Proprietary · · 182 days

Infestation executable carried Winnti backdoor

Electronics Extreme distributed a trojanized Infestation executable. ESET found Winnti backdoor code launched before the game's normal runtime initialization.

ESET described Infestation as one of three Asian gaming supply-chain cases that shared the same embedded backdoor. Infestation was the clearest active case: the Thai developer Electronics Extreme was still distributing a trojanized build when ESET published its research.

The implant ran before the game. Code added near the PE entry point hooked the C runtime initialization path, decrypted an embedded DLL with RC4, launched the backdoor in memory, then resumed normal execution. That shape suggested a build-configuration or build-environment compromise rather than a simple post-download patch.

The backdoor reported host details, including user name, computer name, Windows version, system language, and a MAC-derived bot identifier. Commands were limited but useful: download a file, download and run a file, run a downloaded binary in memory, or disable callbacks through a registry flag.

The Infestation-specific C2 used nw.infestexe.com, a domain built to look related to the game. ESET also saw a Winnti second stage delivered from related infrastructure. This record stays scoped to Infestation even though the broader ESET report covered two other compromised game or gaming-platform products.

Appendix · Affected releases

Infestation.exe game launcher
  • Exact affected game executable versions or patch numbers were not publicly named.
  • ESET redacted some compromised file hashes at a vendor's request; this record keeps only the Infestation-themed payload hash and C2 details.

Indicators

  • familyWinnti
  • familyWin32/HackedApp.Winnti
  • familyWin32/Winnti.AG
  • familyWin64/Winnti.BN
  • domaininfestexe.com
  • domainnw.infestexe.com
  • domainapi.goallbandungtravel.com
  • domaincheckin.travelsanignacio.com
  • ip138.68.14.195
  • urlhttps://nw.infestexe.com/version/last.php
  • fileInfestation.exe
  • registryHKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ImageFlag
  • commandDownUrlFile
  • commandDownRunUrlFile
  • commandRunUrlBinInMem
  • commandUnInstall
  • observableBackdoor code ran before standard C runtime initialization.
  • observableMalware skipped systems configured with Russian or Chinese language.

References

  1. Gaming industry still in the scope of attackers in Asiawelivesecurity.com
  2. ShadowHammer Spreads Across Online Gaming Supply Chainbankinfosecurity.com
  3. Operation ShadowHammersecurelist.com
  4. Infestation: Survivor Stories backdoored with malware from hacker group Bariumreddit.com

Source record: proprietary/infestation/meta.yaml