{"id":5676,"date":"2025-07-27T10:05:15","date_gmt":"2025-07-27T10:05:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/27\/hackers-compromised-official-gaming-mouse-software-to-deliver-windows-based-xred-malware\/"},"modified":"2025-07-27T10:05:15","modified_gmt":"2025-07-27T10:05:15","slug":"hackers-compromised-official-gaming-mouse-software-to-deliver-windows-based-xred-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/27\/hackers-compromised-official-gaming-mouse-software-to-deliver-windows-based-xred-malware\/","title":{"rendered":"Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware"},"content":{"rendered":"<p>    Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company\u2019s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks.<\/p>\n<p>The security breach, which occurred between June 26 and July 9, 2025, represents a troubling example of supply chain attacks targeting the gaming industry. The malware-infected software was distributed directly from Endgame Gear\u2019s official product page, making it particularly difficult for users to detect the threat.<\/p>\n<p>The incident came to light when Reddit users in the MouseReview community <a href=\"https:\/\/www.reddit.com\/r\/EndGameGear\/comments\/1m29q06\/security_alert_endgame_gears_op1w_4k_v2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> suspicious behavior after downloading the legitimate-looking configuration tool. User Admirable-Raccoon597, who first identified the compromise, noted that the infected file came \u201cfrom the official vendor page\u201d rather than any third-party source.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Gaming Mouse Software Compromise<\/strong><\/h2>\n<p>The malware payload was identified as <a href=\"https:\/\/cybersecuritynews.com\/sidewinder-apt-hackers-exploiting-old-office-flaws\/\" target=\"_blank\" rel=\"noreferrer noopener\">Xred<\/a>, a sophisticated Windows-based backdoor that has been circulating since at least 2019. This remote access trojan possesses extensive capabilities designed to compromise victim systems comprehensively.<\/p>\n<p>Xred collects sensitive system information, including MAC addresses, usernames, and computer names, transmitting this data to attackers via SMTP email addresses hardcoded into the malware.<\/p>\n<p>The malware\u2019s persistence mechanisms are particularly concerning. Once executed, Xred creates a hidden directory at C:ProgramDataSynaptics and establishes a <a href=\"https:\/\/cybersecuritynews.com\/windows-registry-manipulated\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Registry<\/a> Run key to maintain a permanent presence on infected systems. It masquerades as legitimate Synaptics trackpad driver software, making detection more challenging for users.<\/p>\n<p>Beyond basic data theft, Xred includes keylogging functionality through keyboard hooking techniques, potentially capturing banking credentials and other sensitive information.<\/p>\n<p>The malware also demonstrates worm-like behavior, spreading through USB drives by creating an <em>autorun.inf<\/em> files and infecting Excel files with malicious VBA macros.<\/p>\n<p>Endgame Gear replaced the infected files with clean versions on July 17 without issuing public warnings or acknowledging the breach.<\/p>\n<p>The company <a href=\"https:\/\/www.endgamegear.com\/security-update\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> an official security statement confirming the incident. The company stated that \u201caccess to our file servers was not compromised, and no customer data was accessible or affected on our servers at any time\u201d.<\/p>\n<p>The manufacturer has since implemented several security enhancements, including additional malware scanning procedures, reinforced anti-malware protections on hosting servers, and plans to add digital signatures to all software files.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gaming-mouse-software-compromised\/\">Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gaming-mouse-software-compromised\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company\u2019s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,1383,129,63],"tags":[130],"class_list":["post-5676","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-attack-today","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5676"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5676"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5676\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}