Over the past couple of days we have become aware of malware targeting gamers! More specifically, a currently unidentified Threat Actor is utilizing an infostealer to target individuals who cheat (Pay-to-Cheat) in video games.
A Call of Duty cheat provider (PhantomOverlay) was alerted of fraudulent activity when user accounts began making unauthorized purchases. The cheat provider was the first to notice the fraudulent activity and reached out to the suspected victim. Since the initial victim was identified, more and more victims have been identified.
The scope of the impact is so large, and in a bizarre twist of fate, Activision Blizzard is coordinating with cheat providers to aid users impacted by the massive infostealer campaign.
Currently there is a presumed impact of:
- 3,662,627 Battlenet accounts compromised
- 561,183 Activision accounts compromised
- 117,366 Elite PVPers accounts compromised
- 572,831 UnknownCheats accounts compromised
- 1,365 PhantomOverlay accounts compromised
When Elite PVPers was approached by PhantomOverlay administrative staff about the compromised accounts, Elite PVPers confirmed they have identified 40,000+ valid user accounts compromised. These are seemingly freshly stolen credentials and are not present from previous publicly available credential dumps. However, due to the size of the data we have not been able to thoroughly review the data for duplicates.
Additionally, impacted users have begun reporting being victims of crypto-draining β their Electrum BTC wallets have been drained. We do not have any information on the amount of money stolen.
A Call of Duty cheat provider (PhantomOverlay) was alerted of fraudulent activity when user accounts began making unauthorized purchases. The cheat provider was the first to notice the fraudulent activity and reached out to the suspected victim. Since the initial victim was identified, more and more victims have been identified.
The scope of the impact is so large, and in a bizarre twist of fate, Activision Blizzard is coordinating with cheat providers to aid users impacted by the massive infostealer campaign.
Currently there is a presumed impact of:
- 3,662,627 Battlenet accounts compromised
- 561,183 Activision accounts compromised
- 117,366 Elite PVPers accounts compromised
- 572,831 UnknownCheats accounts compromised
- 1,365 PhantomOverlay accounts compromised
When Elite PVPers was approached by PhantomOverlay administrative staff about the compromised accounts, Elite PVPers confirmed they have identified 40,000+ valid user accounts compromised. These are seemingly freshly stolen credentials and are not present from previous publicly available credential dumps. However, due to the size of the data we have not been able to thoroughly review the data for duplicates.
Additionally, impacted users have begun reporting being victims of crypto-draining β their Electrum BTC wallets have been drained. We do not have any information on the amount of money stolen.
π₯48π€£46π10β€3π3π±3β€βπ₯1
vx-underground
Over the past couple of days we have become aware of malware targeting gamers! More specifically, a currently unidentified Threat Actor is utilizing an infostealer to target individuals who cheat (Pay-to-Cheat) in video games. A Call of Duty cheat providerβ¦
It should be noted that some of these accounts are also not cheaters. Some users impacted utilized gaming software for latency improvement (?), VPNs, and Controller Boosting software
(we don't know what this means)
(we don't know what this means)
π42π12π€―7β€6π₯°2
Unpopular opinion: cheating in video games is cool and badass
You should have nothing but the utmost respect for nerds who spent their time reverse engineering a game and developing ways to cheat. It isn't easy work especially with the advancement of anti-cheats.
You should have nothing but the utmost respect for nerds who spent their time reverse engineering a game and developing ways to cheat. It isn't easy work especially with the advancement of anti-cheats.
β€214π€84π«‘32π€16π13π€£7π₯6π’3π€2π2π€―1
FTX founder Sam Bankman-Fried has been sentenced to 25 years in prison.
π₯°97π67π€£46π’15π10π₯8π5β€4π€3β€βπ₯1
Checked in with Lockbit ransomware group administrative staff yesterday. We haven't spoken with them in a few weeks. They're now looking to expand operations into Violence-as-a-Service.
Very cool β malware, extortion, money laundering, and now violence π
Very cool β malware, extortion, money laundering, and now violence π
π€£172π30π±12β€11π₯11π«‘10π3π’2π2π₯°1π―1
Happy Supply Chain Attack Friday!
tldr if you updated Kali Linux recently you're pwned with malware
https://twitter.com/kalilinux/status/1773786266074513523
tldr if you updated Kali Linux recently you're pwned with malware
https://twitter.com/kalilinux/status/1773786266074513523
X (formerly Twitter)
Kali Linux (@kalilinux) on X
The xz package, starting from version 5.6.0 to 5.6.1, was found to contain a backdoor. The impact of this vulnerability affected Kali between March 26th to March 29th. If you updated your Kali installation on or after March 26th, it is crucial to apply theβ¦
π€£140π€―47π«‘6π5π’5π₯4π±3π€2β€1π1
The more we read about the xz supply chain attack the more we realize that everyone needs to move to Windows XP.
This wouldn't have happened on Windows XP
This wouldn't have happened on Windows XP
π€£141π―20β€11π4π2π€2β€βπ₯1π€1π€―1
vx-underground
Checked in with Lockbit ransomware group administrative staff yesterday. We haven't spoken with them in a few weeks. They're now looking to expand operations into Violence-as-a-Service. Very cool β malware, extortion, money laundering, and now violence π
Lockbit has clarified this is not to intimidate potential victims of ransomware. Lockbit administrative staff claim they were recently robbed and need to get their money back.
π€£114π€14β€5π1π±1π―1
meemaw shows nerds how to use ffmpeg, uses a 2 character password, uses neofetch, and complains about bloat on her 4gb linux box
based and linux pilled
https://www.youtube.com/watch?v=YVI6SCtVu4c
based and linux pilled
https://www.youtube.com/watch?v=YVI6SCtVu4c
YouTube
How To Use FFMPEG On Linux.
FFMPEG comes with Linux as a terminal based application and video converter. But there is an easy way to convert sound and video files to other formats. I show you how with MystiQ. You can also use QWinFF.
00:00 How To
03:24 MystiQ
05:06 How To Use
08:14β¦
00:00 How To
03:24 MystiQ
05:06 How To Use
08:14β¦
β€183π11π7π€―6π―4π₯3π€3π1
The xz situation is absolutely insane and almost certainly state sponsored.
This is an excellent example of a widely used software being maintained by basically one person.
Read this web article and then frown and become sad.
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
This is an excellent example of a widely used software being maintained by basically one person.
Read this web article and then frown and become sad.
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
boehs.org
Everything I Know About the XZ Backdoor
Please note: This is being updated in real-time. The intent is to make sense of lots of simultaneous discoveries
π±82π€15π₯8π«‘7π4π€―4β€3π€£2β€βπ₯1π’1
The xz backdoor was initially caught by a software engineer at Microsoft. He noticed 500ms lag and thought something was suspicious.
This is the Silver Back Gorilla of nerds. The internet final boss.
This is the Silver Back Gorilla of nerds. The internet final boss.
π₯187π«‘84π€25π12π€£11β€8π―7π5π1π1
Microsoft engineer: 500ms lag in liblzma? Something's up.
Also Microsoft engineer: 45 minute lag in Microsoft Teams? Perfect.
Also Microsoft engineer: 45 minute lag in Microsoft Teams? Perfect.
π€£374π₯42π29β€14π12π―5π₯°3π€3