Cult I Mean Group
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
thingsiplay@beehaw.org to Gaming@beehaw.orgEnglish · 7 months ago

malicious backdoor found in widely used game mod by Low Level [YouTube]

youtu.be

external-link
message-square
17
fedilink
57
external-link

malicious backdoor found in widely used game mod by Low Level [YouTube]

youtu.be

thingsiplay@beehaw.org to Gaming@beehaw.orgEnglish · 7 months ago
message-square
17
fedilink
malicious backdoor found in widely used game mod
youtu.be
external-link
This is why I don't download game mods. Another backdoor has been found, this time in a popular modular for City Skylines 2 by paradox games. Checkout what h...

Invidious, an alternative YouTube client in the browser without using YouTube directly (more private): https://inv.nadeko.net/watch?v=VH_8arwuRz8

Video Description:


This is why I don’t download game mods. Another backdoor has been found, this time in a popular modular for City Skylines 2 by paradox games. Checkout what happened in this video.

reddit.com/r/antivirus/comments/1gh4qp0/popular_mod_for_a_game_may_have_been_malicious_no

alert-triangle
You must log in or register to comment.
  • Telorand@reddthat.com
    link
    fedilink
    arrow-up
    26
    ·
    7 months ago

    Tldr: it’s a crypto wallet stealer.

    Always be wary of unknown code. Check comments on sites like Nexus. Run installers through virus checks.

    • Poopfeast420@discuss.tchncs.de
      link
      fedilink
      arrow-up
      17
      ·
      7 months ago

      If I understand it correctly from the reddit post, this was a popular mod, that you could get directly in-game, so probably available through the Steam Workshop or something. In that case you assume everything is fine and don’t really check out, if there’s something wrong.

      • circuitfarmer@lemmy.sdf.org
        link
        fedilink
        arrow-up
        14
        ·
        7 months ago

        It is a CS2 mod – CS2 lacks Steam Workshop support. Paradox did not put it in, in favor of their own mod platform.

        There was a lot of beef about the lack of workshop support, but it means it was on Paradox’s platform, if anything.

        • teawrecks@sopuli.xyz
          link
          fedilink
          arrow-up
          4
          ·
          7 months ago

          Wonder if steam workshop scans for this kind of thing, or if it would have otherwise been found quicker.

          • thingsiplay@beehaw.orgOP
            link
            fedilink
            arrow-up
            5
            ·
            7 months ago

            This mod had some clever tricks to avoid detection from Antivir scanner. Not sure how deep and complex the Steam Workshop antivir scanner goes (if any). Hard to say if they would have found and prevented it. However, all antivir and other scanner software learned from this and now every malware using this technique could be detected instantly. At least in theory.

            • Poopfeast420@discuss.tchncs.de
              link
              fedilink
              arrow-up
              3
              ·
              7 months ago

              Steam has some basic scans, but nothing special. This kind of thing happened before, with mods and even games.

              • thingsiplay@beehaw.orgOP
                link
                fedilink
                arrow-up
                1
                ·
                7 months ago

                I would assume so. Did this happen in Steam Workshop?

                • Poopfeast420@discuss.tchncs.de
                  link
                  fedilink
                  arrow-up
                  3
                  ·
                  7 months ago

                  Yes. Apparently there were enough mods like this, that someone made a list to unsubscribe from them:

                  https://steamcommunity.com/sharedfiles/filedetails/?id=2749608338

                  Also, this time it’s the first Cities Skyline, I don’t know of any other games, but it wouldn’t surprise me.

      • Telorand@reddthat.com
        link
        fedilink
        arrow-up
        7
        ·
        7 months ago

        Man if that’s the case, that really sucks.

    • DarkThoughts@fedia.io
      link
      fedilink
      arrow-up
      5
      ·
      7 months ago

      At least name the mod.

      • Butterbee (She/Her)@beehaw.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        7 months ago

        It was the traffic mod, and it’s been patched for a while now. Edit: Wait. I’m out of date. It happened AGAIN?

        • Nighed@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 months ago

          That post is from 10 days ago, so is probably the traffic mod?

    • FeelzGoodMan420@eviltoast.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 months ago

      deleted by creator

  • Fitik@fedia.io
    link
    fedilink
    arrow-up
    10
    ·
    7 months ago

    What’s the name of the mod?

    • coyotino [he/him]@beehaw.org
      link
      fedilink
      English
      arrow-up
      14
      ·
      7 months ago

      Paradox posted this the other day: https://www.paradoxinteractive.com/games/cities-skylines-ii/news/traffic-breach-statement

      I think it’s just called “Traffic”? It’s still early days for CS2 mods, not that weird for a mod to have such a generic name.

      • Fitik@fedia.io
        link
        fedilink
        arrow-up
        6
        ·
        7 months ago

        Thanks for the info!

Gaming@beehaw.org

gaming@beehaw.org

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !gaming@beehaw.org

From video gaming to card games and stuff in between, if it’s gaming you can probably discuss it here!

Please Note: Gaming memes are permitted to be posted on Meme Mondays, but will otherwise be removed in an effort to allow other discussions to take place.

See also Gaming’s sister community Tabletop Gaming.


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 54 users / day
  • 481 users / week
  • 2.11K users / month
  • 4.85K users / 6 months
  • 1 local subscriber
  • 31.4K subscribers
  • 3.1K Posts
  • 43.2K Comments
  • Modlog
  • mods:
  • alyaza [they/she]@beehaw.org
  • TheRtRevKaiser@beehaw.org
  • gyrfalcon@beehaw.org
  • Whom@beehaw.org
  • The_Hunted_One@beehaw.org
    cake
  • Chloyster [she/her]@beehaw.org
  • Chris Remington@beehaw.org
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org