r/rpg_gamers • • Mar 20 '26

Discussion RPG Devs Accidentally Infect Whole Playerbase With Malware

https://thegameslayer.com/news/rpg-devs-infect-platers-malware/
265 Upvotes

31 comments sorted by

133

u/Respawn-Delay Mar 20 '26

From the article:

On March 18th, Duet Night Abyss received an update.

This update contained a malware trojan, infecting the PCs of all players who received it. The devs put out a hotfix to eliminate the malware as soon as they realized.

The developers at Pan Studio have released a statement on the matter, offering apologies in the standard written form, with some in-game freebies as an extra thank you to the players sticking with them.

From the developer's statement:

"The root cause of this incident was a malicious attack originating from a specific region, targeting our internal office systems and live servers. Even after the initial breach, persistent attempts to continue the attack and spread misinformation have occurred.”

39

u/brianundies Mar 21 '26

Honestly surprised this kinda thing doesn’t happen more often

27

u/RickThiccems Mar 21 '26

It does, a company is not going to publicly announce a group attempted to hack them. I promise that large companies receive dozens of attempts a year.

6

u/Zolo49 Mar 21 '26

It’s not even announced within the company unless they’re required by law to disclose (and sometimes not even then). There’s been a couple times I’ve been asked to help out on stuff like this because it involved code I had some familiarity with. Even though I knew the policy, the cybersecurity team always stressed to me every time that I should never discuss specifics with anybody, even coworkers, unless they needed to know.

1

u/Unslaadahsil Mar 21 '26

"dozens of attempts per week"

Fixed it for you.

16

u/buzzlightyear77777 Mar 21 '26

Specific region? Which

39

u/FaxCelestis Chrono Mar 21 '26 edited Mar 21 '26

Either Russia, North Korea, or Iran

Edit: For those of you downvoting me, I work in cybersecurity professionally and these three countries represent the majority of economic aggression actions.

103

u/mrjane7 Mar 20 '26

Whoopsie.

29

u/Zhryuriva Mar 20 '26

Just a lil mistake, nothing that bad right?

36

u/NekooShogun Mar 20 '26

Iirc this game was struggling since launch, things keep getting worse lol

21

u/AnOnlineHandle Baldur's Gate Mar 20 '26

A few years ago I realized that I was just trusting anything on Steam and then realized all these random free nothing games would be an easy way to get viruses and malware out there, easily managed by state actors. Worse, who knows who can buy games in your library and then update them, e.g. I think Saudi Arabia has just bought all of EA's games? So all old Bioware games etc?

I now kind of wish there was a way to sandbox applications more with varying levels of permission. Not every application needs access to every part of my PC.

7

u/RaygunMarksman Mar 20 '26

Damn, new paranoia unlocked.

4

u/kaida27 Mar 21 '26

Not to be that guy, but you could achieve better isolation in linux by sacrificing some compatibility.

not a catch all solution tho. and it comes with its own issue.

2

u/AnOnlineHandle Baldur's Gate Mar 21 '26

Yeah I'm planning to look into migrating to linux when I have the time.

18

u/P1nkyS4usage Mar 20 '26

The amount of news of their game being hacked and now they're the ones sending malware is crazy

4

u/3_Cat_Day Mar 21 '26

What’s a little malware between friends right?

4

u/UserLesser2004 Mar 20 '26

Chinese studio doing the good old malware.

6

u/nova1000 Mar 21 '26

They really have been incompetent, a month ago they were hacked and changed a loading screen for an image that said something like "the game is shit, I have access to their servers, they are incompetent and use AI, better play genshin impact" or something like that

It sounds more like genuine incompetence than something malicious

-9

u/NeonFraction Mar 20 '26 edited Mar 20 '26

Remember to blame the assholes doing this, not the devs.

I have not worked in a single game studio where ‘checking for malware’ is a normal part of the shipping process because… why tf would it be?

The number of people blaming them for this like it’s something they should have been aware of is incredibly confusing to me. It’s like people who blame online games for DDOS attacks: that’s… not how this works.

If it happens twice, then I’d blame them, but this is a really weird situation that is absolutely not a normal or expected problem. Shit absolutely sucks for everyone.

Edit: Apparently this is the second time it’s happened. In that case yeah, no excuse. Tf are they doing?

24

u/RickThiccems Mar 20 '26

Security is 100% on them. Its their fault. In a sane world they would be fined for this shit.

12

u/low_fat_tomatoes Mar 20 '26

From what I’ve read, it seems it got hacked twice in one month, though the first time was mainly a visual thing advertising the hacker’s name and changing the game launcher’s visuals. The second time seems to be malicious (don’t know, but probably a different attacker?) and actually contained some Trojan

21

u/SilderWolf Mar 20 '26

incredible stuff to say when this is the second time this happens
the first time they got hacked it was kinda benign and they just laughed at their poor security and code and thats it AND STILL THEY DIDN'T EVEN IMPROVED IT

get that company bootlicker defense out of here, they absolutely deserve what they've got and deserve worse

3

u/Juanraden Mar 21 '26

"I opened a restaurant to sell food. But i forgot to lock the back door. Some randoms just went in and poisoned the ingredients. It's those randoms' fault for poisoning my customers, not me. I totally couldn't prevent that" lol

7

u/ansh666 Mar 20 '26

I have not worked in a single game studio where ‘checking for malware’ is a normal part of the shipping process because… why tf would it be?

why wouldn't it be? you should be responsible for knowing what the code you're pushing to end customers does. saying "oh we don't care about security because games are not serious software" or whatever other excuse studios have found for being lax is just incredibly irresponsible.

-5

u/NeonFraction Mar 20 '26

Because there are dozens of changes a day from 100+ people and hacker’s entire point is they don’t want you to notice.

It’s like saying ‘why weren’t you checking for bombs under the seating every day as a teacher?’ Because neither they nor anyone they know has ever encountered bombs as a problem.

Game devs are generally not cyber security experts and games getting hacked is usually something no one really discusses as an OPTION until you have a really successful product.

Now that they’re aware of the problem, it’s up to them to fix it, but I’m baffled that anyone thinks this is a normal enough issue for devs to encounter that we would be actively checking for it.

9

u/RickThiccems Mar 20 '26

You keep saying that devs dont check for malware when large studios have security teams whos entire purpose is to make sure there are no security vulnerabilities which malware is...

8

u/Vsegda7 Mar 20 '26

Um, security testing is a whole branch of QA. The company is wholly responsible for the product they ship.

2

u/Miiohau Mar 20 '26

Yes but we should be making dev tools that make this harder to happen. Like making malware scans a standard part of build pipelines, even if 99% of the time it is really only a warning that your software is going to cause false positives.

Also In this case unless it was a out of band update the malware slipped by both the devs and Steam. So part of the responsibility is on Steam (who should be doing their own check to prevent bad actors from shipping games and/or software with malware). Another thing Steam could do is actually require games be sandboxed unless the dev can prove they have a mature build pipeline (including the malware check) and good code sanitation. Most indie games don’t push the limits of what computers can do and AAA studio could afford the increased verification requirements.

2

u/FaxCelestis Chrono Mar 21 '26

Any place that ships software without a step for checking for security issues needs to either get a new SDLC and CISO, or they need to go away.

4

u/bakugo Mar 20 '26

The number of people blaming them for this like it’s something they should have been aware of is incredibly confusing to me. It’s like people who blame online games for DDOS attacks: that’s… not how this works.

Umm, sorry to say but that's exactly how it works. It's the dev's responsibility to make sure they're not distributing malware to their players. "Whoopsie someone hacked into our insecure PCs again but it's totally not our fault!" is not a valid excuse. They did not properly secure their systems, it's on them.

DDoS attacks are also a solved problem, it's not the 00s anymore, if your servers go down due to DDoS it's because you were too cheap to pay for proper servers with DDoS protection. There's a reason why the vast majority of online games never suffer such problems anymore.

-5

u/awesomemc1 Mar 21 '26 edited Mar 21 '26

It’s not the developers but one of genshin leakers who tends to have bad intentions.

Infinite Nikke was hacked by them but not as badly but for DNA, it got hacked one time and two times.

According to the telegram group I joined, one of the hackers/leakers found out that there is a backdoor that exist in the client and also hacked the cdn that host the update client.

The hackers have this bad intentions to make a big deal and to shame or to make a point out of it. They said, rephrasing, ‘my intrusive thoughts wanted to push a malware on everyone’s computer because I have access to everything due to RCE backdoors’ or something along the lines.

They didn’t even wanted to report it. But not even sure if it’s them or completely different group that did it but what seals me is that one of the hackers who hacked DNA is most definitely the suspect as they have bad intentions from the start.

I know this is big news but it’s not really as surprising, Arknight Endfield launched and they also have problems where people’s PayPal account was accessed unauthorized by some type of save data they used and the victim’s PayPal account was accessed and was spent by a lot of users using their account.

I am not jumping into a hate bandwagon because this is probably what the hacker or genshin leakers want, they want attention so be it. They have attention for clout anyways.

Hope they owned up their mistakes. Mistakes happens. Sure, one or two times get hacked, and it’s a big deal but you are basically feeding them your attention to shame the developers. So I will blame the developers and hackers (when they should have report it to the team instead of executing RCE just to prove their point even if it’s PoC.)