BlockBlasters Patch Found to Deliver Malicious Software

22 Sep 2025

Security Threat Detected in BlockBlasters

In a recent development, gamers have been advised to exercise caution following the discovery of a malicious software issue in the patch for BlockBlasters. The popular 2D platformer-shooter, developed by Genesis Interactive, has been pulled from Steam after reports that the August 30 patch, identified as Build 19799326, contained multi-stage info-stealing malware.

Security firm G DATA reported that the patch initiated a complex attack sequence, which started with a batch script named game2.bat. This script is designed to collect sensitive information, such as IP locations, Steam login credentials, and details of installed antivirus products. The gathered data is then uploaded to a command and control server located at IP 203.188.171.156:30815/upload.

Malware Analysis and Behavior

The malware executes further actions if it identifies that only Windows Defender is the active antivirus. In such cases, it unpacks password-protected archives that contain additional harmful payloads. The batch script launches Visual Basic script files, launch1.vbs and test.vbs, to execute further malicious operations. These scripts aim to collect information about browser extensions and extract data from local cryptocurrency wallets, with exfiltrated information being sent to the same command and control server.

Subsequent scripts, such as 1.bat, have been designed to alter Microsoft Defender exclusions to omit the game's binary subdirectory. This allows the malware to execute other payloads while simultaneously launching the legitimate game, thereby concealing its true activities. Key binaries, such as Client-built2.exe and Block1.exe, have been identified as part of the attack infrastructure. These binaries include a compiled-Python backdoor and a C++ variant of the StealC stealer, which target browser data from users of Microsoft Edge and Brave browsers.

Impact and Actions Taken

The malicious activities have resulted in significant concern within the gaming community, especially given telemetry data from SteamDB and Gamalytic indicating that over 100 players downloaded the infected patch. There were typically 1–4 active players at any given time in early September, and the infection even reached a streamer during a charity livestream.

In response, Steam swiftly flagged BlockBlasters as suspicious and removed it from their store. Security experts have advised players to immediately remove the game from their systems, conduct comprehensive antivirus scans, and closely monitor their cryptocurrency wallets and accounts for any suspicious activity.

Recommendations for Gamers

For those affected or potentially exposed, it's crucial to stay vigilant. Security professionals recommend regular system checks and being wary of any unusual activity associated with online accounts. Players who suspect they have been targeted should also take note of known indicators of compromise, such as game2.bat, launch1.vbs, test.vbs, and 1.bat, which are key components of the malware's operation.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6766250
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1440077
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
587475
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
464691
downloads

News and reviews for Desktop Windows

Scott Pitkethly Revolutionized Game Engines at Creative Assembly

Scott Pitkethly transformed the battle engine for Rome: Total War at Creative Assembly, creating a legacy that endures in the gaming world.

Read more

NordVPN Ranks Third in Anti-Phishing Test

NordVPN’s Threat Protection Pro achieves 90% detection rate in AV-Comparatives test, ranking third in 2025 evaluations.

Read more

Hello Sunshine Revealed at PC Gaming Show, Playtest Opens

Hello Sunshine debuts at the PC Gaming Show. Developed by Red Thread Games, set for 2026 release with playtest sign-ups now open.

Read more

PC Gaming Show: Most Wanted 2025 Highlights Top Games

The PC Gaming Show: Most Wanted 2025 unveils premieres and Council's top 25, featuring GTA 6 and Slay the Spire 2.

Read more

Prime Gaming Offers 14 Free Games in December

Prime Gaming presents 14 free December games, highlighting Deus Ex and retro D&D titles. Games remain after subscription ends.

Read more

PC Gaming Show Reveals 86 Titles for 2025

The PC Gaming Show unveils 86 game titles, including major franchises, set for release in 2025.

Read more

Kill Joy Game Announced for PC: A Unique System-driven Experience

Kill Joy, a unique systems-driven exploration game, announced for PC. Players escape deceptive worlds by making creatures cry.

Read more

Epic Games Store Offers Free Games: Limited Time Access

Epic Games Store presents Free Games this December: The Darkside Detective and Jackbox Party Pack 4 for one week.

Read more

Sony Partners with Bad Robot for New Co-op Shooter

Sony teams up with Bad Robot Games for a co-op shooter on PS5 & PC, led by Mike Booth.

Read more

Microsoft Patches Windows LNK Zero-Day Exploit

Microsoft addressed a critical Windows LNK vulnerability in 2025-10; impact are worldwide malware risks.

Read more