✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Games
Breach intelligence, attack campaigns, and threat reports targeting the Computer Games sector.
Explore Other Sectors
Computer Games Threat Reports
Zendesk Ticket Systems Hijacked: 2026 Relay Spam Disrupts Global Brands
In January 2026, a massive global spam campaign exploited unsecured Zendesk support systems, enabling attackers to send hundreds of unsolicited emails to targets worldwide. By abusing the open ticket submission feature—allowing ticket creation from any email address without verification—attackers automated fake support requests to generate an overwhelming volume of confirmation emails. Major organizations including Discord, Tinder, Riot Games, Dropbox, and government agencies were impacted, with recipients receiving alarming and confusing messages that appeared to originate from legitimate support channels. No malicious payloads were identified, but the incident caused significant alarm, confusion, and business interruption for affected parties. The heightened ability for attackers to manipulate trusted service communications underscores a growing threat of platform abuse, where legitimate systems are turned against users to bypass security controls and sow disruption. With organizations increasingly reliant on third-party SaaS for customer engagement, this incident illustrates how gaps in self-service security can have wide-reaching and highly visible effects.
6 months ago
Kill Chain
Evelyn Stealer Exposes Developer Credential Risks in VS Code Supply Chain
In January 2026, researchers uncovered a malware campaign exploiting the Microsoft VS Code extension ecosystem to deliver Evelyn Stealer, an infostealer targeting software developers. Threat actors distributed malicious extensions which downloaded and executed a secondary payload, ultimately injecting the stealer into a legitimate process. Once executed, the malware harvested sensitive information—including developer credentials, stored cookies, crypto wallets, and system data—then exfiltrated these assets via FTP to a remote server. Attackers also deployed anti-analysis and evasion techniques, enabling seamless and covert data theft that potentially compromised broader organizational systems by abusing developer environments as entry points. This attack underscores the growing risks to the software supply chain, as developer tools become lucrative vectors for credential and asset theft. The Evelyn Stealer incident reflects an expanding trend where infostealers leverage trusted development ecosystems, highlighting the urgent need for stronger security controls and supply chain hygiene in rapidly evolving threat landscapes.
6 months ago
Kill Chain
Kimwolf Botnet’s 2025 DDoS Blitz: 2M Devices, Unprecedented Risk
In October 2025, the Kimwolf botnet—an offshoot of the notorious Aisuru DDoS network—rapidly infected over 2 million unofficial Android TV devices by exploiting weaknesses in residential proxy networks. The operators, believed to be financially motivated cybercriminals, orchestrated large-scale distributed denial-of-service (DDoS) attacks affecting gaming communities, notably targeting Minecraft servers, and leveraged fast-evolving infrastructure to evade detection. Industry players, including Lumen’s Black Lotus Labs, responded by null-routing botnet-linked IP addresses and blocking command-and-control infrastructure, significantly diminishing Kimwolf’s operational bandwidth and disrupting its growth trajectory. Kimwolf’s meteoric rise highlights the growing threat posed by botnets that co-opt consumer devices and abuse proxy services for stealth and scale. The incident demonstrates the urgent need for robust internal network controls, real-time anomaly response, and resilient segmentation, as attackers escalate their tactics and DDoS attacks hit record-breaking volumes.
6 months ago
Kill Chain
Apex Legends Live Character Hijack: 2026 Gaming Platform Breach Explained
In January 2026, Apex Legends players experienced a major security incident where an external threat actor gained unauthorized control over live player characters during matches. The attacker remotely hijacked user avatars, disconnected players from servers, and manipulated in-game identities, temporarily disrupting the gaming experience for tens of thousands. Respawn Entertainment, the game's publisher, confirmed the attack but stated there was no evidence of remote code execution or malware. Investigation pointed to exploitation of privileged backend debugging or admin interfaces, rather than a software vulnerability affecting all client machines. This incident underscores escalating threats targeting large-scale gaming platforms, where privilege escalation and endpoint attacks now rival phishing or malware techniques in their sophistication. With gaming ecosystems becoming lucrative and complex, attackers continue to innovate, highlighting the urgent need for improved internal traffic security and continuous monitoring.
6 months ago
Kill Chain
VVS Stealer: Obfuscated Python Malware Compromises Discord Accounts in 2025
In April 2025, researchers discovered a new information stealer, VVS Stealer, distributed via obfuscated Python code targeting Discord users. The malware, sold on Telegram, leverages Pyarmor obfuscation techniques to evade detection and focuses on harvesting Discord credentials and authentication tokens. Attackers propagated the malware through malicious campaigns that trick users into executing compromised scripts, resulting in unauthorized access to their Discord accounts. The impact was the loss of sensitive credentials, potential identity theft, and exposure of personal communications, with widespread risk for Discord communities and possibly further compromise of cloud-connected services. This incident exemplifies the growing sophistication in malware targeting online communities, particularly through social engineering and advanced obfuscation. There is a notable trend of threat actors exploiting popular platforms and leveraging encryption or evasion techniques to bypass standard security controls — elevating the urgency for endpoint protection, behavioral monitoring, and defense-in-depth controls.
6 months ago
Kill Chain
VVS Stealer: Advanced Infostealer Targets Discord Users with Pyarmor Obfuscation
In April 2025, Palo Alto Networks researchers uncovered the VVS Discord Stealer, a Python-based infostealer distributed via Telegram and targeting Discord users. Leveraging Pyarmor for advanced code obfuscation and detection evasion, the malware bundled itself as a PyInstaller executable and used sophisticated techniques such as AES-128-CTR encryption and injection of persistent JavaScript payloads into Discord’s Electron framework. VVS Stealer exfiltrated Discord credentials, tokens, browser data, and session information to attacker-controlled webhooks, targeting both Discord-specific and multi-browser artifacts with stealth and persistence. The campaign highlights the rise of infostealers employing dual-use obfuscation to bypass modern security controls, extending dwell time and increasing the risk of credential-based account takeovers across personal and enterprise platforms. This incident exemplifies an ongoing surge in credential theft campaigns leveraging advanced obfuscation tools, notably as infostealers adapt to evade both static and endpoint detection solutions. The widespread abuse of dual-use security tools for malicious purposes is fueling regulatory scrutiny and underscores the urgent need for enhanced threat visibility, real-time anomaly detection, and credential hygiene in communication and collaboration platforms.
6 months ago
Kill Chain
Webrat Infostealer Campaign: How Fake GitHub Exploits Breached the Cybersecurity Supply Chain
In early 2025, security researchers identified a campaign distributing the Webrat infostealer through malicious GitHub repositories. The threat actors disguised their malware as proof-of-concept exploits for high-profile vulnerabilities, targeting not only gamers and users of cracked software, but also inexperienced cybersecurity professionals and students. Victims who downloaded these fake exploits unwittingly executed a dropper that installed Webrat, granting attackers administrator privileges, disabling security controls, and enabling data theft from wallets and communication platforms while providing backdoor access and surveillance. This incident underscores a growing attacker trend of abusing trust in open-source platforms and targeting cybersecurity researchers themselves. As the use of AI-generated content and supply chain attacks increase, professionals must exercise greater scrutiny when handling code from unverified sources, amplifying the need for security awareness and robust isolation practices.
6 months ago
Kill Chain
Critical 2025 UEFI Flaw Enables Pre-Boot DMA Attacks on Leading Motherboards
In December 2025, researchers from Riot Games identified a critical UEFI firmware vulnerability impacting motherboards from ASUS, Gigabyte, MSI, and ASRock. The flaw, tracked as CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304, allows Direct Memory Access (DMA) attacks during the pre-boot phase by bypassing IOMMU protections. Threat actors with physical access can attach malicious PCIe devices to read or alter system memory before the operating system loads, making traditional endpoint protections ineffective. The vulnerability was confirmed by multiple security advisories and coordinated with hardware vendors for urgent firmware updates. This incident highlights the increasing sophistication of firmware-level attacks that can evade operating system and security tool visibility. As hardware supply chains diversify and attackers target pre-boot processes, organizations face heightened risks in both enterprise and consumer hardware ecosystems.
6 months ago
Kill Chain
Hackers Weaponize Blender 3D Assets to Spread StealC V2 Malware
In late 2025, cybersecurity researchers identified a prolonged campaign in which attackers weaponized Blender 3D asset files (.blend) on popular asset-sharing platforms such as CGTrader. By implanting malicious files that executed the StealC V2 information-stealing malware, threat actors compromised unsuspecting users when they opened downloaded assets. Over at least six months, the campaign enabled attackers to harvest login credentials, browser data, and sensitive information from artists and professionals in gaming, animation, and design industries, leading to significant data theft and potential downstream attacks on organizations relying on Blender assets. This incident highlights the growing abuse of trusted creative software supply chains and open asset marketplaces. As creative and industrial processes increasingly depend on third-party digital assets, attackers are evolving to target creators, leveraging social engineering and supply chain weaknesses.
6 months ago
Kill Chain
2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
During the 2025 Black Friday sales period, a massive wave of phishing, financial malware, and scam campaigns targeted global consumers across e-commerce, online banking, payment systems, and gaming platforms. Threat actors leveraged sophisticated phishing pages mimicking major retailers like Amazon, Alibaba, and Walmart, and deployed banking Trojans such as Maverick and Efimer via email and messaging apps. Over 6.4 million e-commerce phishing attempts and 1.09 million banking Trojan attacks were detected, with cybercriminals intensively exploiting shopping and gaming hype to harvest credentials, payment data, and digital assets. This incident highlights an ongoing shift as cyber attackers increasingly time their campaigns around large global retail events, exploiting predictable user behavior and surges in online activity. Threats have diversified across platforms, with a notable rise in attacks on gaming services and dramatic increases in malicious activity leveraging Discord and Steam, signaling a pressing need for adaptive, multi-layered cyber defenses.
6 months ago
Kill Chain
Russian Threat Actors Weaponize Blender Files to Deliver StealC Malware in 2024
In early 2024, a sophisticated cyber campaign was identified where Russian-linked threat actors distributed the StealC V2 infostealing malware using malicious Blender 3D model files uploaded to popular 3D asset marketplaces such as CGTrader. Unsuspecting users who downloaded and opened these Blender files inadvertently executed trojanized Python scripts embedded within, enabling attackers to exfiltrate sensitive information including credentials, browser data, and cryptocurrency wallets. The campaign leveraged trusted platforms to evade detection and maximize potential victims among creative professionals and digital artists worldwide. This incident highlights the growing trend of weaponizing legitimate digital content and developer platforms to deliver sophisticated malware and infostealers. As attackers exploit emerging marketplaces and supply chains, businesses and individuals face increased risk of credential theft and data compromise, driving renewed urgency for Zero Trust security approaches and robust supply chain vetting.
6 months ago
Kill Chain
Tsundere Botnet: How Blockchain-Powered Node.js Malware Threatened Global Supply Chains in 2025
In mid-2025, the Tsundere botnet, attributed to a Russian-speaking threat actor known as "koneko," emerged as a new and flexible malware campaign. It primarily targeted Windows users by disguising itself as installers for popular games or using Remote Monitoring and Management (RMM) tools to deliver its payload. The malware leveraged MSI and PowerShell-based installers to deploy malicious Node.js scripts, establishing persistence and communicating with its command-and-control (C2) infrastructure by dynamically retrieving C2 addresses from Ethereum blockchain smart contracts. This adaptive technique, along with a marketplace-enabled control panel, facilitated operational resilience and monetization among cybercriminals. This incident is significant due to the combination of modern supply chain manipulation, blockchain-based C2 address obfuscation, and pay-per-build business models. Tsundere highlights a trend toward malware leveraging decentralized platforms for better survivability against take-downs and rapid evolution, posing ongoing challenges for traditional defenses and compliance frameworks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports