Probably only on a targeted attack. I don’t see it being a mass target attack like a worm could be.
And in the realm of businesses, how many programs are running in kernel level besides the antivirus/ED(P)R solution?
I don’t see it being a mass target attack like a worm could be.
Why not? Malware that survives a full new install is extremely valuable, and there are loads of games adding vulnerabilities with required kernel level rootkits. It’s only a matter of time until one of these vendors is exploited, and why wouldn’t you permanently own the significant chunk of the market with unpatched serious vulnerabilities while you’re at it?
Again: Mass spread vs target attack.
Remember WannaCry? Yeah, I don’t see that happen.
But (industrial) e-spionage on the other hand? Yup. Will happen 100%
Kernel level game anticheats are a great attack vector, and it’s one that inherently identifies and enables distribution to other vulnerable targets. It’s begging to self replicate.
Industrial espionage does not make sense, because most enterprises have, even if imperfect, restrictions on what can be installed on company computers that contain valuable information. You’re not going to get a game with kernel malware on a managed enterprise computer.
Are you ignoring what I wrote earlier in the same thread?
Probably only on a targeted attack. I don’t see it being a mass target attack like a worm could be.
And in the realm of businesses, how many programs are running in kernel level besides the antivirus/ED(P)R solution?
Anyway. Counter question: Why do you think gamers appear as a more valuable target with the anti cheat as a possible attack vector vs a business running literally the same CPU line-up but with fewer kernel level programs?
My personal opinion: You can’t extract as much money from private folks vs a business through blackmail and other solutions. Not in a wide casted attack.
Targeted individuals can be assumed to be at a higher risk (e.g. hacking their private devices like the gaming pc and then doing home office work in the same network, or misusing trust in the home network between pc and phone and then installing malware like pegasus).
But again: Not in a wide casted net. And you are probably better of using the good exploits for higher value targets.
You’re responding to a post about exploiting kernel level anticheat and saying it would only be a targeted attack, despite that inherently not making sense. When you find a vulnerability in that software, there is absolutely no reason not to spread it en masse. The cost to infect one person is the same as the cost to affect tens of thousands or more. The game is both the vulnerability and the distribution method.
Gamers aren’t more valuable. They’re more accessible. Because there isn’t a kernel rootkit “anticheat” developer on the planet who gives two shits about security in any context, and there are a massive number of systems that their insane hacky bullshit touches. Every single one of them has their security automatically compromised. The goal isn’t just information. You’re getting a massive, distributed, residential IP botnet that you can’t lose unless they throw their systems in the trash.
Probably only on a targeted attack. I don’t see it being a mass target attack like a worm could be.
And in the realm of businesses, how many programs are running in kernel level besides the antivirus/ED(P)R solution?
And with crowd strike we have seen how reliable Antivirus is.
The USB and network stack
Why not? Malware that survives a full new install is extremely valuable, and there are loads of games adding vulnerabilities with required kernel level rootkits. It’s only a matter of time until one of these vendors is exploited, and why wouldn’t you permanently own the significant chunk of the market with unpatched serious vulnerabilities while you’re at it?
Again: Mass spread vs target attack.
Remember WannaCry? Yeah, I don’t see that happen.
But (industrial) e-spionage on the other hand? Yup. Will happen 100%
For what reason?
Kernel level game anticheats are a great attack vector, and it’s one that inherently identifies and enables distribution to other vulnerable targets. It’s begging to self replicate.
Industrial espionage does not make sense, because most enterprises have, even if imperfect, restrictions on what can be installed on company computers that contain valuable information. You’re not going to get a game with kernel malware on a managed enterprise computer.
Are you ignoring what I wrote earlier in the same thread?
Anyway. Counter question: Why do you think gamers appear as a more valuable target with the anti cheat as a possible attack vector vs a business running literally the same CPU line-up but with fewer kernel level programs?
My personal opinion: You can’t extract as much money from private folks vs a business through blackmail and other solutions. Not in a wide casted attack.
Targeted individuals can be assumed to be at a higher risk (e.g. hacking their private devices like the gaming pc and then doing home office work in the same network, or misusing trust in the home network between pc and phone and then installing malware like pegasus).
But again: Not in a wide casted net. And you are probably better of using the good exploits for higher value targets.
You’re responding to a post about exploiting kernel level anticheat and saying it would only be a targeted attack, despite that inherently not making sense. When you find a vulnerability in that software, there is absolutely no reason not to spread it en masse. The cost to infect one person is the same as the cost to affect tens of thousands or more. The game is both the vulnerability and the distribution method.
Gamers aren’t more valuable. They’re more accessible. Because there isn’t a kernel rootkit “anticheat” developer on the planet who gives two shits about security in any context, and there are a massive number of systems that their insane hacky bullshit touches. Every single one of them has their security automatically compromised. The goal isn’t just information. You’re getting a massive, distributed, residential IP botnet that you can’t lose unless they throw their systems in the trash.