Proprietary 2018-01-01 · 434 days ·Data Theft

Point Blank executable shipped backdoor

Point Blank downloads were reported with a signed Winnti backdoor. The same payload family appeared in Asian gaming supply-chain compromises.

Story

ESET reported a cluster of Asian gaming supply-chain compromises in March 2019. Two games and one gaming platform carried the same backdoor code, launched by the same early-entry mechanism. Later reporting named Point Blank as one of the affected games.

The backdoor ran before normal program startup. Added code hooked the C runtime initialization path, decrypted an embedded DLL with RC4, executed it in memory, and then resumed the host application. That shape pointed toward build configuration or build environment compromise.

The payload was small but useful. It reported host identity, operating system, language, and a MAC-derived bot identifier, then accepted commands to download files, run downloaded binaries, execute a binary in memory, or disable callbacks through a registry flag.

ESET's telemetry placed victims mostly in Asia, with Thailand prominent. The record remains cautious about exact Point Blank versions because public reports did not publish a clean package list for that title.

Affected Artifacts

Incident Context

Motive
Espionage
Attribution
State
Cause
Build System Compromise
Transitive
No
Actor
BARIUM (APT17, Axiom, Deputy Dog)
Actor Country
China
Target Country
Asia

External References

Source record: proprietary/point_blank/meta.yaml