Skip to main content

Hackers are leveraging pirated games to spread malware

Pirated or cracked versions of games have long been a hotbed for malware distribution, and cybercriminals are now using CAPTCHA challenges to make their attacks even more effective.

According to a recent report by McAfee Labs, attackers are leveraging CAPTCHA to trick users into thinking that malicious websites or downloads are legitimate. Security researchers first detected the use of CAPTCHAs in malware delivery schemes last month.

Since then, this technique has rapidly gained traction, with reports indicating a growing number of users encountering it worldwide. McAfee’s data suggests that this method of attack is becoming increasingly prevalent, putting more individuals at risk across different regions.

This method is common in pirated games, where users may already expect to jump through extra hoops, like bypassing verification systems. When users search for cracked versions of popular games, they often end up on shady websites. These sites commonly use CAPTCHAs to appear more credible, creating the illusion that the files or content being offered are secure. After solving the CAPTCHA, users are redirected to download a file that is typically riddled with malware, in this case, Lumma Stealer.

Infection chain of the Lumma Stealer malware.
McAfee

Lumma Stealer is a sophisticated information-stealing malware that surfaced in 2022. It targets sensitive data like login credentials, browser cookies, saved passwords, and information from file transfer protocol (FTP) clients and cryptocurrency wallets.

The malware stealthily collects this data from infected systems and transmits it to remote servers controlled by attackers. Its ability to steal from major web browsers, including Chrome, Firefox, and Edge, as well as its capacity to compromise cryptocurrency wallets, makes it a potent threat, particularly to users holding digital assets.

Google search links to pirated or cracked version of Black Myth Wukong.
It is highly recommended to avoid such websites that offer pirated games or software. McAfee

The malware spreads through phishing campaigns, malicious downloads, and compromised websites, often hidden within pirated software or gaming mods. Lumma Stealer employs various evasion tactics, such as encrypting communications with its command-and-control server and using obfuscation techniques to avoid detection by antivirus programs. Its ability to bypass security measures and harvest valuable information makes it a dangerous tool for cybercriminals.

A false sense of security

The CAPTCHA provides an extra layer of camouflage, as it helps malicious websites and downloads bypass automated scanners used by security solutions. CAPTCHA requires human intervention, thus fooling security systems into thinking the site is legitimate.

Pirated games are attractive to cybercriminals for several reasons. First, users looking for free or cracked software are more likely to take risks, bypassing warnings and even turning off antivirus protections to install the software. Secondly, pirated games often require “patches” or “keygens” that are commonly disguised as malware.

The use of CAPTCHA tricks users into believing that the download or website they are interacting with is more secure. Since CAPTCHAs are typically seen as security measures, many users don’t think twice about solving them. After solving the CAPTCHA, they unknowingly download infected files, leaving their systems exposed to attacks.

How to stay protected

To avoid malware attacks, it’s crucial to steer clear of pirated content. Downloading cracked games or software greatly increases the risk of malware infection. Instead, always use legitimate platforms for downloading games and software, as these sources are verified and safer. Keeping your security software, such as antivirus and anti-malware tools, up to date is essential for detecting and preventing new threats. Additionally, if your antivirus tool flags an installation, don’t ignore it; there’s likely a valid reason behind the warning.

As cybercriminals evolve their tactics, staying informed about new malware strategies is vital. CAPTCHAs, originally designed to confirm human users, are now being exploited by attackers as a method to distribute malware, particularly in the realm of pirated gaming. Understanding these risks and taking preventive steps can significantly reduce the likelihood of falling victim to such attacks.

Kunal Khullar
Kunal is a Computing writer contributing content around PC hardware, laptops, monitors, and more for Digital Trends. Having…
Razer just opened the floodgates for its ‘cheating’ Snap Tap feature
Razer Blade 14 sitting on a coffee table.

Razer is expanding support for its Snap Tap feature, which rolled out a few months ago alongside the Huntsman V3 Pro keyboard. It allows much quicker inputs between two keys, particularly when it comes to strafing in games like Valorant, Apex Legends, and Rainbow Six: Siege. Now, the vast majority of Razer's gaming keyboards are getting support, along with Razer Blade laptops -- some of which are among the best gaming laptops you can buy.

Originally, Snap Tap was billed as a feature enabled by the Hall Effect (magnetic) switches, but this latest update proves that's not the case. Snap Tap allows you to switch between two keys without fully lifting your finger when switching between them. In the case of strafing, for example, you're able to bounce back and forth between your A and D keys, and Snap Tap will prioritize your most recent input. That's true even if your finger continues pressing down on the previous key, allowing for very fast, precise strafing.

Read more
HP’s new 2-in-1 laptop packs a 3K OLED touchscreen
A woman sits at a desk, using the new HP EliteBook X.

HP just unveiled three new laptops during its yearly HP Imagine event, and if you use your laptop for work, there's plenty to be interested in. The most eye-catching offering of the trio is the HP OmniBook Ultra Flip, which is a 2-in-1 laptop with a 3K OLED touchscreen. There are two more laptops for professionals, and HP ticks the box for Qualcomm, Intel, and AMD enthusiasts, as the three laptops come with different CPUs.

Let's start with the OmniBook Ultra Flip. This is a 14-inch convertible laptop that comes equipped with Intel's latest Lunar Lake processors, offering up to the Core 9 Ultra 288V with eight cores and eight threads and a maximum clock speed of 5.1GHz. The lowest variant sports the Ultra 5 226V, which also has eight cores and eight threads, but it only boosts up to 4.5GHz. All variants come with integrated Intel Arc graphics, and while the top two chips get the 16GB version, the less premium offerings come with the 8GB version.

Read more
We gave this MacBook Pro alternative a 9 out of 10, and it’s on sale
Asus ProArt P16 front angled view showing display and keyboard.

Even with the discounts from MacBook deals, Apple's MacBook Pro remains pretty expensive. Here's a slightly more affordable MacBook Pro alternative: the Asus ProArt P16, which is on sale from Best Buy at $200 off for a lowered price of $1,700 from $1,900. It's still not budget-friendly, but that's an excellent price for a laptop of its capabilities. And if you like the power and style of a MacBook but prefer Windows, this is a good option. You're going to have to be quick with your purchase though, as there's no telling how much time is left before you miss out on the savings.

Why you should buy the Asus ProArt P16 laptop
We reviewed the Asus ProArt P16 as a legitimate MacBook Pro competitor with a rating of 9 out of 10 stars, as it's a very fast laptop with a relatively affordable price. It's powered by the AMD Ryzen AI 9 HX 370 processor and the Nvidia GeForce RTX 4060 graphics card, with 32GB of RAM that's recommended by our laptop buying guide for running intensive applications and engaging in content creation. The Asus ProArt P16 also features a gorgeous 16-inch OLED touchscreen with 4K resolution, the Asus DialPad that's a circular indentation in the touchpad with an embedded button that provides additional functionality for various apps, and military-grade toughness for guaranteed durability.

Read more