Proprietary · · 1 day
Blade Chronicle update files swapped for malware
Update files for Aiming's online game Blade Chronicle were replaced with malware in May 2014, through the same intrusion at content-delivery provider CDNetworks that tampered with Buffalo's driver downloads.
Part of One CDNetworks breach tampered with four customers' files campaign
Aiming ran Blade Chronicle as an online game, which means its client updated itself. On 26 May 2014 that update path stopped behaving: players reported failures in the game content client at around 14:30, and the update files the client fetched had been replaced with malware.
The compromise was not at Aiming. The files were served through CDNetworks, the content-delivery provider Aiming used, and the same intrusion altered content belonging to several other customers in the same window, including Buffalo's Windows driver and firmware installers. CDNetworks concluded that its own content-upload servers had been logged into directly, most likely from a compromised internal terminal.
Aiming began emergency maintenance at 02:00 on 27 May and ended it at 23:30 the same day. The number of players who received a tampered update is not published, and no public source gives file names or hashes for the altered update files, so this record is scoped to what the timeline and the provider's own disclosure establish.
The case is worth keeping separate from the Buffalo record because the delivery path differs in a way that matters: a game client fetches updates automatically, without a user choosing to download and run an installer. The same intrusion therefore reached one set of victims through a deliberate download and another through software updating itself.
Notes
- Aiming reported a fault in its game content client at 14:30 on 2014-05-26, began emergency maintenance at 02:00 on 2014-05-27 and ended it at 23:30 the same day.
- The number of affected players is not quantified in any source located for this record, so no impact count is recorded.
- Infostealer.Bankeiya.B is the family reported across the Buffalo case in the same intrusion. No source located for this record names the family in the Aiming update files specifically, so it is not recorded as an indicator here.
Appendix · Affected releases
- No file names, versions or hashes for the tampered update files are published in any source located for this record. The artifact is recorded at the level the sources support.
References
- CDNetworks content tampering incident summary and timelinepiyolog.hatenadiary.jp
Source record: proprietary/aiming-blade-chronicle/meta.yaml