Wow it finally happened. So glad I switched to steam running on linux mint last week. I refused to install helldivers because it wanted to install some no holds barred god level permissions anti-cheat software. Windows 11 was the last straw for me. Good times…

The volunteers at the Anti-Cheat Police Department have since issued a PSA announcing, “There is currently an RCE exploit being abused in [Apex Legends]” and that it could be delivered via from the game itself, or its anti-cheat protection. “I would advise against playing any games protected by EAC or any EA titles”, they went on to say.

As for players of the tournament, they strongly recommended taking protective measures. “It is advisable that you change your Discord passwords and ensure that your emails are secure. also enable MFA for all your accounts if you have not done it yet”, they said, “perform a clean OS reinstall as soon as possible. Do not take any chances with your personal information, your PC may have been exposed to a rootkit or other malicious software that could cause further damage.”

  • noevidenz@infosec.pub
    link
    fedilink
    English
    arrow-up
    62
    ·
    9 months ago

    There is currently no evidence of an RCE exploit in EAC, and EAC themselves as well as their owner, Epic, have both denied the existence of an RCE in their software.

    There’s a video from about a month ago in which ImperialHal and Genburten (on separate occasions) are in a match against the person named in the messages sent by the exploit on Genburten’s machine.

    It’s possible that they were in contact with the hacker after that point and that he tricked them into downloading something they shouldn’t have.

    Otherwise, it’s also possible that there is an exploit in Apex/Source that the hacker used. He may have been able to get their IP during the public match a month ago and then use it to target them during the competition.

    Beyond what was seen during the competition, the hacker was also able to gift thousands of Apex packs to several players (seemingly without paying for them) and was able to get 40+ “bot” players into a single match and to all target an individual player. He also claimed to be able to open crates on another player’s account. These other exploits seem to indicate that he has elevated access to both the server and to multiple APIs, but none of them indicate elevated access to user machines in general.

    • merthyr1831@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      edit-2
      9 months ago

      Cancel my comment about this being a possible 0day or whatever. They were playing this tournament on their personal systems, which makes it way easier for someone to accidentally download malicious software without players’ consent.

        • BURN@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          ·
          9 months ago

          Because it’s super annoying, clogs comment feeds and is unnecessary to be a giant wall of text comment for something ~50% of people don’t care about.

          And yes, I use the default YouTube app because it works.

            • Droechai@lemm.ee
              link
              fedilink
              English
              arrow-up
              4
              ·
              9 months ago

              I do love the abbreviation bots though, they should be automatically summoned the first time a new abbreviation is used in a comment tree

              • conciselyverbose@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                4
                ·
                9 months ago

                That one is actually nice.

                I think it should be required to get manually added to a community by moderators still though. Or respond to a summon to a specific thread.