{"id":24199,"date":"2024-03-20T15:10:03","date_gmt":"2024-03-20T23:10:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/03\/20\/news-17929\/"},"modified":"2024-03-20T15:10:03","modified_gmt":"2024-03-20T23:10:03","slug":"news-17929","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/03\/20\/news-17929\/","title":{"rendered":"Apex Legends Global Series plagued by hackers"},"content":{"rendered":"\n<p>The North American finals of online shooter game Apex Legends has been postponed after games were disrupted by hacking incidents. <\/p>\n<p>Apex Legends, published by EA, is currently in an important stage of its Global Series, the regional finals mode. This is a big deal for the top players since there is a $5 million prize pool, with a few of the top teams in each region set to battle it out in the finals.<\/p>\n<p>But on Monday, the Apex Legends official X account tweeted that it had postponed the contest after deciding the &#8220;competitive integrity&#8221; of the series had been compromised.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Due to the competitive integrity of this series being compromised, we have made the decision to postpone the NA finals at this time. <br \/>We will share more information soon.<\/p>\n<p>&mdash; Apex Legends Esports (@PlayApexEsports) <a href=\"https:\/\/twitter.com\/PlayApexEsports\/status\/1769527345176621110?ref_src=twsrc%5Etfw\">March 18, 2024<\/a><\/p><\/blockquote><\/div>\n<\/figure>\n<p>According to <a href=\"https:\/\/www.pcgamer.com\/games\/battle-royale\/apex-legends-streamers-warned-to-perform-a-clean-os-reinstall-as-soon-as-possible-after-hacks-during-na-finals-match\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PCGamer<\/a>, there were at least two major incidents:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201cFirst, Noyan &#8220;Genburten&#8221; Ozkose of DarkZero suddenly found himself able to see other players through walls, then Phillip &#8220;ImperialHal&#8221; Dosen of TSM was given an aimbot.\u201d<\/p>\n<\/blockquote>\n<p>An aimbot is a program or patch that allows the player to cheat by having the character&#8217;s weapon aimed automatically. Using cheats like those would lead to immediate disqualification and total loss of respect if done on purpose.<\/p>\n<p>The volunteers of the Anti-Cheat Police Department warned players against playing any games protected by Easy Anti-Cheat (EAC) or any EA titles for a while, because they suspected a Remote Code Execution (RCE) exploit was being used against the players.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">PSA: There is currently an RCE exploit being abused in <a href=\"https:\/\/twitter.com\/PlayApex?ref_src=twsrc%5Etfw\">@PlayApex<\/a>. It is unsure whether it comes from the game or the actual anti-cheat (<a href=\"https:\/\/twitter.com\/TeddyEAC?ref_src=twsrc%5Etfw\">@TeddyEAC<\/a> ). I would advise against playing any games protected by EAC or any EA titles once they have fixed this or can comment.<\/p>\n<p>Currently,\u2026<\/p>\n<p>&mdash; Anti-Cheat Police Department <img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/14.0.0\/72x72\/1f575.png\" alt=\"\ud83d\udd75\" class=\"wp-smiley\" style=\"height: 1em;max-height: 1em\" \/> (@AntiCheatPD) <a href=\"https:\/\/twitter.com\/AntiCheatPD\/status\/1769532511057584576?ref_src=twsrc%5Etfw\">March 18, 2024<\/a><\/p><\/blockquote><\/div>\n<\/figure>\n<p>However, recent developments point less toward an RCE being the cause and more to an actual infection on the players&#8217; computers&#8230;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-malwarebytes-to-the-rescue\">Malwarebytes to the rescue<\/h2>\n<p>In a <a href=\"https:\/\/www.youtube.com\/watch?v=HLPRaKO2CKg\">livestream<\/a>, affected gamer ImperialHal spoke to cybersecurity expert \u201cPirateSoftware,\u201d who has been investigating the attacks.<\/p>\n<p>ImperialHal uses Malwarebytes to scan his machine which flags an inbound connection from an IP address linked to a server known for malicious activities. <\/p>\n<p class=\"has-text-align-center\"><img decoding=\"async\" loading=\"lazy\" width=\"1488\" height=\"850\" class=\"wp-image-107003\" style=\"width: 650px\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/03\/Screenshot-2024-03-20-at-21.51.13.png\" alt=\"Malwarebytes flags a suspicious IP address\" \/><\/p>\n<p>It appears that the attacker had direct access to ImperialHal&#8217;s computer, likely via a Trojan. PirateSoftware concluded:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>&#8220;I don&#8217;t see evidence of Apex having RCEs. It does not mean that it&#8217;s impossible but I still don&#8217;t see evidence, while I do see evidence of him having direct access to your machine.&#8221;<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\" id=\"h-protect-yourself\">Protect yourself<\/h2>\n<p>We recommend that all gamers scan their computers with <a href=\"https:\/\/www.malwarebytes.com\/\">reliable security software<\/a>. Malwarebytes Premium for Windows&#8217; Brute Force Protection feature blocked the connection from being made to ImperialHal&#8217;s computer, so make sure you <a href=\"https:\/\/support.malwarebytes.com\/hc\/en-us\/articles\/4402387025427-Enable-Brute-Force-Protection-for-Malwarebytes-for-Windows-v4\">enable that feature.<\/a><\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on threats\u2014we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/03\/apex-legends-global-series-plagued-by-hackers\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The North American finals of the Apex Legends Global have been postponed after at least two hacking incidents. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,26699],"class_list":["post-24199","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-personal"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24199"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24199\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24199"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}