, under 6.20%.

Currently, users who suspect they have been infected with PlugX can use a cleaning tool developed by Trend Micro specifically to deal with this malware.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS