BlockBlasters Patch Found to Deliver Malicious Software

22 Sep 2025

Security Threat Detected in BlockBlasters

In a recent development, gamers have been advised to exercise caution following the discovery of a malicious software issue in the patch for BlockBlasters. The popular 2D platformer-shooter, developed by Genesis Interactive, has been pulled from Steam after reports that the August 30 patch, identified as Build 19799326, contained multi-stage info-stealing malware.

Security firm G DATA reported that the patch initiated a complex attack sequence, which started with a batch script named game2.bat. This script is designed to collect sensitive information, such as IP locations, Steam login credentials, and details of installed antivirus products. The gathered data is then uploaded to a command and control server located at IP 203.188.171.156:30815/upload.

Malware Analysis and Behavior

The malware executes further actions if it identifies that only Windows Defender is the active antivirus. In such cases, it unpacks password-protected archives that contain additional harmful payloads. The batch script launches Visual Basic script files, launch1.vbs and test.vbs, to execute further malicious operations. These scripts aim to collect information about browser extensions and extract data from local cryptocurrency wallets, with exfiltrated information being sent to the same command and control server.

Subsequent scripts, such as 1.bat, have been designed to alter Microsoft Defender exclusions to omit the game's binary subdirectory. This allows the malware to execute other payloads while simultaneously launching the legitimate game, thereby concealing its true activities. Key binaries, such as Client-built2.exe and Block1.exe, have been identified as part of the attack infrastructure. These binaries include a compiled-Python backdoor and a C++ variant of the StealC stealer, which target browser data from users of Microsoft Edge and Brave browsers.

Impact and Actions Taken

The malicious activities have resulted in significant concern within the gaming community, especially given telemetry data from SteamDB and Gamalytic indicating that over 100 players downloaded the infected patch. There were typically 1–4 active players at any given time in early September, and the infection even reached a streamer during a charity livestream.

In response, Steam swiftly flagged BlockBlasters as suspicious and removed it from their store. Security experts have advised players to immediately remove the game from their systems, conduct comprehensive antivirus scans, and closely monitor their cryptocurrency wallets and accounts for any suspicious activity.

Recommendations for Gamers

For those affected or potentially exposed, it's crucial to stay vigilant. Security professionals recommend regular system checks and being wary of any unusual activity associated with online accounts. Players who suspect they have been targeted should also take note of known indicators of compromise, such as game2.bat, launch1.vbs, test.vbs, and 1.bat, which are key components of the malware's operation.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7404047
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1701862
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
730747
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491642
downloads

News and reviews for Desktop Windows

Microsoft Expands Game Pass with Major Releases

Microsoft adds major titles like Death Stranding to Game Pass, enhancing the platform's offerings starting 2026-01-21.

Read more

Game Pass Adds Resident Evil Village; Big Releases Ahead

Game Pass updates: Resident Evil Village now available. Death Stranding Director's Cut and more coming soon, impacting player engagement.

Read more

Dune Awakening Expands to Consoles in 2026

Dune Awakening's console release in 2026 aims to capture PS5 and Xbox players, broadening its reach.

Read more

New Titles Including GamePass for January Launch

Xbox GamePass adds new games, including Warhammer and Death Stranding. Titles launch January 2023, expanding game library across platforms.

Read more

0patch Bridges Security Gap for Windows 10 Post-Support

0patch, offering micropatches, addresses security needs for Windows 10 after Microsoft's support ended. Costs may impact long-term use.

Read more

Big Hops Introduces Unique Gameplay by Luckshot Games

Big Hops by Luckshot Games adds unique mechanics to platformer genre with engaging movement and collectibles.

Read more

Project Reforged: Sonic Revamp with Alpha Demo Released

Project Reforged, by Besky, offers a fan remake of Sonic and the Black Knight with new levels and mechanics in its alpha demo.

Read more

Cor3 Countdown Hints at New Space FPS by Tarkov Lead

Cor3, linked to Escape From Tarkov's Buyanov, teases potential space FPS with a countdown ending on 2026-02-01.

Read more

PDFSIDER Malware Bypasses EDR via PDF24 Exploits

PDFSIDER backdoor exploits PDF24 vulnerabilities, evading EDR. Analyzed by Resecurity, it impacts endpoint defenses.

Read more

Inkle Launches New PC Game: World War Investigation Sim

Inkle releases a PC game this week: a World War investigation sim. Other PC games include strategy, RPGs, and platformers. Expect diverse gameplay.

Read more