The ShadowHammer Trojanized Game Builds
Updated 5 Oct 2026 · Incident date 1 Jun 2018 · vendor binary
Electronics Extreme (Infestation: Survivor Stories), Zepetto (Point Blank) and Innovative Extremist signed builds, 2018the vendors' own signed game/client executables; no fil...Kaspersky found that signed game programs from Electronics Extreme, Zepetto and Innovative Extremist carried hidden backdoor code in 2018. The affected products include Infestation: Survivor Stories and PointBlank.
This was the second part of the ShadowHammer research. The first part covered ASUS Live Update. The sources do not give build or version numbers for the game builds.
What happened
Attackers put a backdoor into the signed executables of at least two game products and the signing certificate of a third company. Kaspersky's report names the companies below.
- Electronics Extreme Company Limited (Thailand) made Infestation: Survivor Stories. The game servers were taken offline on 15 December 2016.
- Innovative Extremist Co. LTD. (Thailand) originally signed copies of Infestation. Its certificate is now revoked.
- Zepetto Co. (South Korea) made PointBlank. Kaspersky writes that Zepetto seems to have stopped using the affected certificate at the end of February 2019.
Kaspersky also reports that the related samples were compiled in June and July 2018.
The injection differs from the ASUS case. The malicious code was not added as a resource. It was compiled into the program. Kaspersky concludes that the attackers either had source code access or injected the code on the premises during compilation. Kaspersky also found a trojanized Microsoft Visual Studio linker, link.exe, uploaded in late 2018. It loaded a malicious DLL and swapped legitimate .lib files for malicious ones for chosen executable names.
The embedded payload had these behaviours.
- It checked for administrator rights.
- It checked a registry key and collected the MAC address, host name, CPU architecture and language.
- It talked to a command server over HTTP.
- It supported four commands:
DownUrlFile,DownRunUrlFile,RunUrlBinInMemandUnInstall.
The malware stopped if it saw Wireshark, ProcMon or Process Explorer. It also stopped if the system language was Simplified Chinese or Russian, or if its mutex already existed. BleepingComputer adds that Kaspersky found three more South Korean victims: a video game company, a holding company and a pharmaceutical company. Kaspersky linked the operation to the Winnti umbrella group and noted code overlap with ShadowPad and the CCleaner attack, per BleepingComputer and SecurityWeek. Read the full Kaspersky Securelist report.
A signed build that gains download-and-run code is the same shape as other trusted-update attacks. See GuptiMiner for another vendor binary case.
Affected versions
The sources name products and signers, not version numbers.
- Infestation: Survivor Stories, from Electronics Extreme, signed by Innovative Extremist Co. LTD.
- PointBlank, from Zepetto, signed with a certificate that Zepetto stopped using at the end of February 2019.
Kaspersky links the activity to the same group as the ASUS Live Update attack. More than 57,000 Kaspersky users encountered the injected ASUS code.
Indicators of compromise
- Command server URL:
https://nw.infestexe[.]com/version/last.php - Registry key checked by the malware:
HKCU\SOFTWARE\Microsoft\Windows\{0753-6681-BD59-8819} - Mutex:
Windows-{0753-6681-BD59-8819} - Target tag in the payload:
warz - Sleep interval: 240000 milliseconds.
- Commands:
DownUrlFile,DownRunUrlFile,RunUrlBinInMem,UnInstall. - A
link.exelinker from late 2018 that loaded a malicious DLL.
How to check
Look for the registry key and for traffic to the command server. This command checks the key on Windows.
reg query "HKCU\SOFTWARE\Microsoft\Windows\{0753-6681-BD59-8819}"If the command prints a key, the malware ran on that user account. Also search your DNS and proxy logs for infestexe. The sources do not publish file hashes for the game builds, so this page lists none.
What to do now
- Uninstall any copy of Infestation: Survivor Stories or an affected PointBlank build.
- Run the registry check above and search network logs for the command server host name.
- If a hit appears, isolate the machine and rebuild it. The malware can download and run more software.
- Change passwords used on that machine from a clean device.
- If you ship software, protect your build machine and your signing certificate. Revoke a certificate that signed a bad build.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 67 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED Electronics.exe It now downloads from the internet. It did not before.
Frequently asked questions
What was ShadowHammer phase two?
Kaspersky found that signed game builds from Electronics Extreme, Zepetto and Innovative Extremist carried compiled-in backdoor code, in the same research as the ASUS Live Update attack.
Which games carried the ShadowHammer backdoor?
Infestation: Survivor Stories and PointBlank, according to Kaspersky.
What could the ShadowHammer game backdoor do?
It sent system data to a command server and could download a file, download and run a file, run a binary in memory, or uninstall itself.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.