Malware Disguised as a Popular South Korean Game Training Program
Recently, malware disguised as a game training program has been discovered in the increasingly popular South Korean game, PlayerUnknown's Battlegrounds.
[Figure 1] Introduction to PlayerUnknown's Battlegrounds (source: pubg.game.daum.net)
Game training programs are one of many programs used by players to gain an advantage and maximize their experience. However, creation and distribution of game trainers, along with any hacks, cheat keys, or macros that modify the game, is illegal in Korea.
[Figure 2] Malware Icon
The discovered malware is a .Net Framework-based program so it not run on PCs that do not have the .Net Framework software installed.
When a user on a .Net Framework installed computer downloads and runs the malware, a legitimate game trainer is also executed making it difficult for the user to detect the malware. Once executed, the malware adds itself to the registry to be automatically executed at system start and attempts a network connection to a specific port. If the connection is successful, the malware receives commands from its creator and performs additional malicious activities on the infected computer.
Software programs related to games are a frequently used tool by malware creators to disguise their malicious software. Therefore it is advised that game players use official products distributed by the game manufacturer and avoid downloading illegal programs.
The aliases identified by AhnLab's anti-malware solution AhnLab V3 are as below:
- Trojan/Win32.Dropper
- Trojan/Win32.Nitol