Clearly that is the intent. These companies have no shame. Remember Sony's response to their rootkit being discovered? https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
Clearly that is the intent. These companies have no shame. Remember Sony's response to their rootkit being discovered? https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
But other commenters are right. It is compatible with being written by an independent vigilante, and it is compatible with being written by or on behalf of stakeholders.
I will withhold conclusion until further evidence is tendered.
Do you think this was backed by companies? It seems reasonable to suspect it, but it’s a issue radioactive now so won’t be easy to find out.
*(Unrelated to the CFD software, obviously)
This was the stuff the New York AG investigation unraveled:
https://ag.ny.gov/press-release/2021/attorney-general-james-...
https://arstechnica.com/tech-policy/2021/05/biggest-isps-pai...
(From Ars: "With broadband companies having used third-party vendors to conduct the campaign, the AG said it found no evidence that ISPs themselves "had direct knowledge" of the fraudulent behavior.")
Frankly I'd be shocked if it wasn't.
It could be some kind of Robinhood vigilante figure, but that's a hard sell for me given the already-known abusive history and tactics of the game industry.
Here's another hard sell : it's the TPB people releasing it in an effort to reduce their hosting costs. (It's not, but since we're throwing everything at the wall to see what sticks, why not?)
Many of these video game groups write root-kit style DRM mechanisms for a living; given the (shady) history & experience at the task, it's not a far leap to assume that one of these groups would irresponsibly combine the efforts, if given enough legal ambiguity and a long enough paper-trail to make legal harassment separated from the major group.
Personal anecdote : it's often talked about within game-cheating circles that mega-game groups actually take part in the ownership and funding of groups that sell third-party 'cheating' software. This new virus-writing behavior wouldn't surprise me in the least.
from the sound of the article, the malware sounds extremely unsophisticated, though. It edits your hostname, sends your ip and what you downloaded to some php script, and that's it. it doesn't even persistently install itself in any way. Basically anyone could put something like this together without much skill required. Not even disputing this wouldn't come from some sort of ip-based adjacent company, but I doubt it would be written by the same people who write DRM software
On the contrary, it makes one curious. Is it an attempt to ensnare the victim into heightened surveillance and suspicion (and hence higher likelihood of coming to harm) from governments, based on the assumption that their own malware uses these keywords to scan for targets? Or perhaps it creates some other kind of liability for the victim.
It seems very strange.