{"id":7126,"date":"2025-09-23T10:03:42","date_gmt":"2025-09-23T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/23\/blockblasters-steam-game-downloads-malware-to-computer-disguised-as-patch\/"},"modified":"2025-09-23T10:03:42","modified_gmt":"2025-09-23T10:03:42","slug":"blockblasters-steam-game-downloads-malware-to-computer-disguised-as-patch","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/23\/blockblasters-steam-game-downloads-malware-to-computer-disguised-as-patch\/","title":{"rendered":"BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch"},"content":{"rendered":"<p>    BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing hundreds of Steam users to data theft and system compromise.<\/p>\n<p>The malicious patch, deployed on August 30, 2025, demonstrates how threat actors are increasingly exploiting the gaming ecosystem to distribute information-stealing malware while users remain unaware of the ongoing compromise.<\/p>\n<p>BlockBlasters, developed by Genesis Interactive and initially released on July 31, 2025, had garnered positive reviews from the gaming community before becoming the latest victim in a growing trend of Steam game infections.<\/p>\n<p>The malicious Build 19799326 patch contains multiple files that exhibit dangerous behaviors, transforming what appeared to be a routine game update into a multistage attack capable of exfiltrating sensitive user data including cryptocurrency wallet information, browser credentials, and Steam login details.<\/p>\n<p>G Data analysts <a href=\"https:\/\/www.gdatasoftware.com\/blog\/2025\/09\/38265-steam-blockblasters-game-downloads-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware campaign after their MXDR platform flagged the suspicious activities within the game\u2019s patch files.<\/p>\n<p>The security researchers discovered that the threat actors had successfully bypassed Steam\u2019s initial security screening, allowing the deployment of malicious updates that could potentially affect hundreds of players who had the game installed on their systems.<\/p>\n<p>This incident follows a concerning pattern of similar attacks on Steam games, including the notable PirateFi and Chemia cases, highlighting the platform\u2019s ongoing vulnerability to such sophisticated infiltration attempts.<\/p>\n<p>The attack represents a significant escalation in gaming-focused malware <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a>, as threat actors continue to refine their techniques for distributing malicious payloads through legitimate software distribution channels.<\/p>\n<p>The incident particularly stands out due to its multistage infection process and the range of sensitive data it targets, making it a comprehensive information theft operation rather than a simple malware installation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-infection-mechanism-and-payload-delivery\"><strong>Technical Infection Mechanism and Payload Delivery<\/strong><\/h2>\n<p>The BlockBlasters <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> operates through a sophisticated three-stage infection mechanism that begins with the execution of a seemingly benign batch file named <code>game2.bat<\/code>.<\/p>\n<p>This initial payload performs several reconnaissance functions, including collecting IP and location information through queries to legitimate services like \u201cipinfo[.]io\u201d and \u201cip[.]me\u201d, while simultaneously detecting installed antivirus products to assess the target environment\u2019s security posture.<\/p>\n<p>The batch file\u2019s primary function involves collecting Steam login credentials, including SteamID, AccountName, PersonaName, and RememberPassword data, which it then uploads to the command and control server located at <code>hxxp:\/\/203[.]188[.]171[.]156:30815\/upload<\/code>.<\/p>\n<p>The malware employs password-protected ZIP archives with the password \u201c121\u201d to conceal its payloads during download, effectively evading initial detection mechanisms.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhk6D82qmqjTsDtJtTP1F1BLUrGivhSL4lYhTUei2Eg8jsV20A3a6d5nhHMsgeFKJl89-KiGkPd1PS-SgKilqVO8sSGeyV5rSGBeJFvUEArfm0NpQpd1MsTf5viZEI00A3q5XC464VAOxWBU5-xzxOqQ8PDNw5yNhxnQT5Lt8Z-ZOMlvPFI95r0c-46obk\/s16000\/SteamDB%2520Patch%2520Files%2520from%2520SteamDB%2520%28Source%2520-%2520G%2520Data%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">SteamDB Patch Files from SteamDB (Source \u2013 G Data)<\/figcaption><\/figure>\n<\/div>\n<p>Upon successful environment assessment, the malware deploys VBS loader scripts (<code>launch1.vbs<\/code> and <code>test.vbs<\/code>) that execute additional batch files while maintaining stealth through hidden console execution.<\/p>\n<p>The <code>test.bat<\/code> component specifically targets browser extensions and cryptocurrency wallet data, demonstrating the campaign\u2019s focus on high-value financial information.<\/p>\n<p>The final stage involves the deployment of two primary payloads: <code>Client-built2.exe<\/code>, a Python-compiled backdoor that establishes persistent communication with the C2 infrastructure, and <code>Block1.exe<\/code>, which contains the StealC information stealer.<\/p>\n<p>The malware strategically adds its execution directory to Microsoft Defender\u2019s exclusion list using the path <code>Drive:SteamLibrarysteamappscommonBlockBlastersEngineBinariesThirdPartyOggcwe<\/code>, ensuring continued operation without triggering <a href=\"https:\/\/cybersecuritynews.com\/fake-github-security-alerts-let-hackers-hijack\/\" target=\"_blank\" rel=\"noreferrer noopener\">security alerts<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj2iBUy2D5kZxS9P7ODoeLusseQ08yckPSuHv_sdoDlWvT15IvXjU9t4A_c63BQLs6DzVh1AhlPzRhllOJrzc-O2V8Yhlpo69GquF2Tmag4ZC4PVOCjEnxOexUrM7SEmINC10xOwmggRY1eScCfz5aUkOhTKCi24KbrcBC0qU_qRnbp8izYHSPXp60dIV0\/s16000\/Game2.bat%2520unpacking%2520files%2520inside%2520password-protected%2520archives%2520and%2520then%2520executing%2520it%2520%28Source%2520-%2520G%2520Data%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Game2.bat unpacking files inside password-protected archives and then executing it (Source \u2013 G Data)<\/figcaption><\/figure>\n<\/div>\n<p>The StealC component targets multiple browsers including Google Chrome, Brave Browser, and Microsoft Edge, accessing their respective Local State files to extract stored credentials and sensitive information.<\/p>\n<p>The malware uses deprecated RC4 encryption to <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscate<\/a> its API calls and key strings, connecting to a secondary C2 server at <code>hxxp:\/\/45[.]83[.]28[.]99<\/code> for data exfiltration operations, demonstrating the campaign\u2019s distributed infrastructure approach to maintaining operational security.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/blockblasters-steam-game-downloads-malware\/\">BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/blockblasters-steam-game-downloads-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing hundreds of Steam users to data theft and system compromise. The malicious patch, deployed on August 30, 2025, demonstrates how threat actors are increasingly exploiting [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7126","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7126"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7126"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7126\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}