The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Computer Games
Breach intelligence, attack campaigns, and threat reports targeting the Computer Games sector.
Explore Other Sectors
Computer Games Threat Reports
2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
During the 2025 Black Friday sales period, a massive wave of phishing, financial malware, and scam campaigns targeted global consumers across e-commerce, online banking, payment systems, and gaming platforms. Threat actors leveraged sophisticated phishing pages mimicking major retailers like Amazon, Alibaba, and Walmart, and deployed banking Trojans such as Maverick and Efimer via email and messaging apps. Over 6.4 million e-commerce phishing attempts and 1.09 million banking Trojan attacks were detected, with cybercriminals intensively exploiting shopping and gaming hype to harvest credentials, payment data, and digital assets. This incident highlights an ongoing shift as cyber attackers increasingly time their campaigns around large global retail events, exploiting predictable user behavior and surges in online activity. Threats have diversified across platforms, with a notable rise in attacks on gaming services and dramatic increases in malicious activity leveraging Discord and Steam, signaling a pressing need for adaptive, multi-layered cyber defenses.
8 months ago
Kill Chain
Russian Threat Actors Weaponize Blender Files to Deliver StealC Malware in 2024
In early 2024, a sophisticated cyber campaign was identified where Russian-linked threat actors distributed the StealC V2 infostealing malware using malicious Blender 3D model files uploaded to popular 3D asset marketplaces such as CGTrader. Unsuspecting users who downloaded and opened these Blender files inadvertently executed trojanized Python scripts embedded within, enabling attackers to exfiltrate sensitive information including credentials, browser data, and cryptocurrency wallets. The campaign leveraged trusted platforms to evade detection and maximize potential victims among creative professionals and digital artists worldwide. This incident highlights the growing trend of weaponizing legitimate digital content and developer platforms to deliver sophisticated malware and infostealers. As attackers exploit emerging marketplaces and supply chains, businesses and individuals face increased risk of credential theft and data compromise, driving renewed urgency for Zero Trust security approaches and robust supply chain vetting.
8 months ago
Kill Chain
Tsundere Botnet: How Blockchain-Powered Node.js Malware Threatened Global Supply Chains in 2025
In mid-2025, the Tsundere botnet, attributed to a Russian-speaking threat actor known as "koneko," emerged as a new and flexible malware campaign. It primarily targeted Windows users by disguising itself as installers for popular games or using Remote Monitoring and Management (RMM) tools to deliver its payload. The malware leveraged MSI and PowerShell-based installers to deploy malicious Node.js scripts, establishing persistence and communicating with its command-and-control (C2) infrastructure by dynamically retrieving C2 addresses from Ethereum blockchain smart contracts. This adaptive technique, along with a marketplace-enabled control panel, facilitated operational resilience and monetization among cybercriminals. This incident is significant due to the combination of modern supply chain manipulation, blockchain-based C2 address obfuscation, and pay-per-build business models. Tsundere highlights a trend toward malware leveraging decentralized platforms for better survivability against take-downs and rapid evolution, posing ongoing challenges for traditional defenses and compliance frameworks.
8 months ago
Kill Chain
Tsundere Botnet: How Blockchain-Powered C2 Supercharged Windows-Based Attacks in 2025
In mid-2025, researchers identified a rapidly expanding botnet dubbed "Tsundere" specifically targeting Windows users. This malware, active since at least June 2025, leverages game-themed lures to infect systems, enabling attackers to execute arbitrary JavaScript code via a sophisticated command-and-control (C2) infrastructure built on the Ethereum blockchain for resilient communications. Tsundere’s propagation tactics remain opaque, but evidence indicates an advanced, multi-functional platform designed to maintain persistence, evade detection, and potentially facilitate lateral movement within victim networks. The business impact includes increased exposure to data theft, possible ransomware deployment, and widespread compromise of user endpoints. The Tsundere botnet exemplifies the rising trend of attackers exploiting blockchain technology for C2 communications, making conventional takedown efforts far more difficult. This incident underscores the urgency for organizations to enhance east-west threat visibility, strengthen endpoint defenses, and adopt zero-trust policies as botnets grow more evasive and robust.
8 months ago
Kill Chain
RedTiger Infostealer Attack Hits Discord Users in 2024
In early June 2024, cybersecurity researchers uncovered a new campaign in which attackers used a RedTiger-based infostealer to target Discord users. The campaign leveraged the open-source red-team tool RedTiger to build a custom infostealer designed to harvest Discord account credentials and stored payment information by injecting malicious code into Discord’s directories. Victims typically became infected through malicious downloads or phishing websites, unknowingly handing over sensitive data, including authentication tokens and payment details, to the attackers. As a result, stolen Discord accounts were sold or used for further fraud and account takeovers, risking both personal and organizational information leakage. This incident highlights an escalating trend of using open-source red-team tools for malicious infostealer campaigns, boosting attackers’ agility and reach. It underscores the risk of credential-based attacks on popular platforms, the need for real-time threat detection, and reinforces the importance of continuous endpoint monitoring and stronger egress security controls.
8 months ago
Kill Chain
Stealit Malware Abuses Node.js SEA in 2025 Infostealer Supply Chain Campaign
In October 2025, cybersecurity experts uncovered an active malware campaign involving Stealit, an advanced infostealer that exploits Node.js' Single Executable Application (SEA) feature to deliver its malicious payloads. The campaign also utilized the Electron framework and disguised its distribution through popular but trojanized game and VPN installers. Once executed, Stealit exfiltrated sensitive data from victims—such as credentials, browser information, and cryptocurrency wallets—using stealthy techniques while evading detection. The attack led to significant risks of account compromise and potential financial loss, particularly for organizations relying on affected software supply chains. This incident highlights a broader trend of attackers weaponizing modern development frameworks (like Node.js and Electron) to bypass traditional endpoint defenses. The use of legitimate-looking installers and supply chain manipulation signal an evolution in infostealer delivery tactics, making vigilance and advanced network segmentation crucial for organizational resilience.
8 months ago
Kill Chain
Zendesk's 2025 Email Bomb: How Lax Authentication Led to Mass Inbox Floods
In October 2025, a campaign exploited insecure ticket creation configurations across hundreds of Zendesk customer accounts, allowing attackers to bombard target inboxes with thousands of emails by abusing anonymous support workflows. Attackers submitted forged support requests via vulnerable Zendesk setups that lacked mandatory user authentication; as a result, victim inboxes were flooded with email notifications that appeared to originate from major brands like NordVPN, The Washington Post, and Discord. This distributed email flood (email bomb) compromised brand integrity, overloaded recipient systems, and created significant disruption for both targeted individuals and the affected organizations, highlighting the dangers of misconfigured application authentication and notification systems. Incidents like this reflect a rising trend in application-layer abuse, where attackers exploit lenient platform defaults and automated workflow triggers to amplify malicious campaigns. As business reliance on cloud-based customer service solutions increases, proper authentication and anti-abuse controls have become critical to both user and organizational protection.
8 months ago
Kill Chain
Aisuru Botnet’s Record DDoS Assaults Expose IoT Weaknesses in US ISPs
In October 2025, the Aisuru botnet orchestrated the largest recorded distributed denial-of-service (DDoS) attacks to date, leveraging over 300,000 compromised IoT devices primarily hosted on major U.S. ISPs such as AT&T, Comcast, and Verizon. The botnet, evolved from Mirai code, exploited insecure or outdated IoT firmware, driving attack volumes to nearly 30 terabits per second. Recurrent DDoS waves severely disrupted online gaming infrastructure and collateral users, overwhelming both DDoS mitigation providers and ISPs, and causing service dropouts and customer impact across multiple networks. This incident exemplifies the rising scale and sophistication of IoT-based botnets and exposes urgent deficiencies in outbound DDoS filtering at the ISP level. The Aisuru event also highlights a growing threat trend: attackers using compromised consumer IoT to reinforce both DDoS infrastructure and residential proxy networks, broadening attacker capabilities and the attack surface for businesses and critical providers.
8 months ago
Kill Chain
How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach
In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release. This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.
8 months ago
Kill Chain
Unity Game Engine Vulnerability 2025: Millions Exposed to Supply Chain Attacks
In October 2025, a significant supply chain vulnerability (CVE-2025-59489) was discovered in the Unity game engine, impacting applications built since version 2017.1 and endangering millions of global end-users. The flaw, identified by security researcher RyotaK, enables attackers to achieve arbitrary code execution or information disclosure by exploiting unsafe file loading mechanisms in the Unity Runtime component. Affected games include widely popular titles like Hearthstone, Fallout Shelter, and Doom (2019). Valve and Microsoft responded quickly, recommending users uninstall vulnerable games and developers patch or rebuild applications, while Unity issued updates and fixes for supported engine versions. This incident underscores the growing risks of supply chain vulnerabilities in modern software ecosystems, particularly as game engines and third-party frameworks become foundational across industries. The rapid coordinated response highlights heightened industry attention to upstream code security, as adversaries increasingly target widely deployed runtime components for maximum impact.
8 months ago
Kill Chain
Discord 2024 Breach: Third-Party Support Attack Exposes User Data
In early March 2024, Discord disclosed a data breach after threat actors compromised a third-party customer service provider’s systems. Attackers gained access to customer support tickets, exposing partial payment information, names, email addresses, and government-issued IDs of Discord users who had interacted with support. The breach occurred through unauthorized access to the provider’s internal systems, allowing exfiltration of sensitive, personally identifiable information linked to support requests. Discord promptly investigated, notified affected users, and terminated the third party’s access to its systems. This incident highlights the increasing risks associated with third-party vendors handling sensitive data, especially as social engineering and supply chain attacks become more common. Growing scrutiny from regulators and customers underscores the need for robust supply chain security and continuous monitoring of vendor access.
8 months ago
Kill Chain
Microsoft Warns: XCSSET macOS Malware Evolves to Target Xcode Devs in 2025
In September 2025, Microsoft Threat Intelligence identified a new, advanced variant of the XCSSET macOS malware targeting Xcode developers. This infostealer propagates by infecting Xcode projects—widely shared among software engineers—allowing it to execute malicious code each time a compromised project is built. The updated malware features enhanced browser data theft (including Firefox), clipboard hijacking to steal cryptocurrency via address swapping, and improved persistence mechanisms. Though observed only in limited, targeted attacks so far, XCSSET poses a significant risk to both assets and sensitive developer tooling. This incident is especially relevant today as targeting the software supply chain and developer toolchains is becoming a favored method for threat actors seeking high-privilege access. The sophistication of XCSSET’s mechanisms mirrors broader trends in stealthy, data-focused attacks against development environments, pressing organizations to reassess internal controls and software sharing practices.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports