Hackers Use Steam Game To Secretly Steal User Data

Image by Florian Olivio, from Unsplash

Hackers Use Steam Game To Secretly Steal User Data

Reading time: 2 min

Hackers used a Steam game called Chemia to hide malware that secretly steals player data

In a rush? Here are the quick facts:

  • The game delivered HijackLoader and Vidar infostealers to user devices.
  • Malware connected to a Telegram-based command-and-control system.
  • The attack was stealthy, with no impact on gameplay performance.

The hacking group EncryptHub secretly embedded info-stealing malware into the early access Steam game  Chemia, putting unsuspecting players at risk.

BleepingComputer, who first reported this story, explains that Chemia, a survival crafting game by Aether Forge Studios, is still in early access and has no official release date.

According to cybersecurity firm Prodaft, the compromise began on July 22 when EncryptHub added malicious files to the game.

The first malware, HijackLoader (CVKRUTNP.exe), sets up long-term device access before downloading the Vidar info-stealing program. The malware connects with its command center through a Telegram channel.

The second malware, Fickle Stealer, is added through a DLL file named cclib.dll just three hours after the initial malware deployment. The file executes PowerShell scripts to retrieve its main payload from an untrustworthy  domain.

BleepingComputer explains that the Fickle Stealer malware steals browser data,  including passwords, cookies and cryptocurrency wallet information.

“The compromised executable appears legitimate to users downloading from Steam, creating an effective social engineering component that relies on platform trust rather than traditional deception techniques,” Prodaft told BleepingComputer.

“When users click on the Playtest of this game, which they find in the free games, they are actually downloading malicious software,” the researchers added.

The malware runs silently, without disrupting gameplay, so most players remain unaware that their data is being  stolen. The exact method  through which EncryptHub accessed the game remains unknown, but insider involvement  seems probable.

The game developers have not made any public  announcements about the situation, while the game continues to remain live on Steam.

BleepingComputer notes that this is the third malware case involving early access Steam games this year. Until an official investigation is completed, experts recommend avoiding Chemia and being cautious with early access titles.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback