468
submitted 9 months ago* (last edited 9 months ago) by catch22@programming.dev to c/technology@lemmy.world

Wow it finally happened. So glad I switched to steam running on linux mint last week. I refused to install helldivers because it wanted to install some no holds barred god level permissions anti-cheat software. Windows 11 was the last straw for me. Good times..

The volunteers at the Anti-Cheat Police Department have since issued a PSA announcing, "There is currently an RCE exploit being abused in [Apex Legends]" and that it could be delivered via from the game itself, or its anti-cheat protection. "I would advise against playing any games protected by EAC or any EA titles", they went on to say.

As for players of the tournament, they strongly recommended taking protective measures. "It is advisable that you change your Discord passwords and ensure that your emails are secure. also enable MFA for all your accounts if you have not done it yet", they said, "perform a clean OS reinstall as soon as possible. Do not take any chances with your personal information, your PC may have been exposed to a rootkit or other malicious software that could cause further damage."

you are viewing a single comment's thread
view the rest of the comments
[-] ramielrowe@lemmy.world 19 points 9 months ago

I do not buy this RCE in Apex/EAC rumor. This wouldn't be the first time "pro" gamers got caught with cheats. And, I wouldn't put it past the cheat developers to not only include trojan-like remote-control into their cheats, but use it to advertise their product during a streamed tournament. All press is good press. And honestly, they'd probably want people thinking it was a vulnerability in Apex/EAC rather than a trojan included with their cheat.

[-] KairuByte@lemmy.dbzer0.com 16 points 9 months ago

Mmmm I’ve not done any digging, but the likelihood of a large number of streamers all using cheating software and a large number of them literally announcing it and leaving the game is quite slim.

Think of it this way, assuming they were cheating, the streamers would not want to get caught right? So they would be using cheats that aren’t being broadcast over their streaming software. To then announce “oh no I’m cheating” and quit would be silly, what would be the point of this even joining the tournament at that point? On the other hand, if the cheats were visible on their streams… that seems like a glaring issue a streamer wouldn’t make, never mind a large number of them.

[-] bjoern_tantau@swg-empire.de 11 points 9 months ago

I think their hypothesis is that the streamers had installed and used cheats outside of the tournament and that the cheat suppliers enabled them remotely to advertise on the big stream.

[-] KairuByte@lemmy.dbzer0.com 3 points 9 months ago

Doubtful. Unless the cheats popped up and said “buy cheats at [cheat website]” then it’s not even really advertising. They’d also be shooting themselves in the foot by showing their cheats are remotely controlled.

Don’t get me wrong, I absolutely believe it’s possible. But it’s much more likely that a “fuck you” hack was pulled, rather than the majority of streamers all cheating by coincidence.

[-] BURN@lemmy.world 5 points 9 months ago

These 2 pros have performed at lan multiple times and the type of cheats used would have been immediately noticed on any stream.

The hacker (destroyer2009) also gifted in excess of $8k worth of lootboxes to multiple streamers, suggesting that they have access to some remote APIs they shouldn’t.

On top of that a few months ago there was a widespread issue with top players being targeted in lobbies where they’d drop and then 57 bots would drop and zombie rush, all named the same thing and controlled by some kind of rudimentary script.

Pretty much everything together has ruled out the possibility of either of the players involved being the ones who are purposefully cheating.

[-] ramielrowe@lemmy.world 0 points 9 months ago* (last edited 9 months ago)

I'm not saying they were purposefully cheating in this or any tournament, and I agree cheating under that context would be totally obvious. But, it is feasible that a pro worried about their stats might be willing to cheat in situations where the stakes are lower outside of tournaments.

What I also don't understand is, if this hacker has lobby wide access, why was it only these two people who got compromised? Why wouldn't the hacker just do the entire lobby? Clearly this hacker loves the clout. Forcing cheats on the entire lobby would certainly be more impressive.

PS. This is all blatant speculation. From all sides. No one, other than the hacker and hopefully Apex really knows what happened. I am mostly frustrated by ACPD's immediate fear mongering of a RCE in EAC or Apex based on no concrete evidence.

[-] Tarquinn2049@lemmy.world 4 points 9 months ago* (last edited 9 months ago)

They probably didn't randomly guess what happened. There would be pretty obvious clues as to how it happened. The network traffic for tournaments like this is monitored. Because they have to be done online. If they had no idea what actually happened, they would have at least been suspicious of the players at first. No matter what messages were playing in chat at the time.

[-] ramielrowe@lemmy.world 22 points 9 months ago* (last edited 9 months ago)

This isn't a statement from Apex or EAC. The original source for the RCE claim is the "Anti-Cheat Police Department" which appears to just be a twitter community. There is absolutely no way Apex would turn over network traffic logs to a twitter community, who knows what kind of sensitive information could be in that. At best, ACPD is taking the players at their word that the cheats magically showed up on their computers.

PS. Apparently there have been multiple RCE vulnerabilities in the Source Engine over the years. So, I’m keeping my mind open.

[-] CaptainBasculin@lemmy.ml -1 points 9 months ago

There is an RCE exploit in EAC which has been confirmed by their twitter account; but they didn't confirm of it being exploited anywhere.

My belief is that the people responsible into it hacked these people months ago; as a few months ago the same hacker did attack ImperialHal while on stream with botted zombie accounts that follow him to kill him. On that stream's highlights all those bots were named (number)destroyer2009fan; which is the same as the person that spammed the chat at the time of the hack.

This is not an advertisement for cheats. Searching the hacker's name in cheat forums doesn't point to any specific program. I suspect that this is openly calling out Respawn to fix their anticheat, which has been a laughing stock.

[-] noodlejetski@lemm.ee 13 points 9 months ago

There is an RCE exploit in EAC which has been confirmed by their twitter account

really? because all I've seen was them saying the exact opposite: https://twitter.com/TeddyEAC/status/1769725032047972566

[-] Blxter@lemmy.zip 1 points 9 months ago

Afaik nothing has been confirmed besides that tweet from EAC

[-] CaptainBasculin@lemmy.ml 0 points 9 months ago

The tweet says they've seen the reports of a potential RCE, if they acknowledge this that pretty much means there is something that could achieve it. (or am i reading into it incorrectly?)

But they also state that this hasn't been exploited.

this post was submitted on 19 Mar 2024
468 points (92.4% liked)

Technology

60148 readers
1977 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS