The ShadowHammer Trojanized Game Builds

Updated 5 Oct 2026 · Incident date 1 Jun 2018 · vendor binary

PackageElectronics Extreme (Infestation: Survivor Stories), Zepetto (Point Blank) and Innovative Extremist signed builds, 2018
Filethe vendors' own signed game/client executables; no fil...

Kaspersky found that signed game programs from Electronics Extreme, Zepetto and Innovative Extremist carried hidden backdoor code in 2018. The affected products include Infestation: Survivor Stories and PointBlank.

This was the second part of the ShadowHammer research. The first part covered ASUS Live Update. The sources do not give build or version numbers for the game builds.

What happened

Attackers put a backdoor into the signed executables of at least two game products and the signing certificate of a third company. Kaspersky's report names the companies below.

Kaspersky also reports that the related samples were compiled in June and July 2018.

The injection differs from the ASUS case. The malicious code was not added as a resource. It was compiled into the program. Kaspersky concludes that the attackers either had source code access or injected the code on the premises during compilation. Kaspersky also found a trojanized Microsoft Visual Studio linker, link.exe, uploaded in late 2018. It loaded a malicious DLL and swapped legitimate .lib files for malicious ones for chosen executable names.

The embedded payload had these behaviours.

The malware stopped if it saw Wireshark, ProcMon or Process Explorer. It also stopped if the system language was Simplified Chinese or Russian, or if its mutex already existed. BleepingComputer adds that Kaspersky found three more South Korean victims: a video game company, a holding company and a pharmaceutical company. Kaspersky linked the operation to the Winnti umbrella group and noted code overlap with ShadowPad and the CCleaner attack, per BleepingComputer and SecurityWeek. Read the full Kaspersky Securelist report.

A signed build that gains download-and-run code is the same shape as other trusted-update attacks. See GuptiMiner for another vendor binary case.

Affected versions

The sources name products and signers, not version numbers.

Kaspersky links the activity to the same group as the ASUS Live Update attack. More than 57,000 Kaspersky users encountered the injected ASUS code.

Indicators of compromise

How to check

Look for the registry key and for traffic to the command server. This command checks the key on Windows.

reg query "HKCU\SOFTWARE\Microsoft\Windows\{0753-6681-BD59-8819}"

If the command prints a key, the malware ran on that user account. Also search your DNS and proxy logs for infestexe. The sources do not publish file hashes for the game builds, so this page lists none.

What to do now

  1. Uninstall any copy of Infestation: Survivor Stories or an affected PointBlank build.
  2. Run the registry check above and search network logs for the command server host name.
  3. If a hit appears, isolate the machine and rebuild it. The malware can download and run more software.
  4. Change passwords used on that machine from a clean device.
  5. If you ship software, protect your build machine and your signing certificate. Revoke a certificate that signed a bad build.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Electronics-prev --new Electronics-current
files scanned: 67

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    Electronics.exe
           It now downloads from the internet. It did not before.

Frequently asked questions

What was ShadowHammer phase two?

Kaspersky found that signed game builds from Electronics Extreme, Zepetto and Innovative Extremist carried compiled-in backdoor code, in the same research as the ASUS Live Update attack.

Which games carried the ShadowHammer backdoor?

Infestation: Survivor Stories and PointBlank, according to Kaspersky.

What could the ShadowHammer game backdoor do?

It sent system data to a command server and could download a file, download and run a file, run a binary in memory, or uninstall itself.

Sources

  1. securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/
  2. bleepingcomputer.com/news/security/shadowhammer-targets-multiple-companies-asus-just-one-of-them/
  3. securityweek.com/kaspersky-links-shadowhammer-supply-chain-attack-shadowpad-hackers/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free