#336 Could this news be about the patch ? (virus abuse)

Closed
opened 1 year ago by Th1nkCh3ck · 6 comments
https://twitter.com/campuscodi/status/1562762475485171714?t=uN_BMCGkGXPJTPPEDD94kw&s=19 https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Th1nkCh3ck commented 1 year ago
Poster

No it actually isn't about the patch but it looks like the anti cheat could be changed due to this piece of news

No it actually isn't about the patch but it looks like the anti cheat could be changed due to this piece of news

They used started as admin Anti-cheat driver to inject a virus?

It's genius! Really...

Good that Linux run wine in userland, we're save (maybe).

They used started as admin Anti-cheat driver to inject a virus? It's genius! Really... Good that Linux run wine in userland, we're save (maybe).

The vulnerability itself does not affect us, but the fallout (changes to anti-cheat) most likely will. So if you feel like you need to do something in game this month, you're probably better off doing it before this hits!

The vulnerability itself does not affect us, but the fallout (changes to anti-cheat) most likely will. So if you feel like you need to do something in game this month, you're probably better off doing it before this hits!

So if you feel like you need to do something in game this month, you're probably better off doing it before this hits!

I have win10 in dual boot, just in case =)

But this is uncomfortable, reboot every time, and also game performance was a bit better under WINE.

> So if you feel like you need to do something in game this month, you're probably better off doing it before this hits! I have win10 in dual boot, just in case =) But this is uncomfortable, reboot every time, and also game performance was a bit better under WINE.
kumik commented 1 year ago

I first came to know of kernel level anti cheats when I tried running Genshin on my box, and wondered how was this kind of stuff even allowed in the first place.

I honestly don't have plans to dual boot Windows if the changes somehow break the patching of the anti cheat. Last time I tried I felt physically sick, without exaggeration.

I first came to know of kernel level anti cheats when I tried running Genshin on my box, and wondered how was this kind of stuff even allowed in the first place. I honestly don't have plans to dual boot Windows if the changes somehow break the patching of the anti cheat. Last time I tried I felt physically sick, without exaggeration.
Krock commented 1 year ago
Owner

There are a few projects on GitHub about using the mhyprot2 service to modify memory and manipulate processes. The root of the problem is long-known, it was only a matter of time until someone abuses it.

Closing. This is a non-issue (for now). Feel free to continue the discussion nonetheless.

There are a few projects on GitHub about using the mhyprot2 service to modify memory and manipulate processes. The root of the problem is long-known, it was only a matter of time until someone abuses it. Closing. This is a non-issue (for now). Feel free to continue the discussion nonetheless.
Sign in to join this conversation.
Loading...
Cancel
Save
There is no content yet.