In an unexpected security incident on Christmas Day, the popular mod called Downfall for the game Slay The Spire became the unwitting conduit for cyber attackers to spread malware through the Steam gaming platform. The main purpose of this malicious software was to hijack personal data by stealing passwords from users.
The developers of the Downfall mod reported that their creation suffered a critical "security breach" when hackers found a way to distribute the malware. This malware was specifically engineered to target and extract password information from various common internet browsers, as well as from popular messaging platforms such as Telegram and Discord.
During the time of the attack, individuals who launched the Downfall mod were confronted with a deceptive "Unity library installer popup." This was part of the hacker's scheme to infiltrate the user's system. The infiltration was promptly identified and remedied by the Downfall team by 1:40pm ET (6:40pm GMT) on Christmas Day, following the release of the announcement.
Despite the quick response, the Downfall developers alerted the community that most antivirus programs failed to block the execution of the malware. However, they were effective in preventing the stolen data payload from transmitting over the internet. Consequently, users whose systems executed the malware weren't necessarily impacted if the payload was halted successfully.
The insidious payload in question was designed to scrape passwords stored in several applications. It targeted Windows local login credentials, browsers such as Google Chrome, Yandex, Microsoft Edge, Mozilla Firefox, Brave, and Vivaldi, and also messaging apps including Telegram and Discord. It also searched for any files containing the word 'password' in hopes of extracting more sensitive data.
Users affected by the compromise began noticing suspicious files cropping up in varying locations across their computer hard drives. The developers included details in their announcement concerning these files, prompting the community to be vigilant. They advised users to cautiously probe into these suspicious files only with their internet connection disabled to avoid further risk.
For those who experienced the dubious Unity popup, the developers issued strong recommendations to promptly change all vital passwords, emphasizing the importance of securing accounts that lack 2-factor authentication (2FA). This extra layer of security is crucial for protecting against such breaches.
Downfall is recognized as a significant modification to Slay The Spire, appreciated widely for introducing new characters, a new mode, and other content. This malware incident has not only cast a shadow upon the mod's reputation but also raised concerns over the safety of mod distribution platforms. Since the incident, the developers behind Downfall shifted their focus to developing Tales & Tactics, which is a standalone auto-battling Chess roguelike game.
In response to this incident, the gaming community is urged to stay alert for any unusual activity and to maintain strong cybersecurity practices when downloading and using mods. It's a reminder of the potential dangers that come with modding games and the importance of sourcing mods from reputable creators and sites. The game's developers are undoubtedly taking steps to both rectify the damage done and to prevent such breaches from occurring in the future.
Gamers affected by the malware should take immediate action to secure their personal information and continue to observe the recommended preventative measures. Regularly updating anti-virus and anti-malware software, using complex and unique passwords, and enabling two-factor authentication wherever possible can be key lines of defense against similar cyber-attacks.
