Undetected Infostealer in Steam Game ...AGAIN

preview_player
Показать описание
Steam Games can have hidden undetected infostealers, beware of new store listings, especially if you receive a message from a friend asking you to download it.

Рекомендации по теме
Комментарии
Автор

Just wanted to say this, this game was not originally on Steam. They used Steam as a way of advertising, to get the demo of the game you had to visit the developers website. So in a way Steam was used as a tool, you could not get it directly from Steam.

lioneagle
Автор

golden rule : if a friend sends me a gift code/game/whatever through any chat I'm always suspicious

kip
Автор

I think its a bit unfair to leave blank, that the malware WAS NOT the game on steam, it was on their own website, a fake demo. That is a BIG difference.

monkaSisLife
Автор

The legitimate game "Sand" recently had something like this happen. Compromised accounts were sending fake beta invites that redirected to Steam in a browser asking you to sign in.

xemphios
Автор

Antivirus providers could check a file for empty bloat and warn you about it. That is not full analysis, but a starting point.

Blackdeath
Автор

I wish AVs at least gave you the option to scan very large files.

cpuuk
Автор

The fact most AV will ignore large files is annoying.
I'm not sure if the following setting affects it but Bitdefender has a " Ignore archives grater than X MB " setting and can be set to 9999 MB

saadhero
Автор

Wasn't hosted on the steam servers, so no risk of infection from a steam game, you had to leave steam to download the demo. Nice bit of info you avoided there to try flog an anti-virus that no one needs.

Calesti
Автор

Why do so many people blame steam for this one? At 1:35, the discord message clearly says that the scammer linked a steam webpage and claim its safe. Then they sent a link that make you download the infostealer from github. Not through steam client. How can valve do anything about this if no one report it?
PC Security Channel also not doing a great job to explain the situation and use a clickbait title to make people mad at valve.

lamyipan
Автор

If everyone knows that making a file very large is often used to hide malware, why haven't the AV companies just bit the bullet and have their software scan everything?

DamonWakefield
Автор

Another way these hackers hack you in Steam is they sell cheap game keys or give it away for free but these games actually have malwares in them.

I have a very strong Steam password with 2FA also enabled but the hacker was still able to get my password and tried to login to my Steam account. I keep getting alerts of new logins to my Steam account. Good thing I set up 2FA to my Steam account so they didn't get far.

At first I didn't know how they did it. I always used the official Steam site for games and don't pirate games or use warez. But even after changing my password a few times, I was still getting login attempts. After uninstalling the compromised game, it stopped.

This was the first time it happened to me. Someone on my friend's list was giving away free games and I tried one. Big mistake on my part. Be careful y'all.

xellaz
Автор

I hope steam gets a handle on these and revises their approval process for publishing new games to its store.

fyrestorme
Автор

First was Abstractism (Cryptomining Trojan), Second was PirateFi (Info-Stealer) and Now, Sniper Phantom Resolution (Info-Stealer)

jakeferrison
Автор

Thanks so much Leo, I really appreciate your diligence.

highcue
Автор

you would have thought valve would have started trying harder to prevent this stuff, but I guess its harder when the malware is ud and unpacked

stratxgydev
Автор

Chrome devs worked so hard on protecting data only for a malware to come in and just relaunch the browser with options to bypass it.

nanopi
Автор

Kaspersky and Bitdefender need to step up their game with stuff like this. I have to be honest, I hate AVAST and AVG cause of the way the apps function and the ads, but something like this tells me they are more proactive with 0 day threats and may be worth another look.

teddym
Автор

4:30 get to know your friends better! I mean we all have ways of speaking/typing that’s pretty unique to each of us, so if you get a message from a friend that dosnt really feel right double check (heck it probably pays to double check anyway just in case your friends are playing a prank on you).

permeusnd
Автор

Now I wanna see if top AVs can detect info stealers when you try to run them if the initial scan doesn’t detect anything

Pirateking
Автор

Game: Windows Defender Smartscreen
Leo: Pretending to be the anitivirus [componant]
Me: Hol up.

Marioa
visit shbcf.ru