HelloKitty ransomware rebrands, releases CD Projekt and Cisco data
bleepingcomputer.com
bleepingcomputer.com
> One representative of the group compiling Witcher 3 known as 'sventek' told BleepingComputer that the leaked CD Projekt data is 450 GB uncompressed and contains source code for Witcher 3, Gwent, Cyberpunk, various console SDK (PS4/PS5 XBOX NINTENDO), and some build logs.
> Sventek told BleepingComputer that they were previously able to compile Cyberpunk 2077 from the CD Projekt's leak...
Is 450gb really that big enough? Games are individually often close to a hundred gb, and I'd assume the source code has more things.
I’ve worked on a bunch of AAA game projects and the “MAIN” stream is usually somewhat small because people often want to have multiple checkouts on one drive.
Usually the main stream can compile the entire game so it has all the required assets, but not everything that is used to make the assets for the game in the first place.
Raw assets like textures, I'd guess? These often get downscaled and compressed as part of build.
The only scenario I can think of is games supporting surround sound which can't afford the extra cycles of decompression.
PC gamers (especially those with SSDs) were puzzled to find out that Titanfall had a gargantuan 48 GB file size, despite the lack of a single player campaign and the fact that it was running on a modified source engine. Some digging around in the files revealed that a huge portion of that size was due to a whopping 35 GB of completely uncompressed audio. Respawn has now explained that the reason the audio was not compressed was so they could dedicate more system resources to running the game, and less to unpacking audio files.
...
He did, however, admit that most PC gamers probably wouldn’t even notice the difference. “On a higher PC it wouldn’t be an issue. On a medium or moderate PC, it wouldn’t be an issue, it’s that on a two-core [machine] with where our min spec is, we couldn’t dedicate those resources to audio.”
[0] https://www.escapistmagazine.com/titanfall-dev-explains-the-...Assets are not part of the source code, so this is huge.
That's almost 20,000 times all of Wikipedia, or 2 whole single page applications using a JavaScript framework!
450GB is ~450•10^9 B (~ to handle the fact that it might be GiB), which is 450 billion bytes in the short scale (450 thousand million/450 milliard in the long scale).
1B may or may not equal 1 character depending on your encoding, but 1000 characters per byte is unlikely.
Depends how linguistically precise the hackers are being. I could see them calling the contents of a repository the source code, and to my understanding, especially around the time of witcher 3's development, a lot of game dev studios used Perforce specifically because they were checking assets in and Perforce handled that better.
Aah thanks, that helps clarifying it. Yep, without media I could see that that many lines of code would be a lot. But how would they make the game without textures? I guess just ripping them from the published version, or just going "it compiles!" and calling it quits?
But also it isn't that uncommon at game studios for assets to be checked in alongside the code, so I wouldn't be shocked if these source code dumps and the associated sizes being reported also include the assets.
Around 45gb src for a 5gb game (pc, android, ios)
Here's some more math for you: you've used 204 characters to write "Javascript bad", which is 15 characters. That's almost 14 times more characters than what you could've used!
That's a Lovecraftian horror. Also, it also almost certainly does not exist. The largest codebases would be lucky if they hit a 200MBs-2GB of straight code. And they're far an away the exceptions, not the norm.
Google has billions of lines of code in one repo. I don’t have hard numbers on file sizes, but a billion bytes is a gigabyte. A billion lines taking tens of gigabytes does not seem unreasonable.
https://cacm.acm.org/research/why-google-stores-billions-of-...
> That's a Lovecraftian horror
Perhaps.
That repo has over a hundred apps.
> I don’t have hard numbers on file sizes, but a billion bytes is a gigabyte. A billion lines taking tens of gigabytes does not seem unreasonable.
Again, multiple apps/projects. But even so, I said the low GBs was possible and represents an extreme exception. Even with you stretching to find that exception, we're still far away from 450GB as a "normal" amount.
So what is your point? My napkin math was off by a few GB? Congrats, got me.
> Games are individually often close to a hundred gb, and I'd assume the source code has more things
They acknowledge they were mistaken about code size in a sister comment.
Edit
Found it, previously they released a magnet link called funnytorrent that was over 800gb, but all files are 7z encrypted and no password was available. There are still seeds :O
So I'm guessing the new thing is the new TW3 version CDP confirmed this week they are working on.
Edit 2
The "new magnet" link is the same hash, so no new files in there.
And we see the results of those concerns even when games do get open-sourced - for example, last week Descent 3's engine was released as open-source, and it was released without those parts (c.f.: https://github.com/DescentDevelopers/Descent3/blob/61bb9a337... )
-------
When a software company licenses a third-party library in source-form, invariably the license agreement includes a stipulation that the licensee take all reasonable precautions to prevent the release of the source-code - so if it can be shown that CD Projekt Red was negligent in keeping their source secure such that it was leaked by HelloKitty, then they're open to civil liability here. Obviously the onus is on the plaintiffs to prove that CD Projekt Red was negligent here.
I'm not accusing CD Projekt Red of being organizationally negligent myself; but I assume that most of their devs had a copy of their entire source-tree on their machines (just like I have all of my org's source on my machines) - and it only takes 1 person to disable their antivirus for something like this to happen. What I am saying is that it's possible that CD Projekt Red was negligent in keeping any licensed source-code reasonably secure, and that HelloKitty was aware of this fact, and used that as leverage in their extortion attempt: i.e. "we know you didn't secure your source-tree - and MIDDLEWARE_PROVIDER won't be happy about that and we estimate you'll owe MIDDLEWARE_PROVIDER about $500k if they find out, so if you pay us $250k we'll keep quiet about this, if not, we'll leak everything".
Again, I'm just positing by connecting-the-dots here - I'm not making any assertions.
[1] https://www.tweaktown.com/news/96928/apex-legends-pro-player...
I stopped what I was doing and drove over there. Luckily someone DDoS'd the pay site so they couldn't pay. I asked them what they were thinking. They told me that they were going to pay with their super prestigious credit card and refute the charge as fraud because in their words, "Technically, this is fraud."
I shook my head and cleaned it up and restored the backups. I asked them a week later how much data was lost. They asked me what I was talking about. Apparently they didn't have anything important they did since the backup ran the night before. They switched to a SaaS shortly afterwards. Then raided by the government & shut down a couple years later. Good times.
[1] https://www.wired.com/story/change-healthcare-ransomhub-thre...