We have observed a wave of Remote Code Execution vulnerabilities affecting Steam games and Workshop maps. 9 games so far:
Unturned Twice, Stick Fight Once, Mecha Chameleon once, Banana Shooter, Perfect Heist 2, Golf Gang, Bean Battles, Grapples Galore & Fragsurf
The attack is as follows:
- Victim joins a server
- Workshop map downloads automatically
- The map contains a .exe/.vbs/.bat/.dll file
- The map loads, and somehow, a completely intentional game feature executes a file. A "visit website" button handler wired to Application.OpenURL or even an animation event. A map scripting entity. Blueprint on BeginPlay.
Funny enough tho, the game doesn't actually run a file. It rather just asks windows to open it (basically the same thing). This falls into the category of RCE, and is just as dangerous regardless if we like it or not.
In at least 4 titles, the entire exploit chain is Application.OpenURL("payload.bat"). This is a function intended for opening the developer's website. And it is being used to open malware.
Most of these are already exploited in the wild by the same actor, who we assume is very bored? (V7rtual)
One game we came across (Redmatch 2) was NOT vulnerable. They validate content at load time and strip animator events. This is apparently possible.
Valve could end a good chunk of this entire wave overnight with a file-extension filter on workshop content and Mark-of-the-Web on downloads. Instead, each developer is discovering that Application.OpenURL executes files individually and by the time many people get their PCs infected.
Not so fun fact: Streamer @KickPapaGambles was hit by this nonsense and got 70,000$ stolen and drained off his wallets, all because he got social engineered to play Grapples Galore.
Controversial takes,
- Don't let workshop maps contain a .bat file
- A function named OpenURL should open a URL
@vxunderground@EricParker@Steam
i lost a million robux from a rce exploit on steam...
roblox user: BADUS1RNAM3 (red ice crown and red bucket of cheer). Please like if roblox moderation is cheeks.
@KreekCraft@Roblox_RTC@Roblox@Rolimons
We have observed a wave of Remote Code Execution vulnerabilities affecting Steam games and Workshop maps. 9 games so far:
Unturned Twice, Stick Fight Once, Mecha Chameleon once, Banana Shooter, Perfect Heist 2, Golf Gang, Bean Battles, Grapples Galore & Fragsurf
The attack is as follows:
- Victim joins a server
- Workshop map downloads automatically
- The map contains a .exe/.vbs/.bat/.dll file
- The map loads, and somehow, a completely intentional game feature executes a file. A "visit website" button handler wired to Application.OpenURL or even an animation event. A map scripting entity. Blueprint on BeginPlay.
Funny enough tho, the game doesn't actually run a file. It rather just asks windows to open it (basically the same thing). This falls into the category of RCE, and is just as dangerous regardless if we like it or not.
In at least 4 titles, the entire exploit chain is Application.OpenURL("payload.bat"). This is a function intended for opening the developer's website. And it is being used to open malware.
Most of these are already exploited in the wild by the same actor, who we assume is very bored? (V7rtual)
One game we came across (Redmatch 2) was NOT vulnerable. They validate content at load time and strip animator events. This is apparently possible.
Valve could end a good chunk of this entire wave overnight with a file-extension filter on workshop content and Mark-of-the-Web on downloads. Instead, each developer is discovering that Application.OpenURL executes files individually and by the time many people get their PCs infected.
Not so fun fact: Streamer @KickPapaGambles was hit by this nonsense and got 70,000$ stolen and drained off his wallets, all because he got social engineered to play Grapples Galore.
Controversial takes,
- Don't let workshop maps contain a .bat file
- A function named OpenURL should open a URL
@vxunderground@EricParker@Steam
Active RCE 1/5, Bean Battles; https://t.co/06MDadgUvT
Bean Battles, much like every other game which i'll soon post, happens to have workshop maps. This is not random, as these threat actors always use the same DNA criteria for these attacks. These games push the workshop maps to every player joining a lobby, which already clears out most of the delivery. A POC video demonstrating the exploit can be seen in this post.
In the meantime, please stay away from this game and do not join public lobbies until there is a patch.
@BeanBattlesGame, please reach out to us, we're happy to help.
@EricParker, @IntCyberDigest
Active RCE 1/5, Bean Battles; https://t.co/06MDadgUvT
Bean Battles, much like every other game which i'll soon post, happens to have workshop maps. This is not random, as these threat actors always use the same DNA criteria for these attacks. These games push the workshop maps to every player joining a lobby, which already clears out most of the delivery. A POC video demonstrating the exploit can be seen in this post.
In the meantime, please stay away from this game and do not join public lobbies until there is a patch.
@BeanBattlesGame, please reach out to us, we're happy to help.
@EricParker, @IntCyberDigest
Steam is being hit by a wave of threat actors using frontier AI models to find RCE Vulnerabilities. These are used to RAT victims and as a defense, we'll be using this page to report each single one of these games to raise awareness for you to STAY AWAY from those games.
These games are legitimate games with a reputation, so its not just published malicious games anymore. A handful of actual games could compromise your PC, simply just by joining a lobby.
Steam is being hit by a wave of threat actors using frontier AI models to find RCE Vulnerabilities. These are used to RAT victims and as a defense, we'll be using this page to report each single one of these games to raise awareness for you to STAY AWAY from those games.
These games are legitimate games with a reputation, so its not just published malicious games anymore. A handful of actual games could compromise your PC, simply just by joining a lobby.