The Apex Legends Hack.
Key Takeaways
The video discusses a cybersecurity incident involving Apex Legends professional players who had their games compromised with cheats during a tournament, and explores the possible causes and consequences of the hack, including the potential involvement of a Source engine bug and the importance of keeping antivirus software up to date. The video also mentions various tools and frameworks used in the investigation, such as Malwarebytes, EAC, and VirusTotal.
Full Transcript
all right let's talk about the Apex Legends thing so if you've been living under a rock quick context a few days ago at the Apex Legends game series two of the professional players had their games presumably compromised and enabled cheats live during the tournament I'm getting hacked I'm getting hacked but I know I know it's true can you play the game bro I'm getting hacked I know but can you play can you play yeah but I'm it's cheating gen Burton and Imperial how were of course taken by surprise and they couldn't really play because these active cheats like Aimbot or others would disqualify them from the event get them banned from online games and then of course there was an obviously growing concern that there was some vulnerability or exploit or hack that would make Apex Legends unsafe to play so in this video I'd like to chat about it or at least offer my take now I know there are a ton of people curious about this I've gotten a handful of messages and posts asking if I would end up discussing it in a video and I even had some questions from reporters and journalists at work now let me say outright I don't play Apex I'm not in the traditional Gaming Community but I am in the cyber security community in case you're new here just for credibility sake I worked at the defense threat reduction agency as a red teamer I taught as an instructor with the Department defense cyber training academy and right now I work as a practitioner and cyber security researcher at a managed security platform called Huntress I've been in the industry for a little bit have a few cves to my name and I try to share education here on YouTube I don't call myself a cyber security expert because honestly in my mind there are no experts in this field the industry this whole scene is just too big but the thing is the cyber security industry and the gaming industry do intertwine here and there for vulnerabilities just like it did when there was an HTML injection bug and Counter Strike or log forj weaknesses in Minecraft and so much more so I think it's really cool when we get to chat about this stuff and we have these Two Worlds Collide when there's a chance to bridge the gap and talk about this I think it is really worthwhile to do so with that said I'll be straight up I don't have any definitive or hardcore answers for you and no one does right now as far as I know thus far there haven't been any confirmed details on what the hack really was how it was performed or what the impact truly even is there's been loads of speculation lots of confusion jumping to conclusions and potentially blowing things out of proportion by the online gaming community the only core facts is that the player gen Burton was competing in the Apex Legends Global series or algs and suddenly chat messages were sent into the game lobby as Apex hacking Global series and buy Destroyer 2009 and random for a few frames a game rendered user interface pops up with a TSM Halal hook title with presumably settings to configure an Aimbot maybe visuals credits for the tool and miscellaneous other options now a lot of people are jumping in and calling this a remote code execution vulnerability here's the thing this rendered user interface looks like an in-game window you can see a little bit of transparency in the background and that at least looks to me like it resides in game not the full-blown machine or the computer that that player is using so with these observations alone they don't definitively mean remote code execution just off of these clips and footage it doesn't a, % guarantee that there is an rce vulnerability in the source engine the game engine behind Apex Legends or the anti-che engine it could suggest something of that scale but it's still uncertain and unconfirmed but it wasn't just G burden it wasn't just one player this incident happens at the same time for another player Imperial Hal shoot can we shoot height can we shoot height yeah yeah shoot now I'm I'm cheating I'm cheating I'm cheating I got Aimbot I have Aimbot oh no uh leave the game you got to leave the game bro you got to leave the game the door's lock break it break it break it I'm I have Aimbot right now the chat messages in the user interface don't appear on his screen but presumably the Aimbot sheet is turned on for him as well and again this is speculation but noting this only impacted two players in the competitive tournament perhaps it's an attempt to sabotage their performance in the event but this is surprising to me if this is an actual exploit that's used with a limited blast radius that just seems odd to me if an ill-intended adversary really wanted to do damage they would typically spread this as far and wide as possible and impact the maximum amount of users possible these two players that were impacted are live streamers with the highest view count during the event so a chat message like hacked by Destroyer 2009 in random might just be to get their name out there for kicks or for trolling or virality if it were real burning a remote code execution vulnerability in a driver level anti-che engine just to inject cheats into a streamer's game to mess with them or the tournaments it's just really unlikely in my mind I think this is especially true for like the pay to cheat business like if a game modder or a hacker were selling this as a tool if you're a broker you don't want this type of publicity for your cheats or other cheats being used in a game that you create these cheats for because that could potentially burn how your cheats get loaded and then regular people get discouraged from playing the game which in turn causes the game developers and companies to crack down on cheating even more so if I were to put my hacker hat on that just doesn't make a lot of sense to me I will note though the players Imperial Hal and gen Burton were banned from playing the Apex game online since they were forced to cheat and as far as I know they still are banned still nothing proves this to be a remote code execution vulnerability in either Apex itself or the anti-che engine or if the players just simply had Mau on their computers and they were compromised prior again I'm not in the Apex Legends community so I don't know all of the details but from what I understand Destroyer 2009 is a known video game modder and hacker within the Apex Legends Community other clips and footage of gameplay have surfaced online where other public lobbies have been seen with the distributed flood of messages referring to Destroyer 2009 but those chat messages alone aren't an indicator of either that individual as the bad actor or that this was remote code execution on Twitter or X Apex Legends shared a post stating that they were postponing the tournament finals due to the competitive Integrity being compromised now I'm an outsider looking in but in my opinion frankly this is a good decision regardless of the being an exploited vulnerability or not since the competition was tampered with in any way calling a timeout is probably prudent they state that they will release further information soon and we'll chat about that in just a sec but just following the easy anti-che framework used for Apex Legends online gameplay posted publicly their statement that there is no remote code execution vulnerability in their tooling now we might take that at face value and then think okay it could be either the The Source engine for Apex Legends itself that has a flaw or weakness or the end user in the player's computer could have been compromised but eac's tweet might not represent them having done a full and complete root cause analysis we don't have the inside info or knowledge on whether or not they have a full or comprehensive understanding of what happened and that's not me Throwing Shade that's just acknowledging that a public blanket statement might not have the full picture take that with of salt because I don't know with all this in mind while there could be a remote code execution bug in Apex Legends or the source engine nothing is confirmed if there really were this vulnerability it would be surprising to me and admittedly a little bit convoluted as to how that can make for a threat outside of the game and I mean running applications on the player's computer invoking malware or deploying ransomware it makes more sense to me if Destroyer 2009 or whatever actor had an exploit to make changes to a game Lobby server that might spawn other Bots or enemies Enable cheats flood or spam chat messages but all that relies within the game itself it could be access to the game server maybe or just hijinks with their API or more likely just automated tooling and I mean automated tooling like on the client side from the players perspective to maybe manipulate game objects for an online lobby but that does not prove remote code execution pushed through a game Lobby or an online server to compromise the whole computer or the Endo that players are using that seems like the most likely explanation in my mind maybe Destroyer 2009 or whatever actor manipulating the client to do any nefarious stuff on the game server that could adust the game environment or the game Lobby and the game players but that doesn't mean they have arbitrary code execution on the server machine itself or any of the computers so to answer the question of look is Apex Legends safe to play right now I don't know I I don't know for sure and I'm not going to pretend like I do but I would like to think and I'd hope that hey maybe it's not too much of a world shift or life change if you just sort of put it away for a little bit maybe wait until this whole Halo dies down and we get some real facts and information from the source and on that note hey the latest update at least at the time we recording this video is that the Twitter or X accounts from respawn and play Apex did acknowledge this with a statement they say on Sunday a few professional Apex Legends players were hacked during the algs event game and player security is our highest priorities which is why we paused the competition to address the issue immediately our teams have deployed the first of a layered series of updates to protect the Apex Legends community and create a secure and safe environment and experience for everyone thank you for your patients now I don't know about you but at least to me that is kind of a whole lot of nothing it doesn't really answer any questions or explain anything it just said we're on it so cool I see a lot of mixed reactions to this online like it's great that they acknowledge this but I think personally and maybe for a whole lot of other folks would really like to see maybe a little bit more behind the curtain now just before that public statement I did see this article pop up with alleged new findings in the Apex Legends hacking incident it discusses the conversation with Imperial Hal and pirate software which by the way hey Thor if you happen to be watching this I think you're super duper cool and would love to chat please hit me up anytime but the article focuses on how these two got to chat and Imperial Hal ran a malware bite scan and found hey one alert one notice for inbound network communication and to be clear this is communication to the windows service host.exe process which is usually a default and natural process on Windows but it can be spoofed and this is communication on Port 135 which is typically for RPC or the remote procedure call additionally this IP address 107.170 2365 is a digital ocean IP address for folks not familiar that's not the actor's home IP address that's a cloud instance which means it could be a totally temporary an ephemeral IP address that could rotate over time as that cloud hosting provider digital ocean just hands that IP address out to anyone spinning up a machine on the internet the 135 RPC Port is really interesting because sure that could mean command and control instructions sent to how's machine though it is odd to me that that would just naturally work if an inbound connection unless you had that Port publicly exposed and you weren't behind a router's gat like Network address translation any other source Port from the remote machine could communicate to that destination port and Port 135 RPC is always listening by default on Windows if we do take a look at this IP address on virus total and even showan and census there aren't a ton of hits for this even historically though there are some really interesting domain names attached to this I won't fall down that rabbit hole here because honestly candidly there's not enough information to go off of just from this Mau by screenshot alone if there were more alerts or more triggered notifications and just some other details that could help color the picture I'd be fine with more to run with here but I don't think that there was network communication is enough to definitively say oh that person's compromised now on the other end of this digital ocean the cloud hosting provider could check in and see and investigate what account has that IP address in their machine pool and that could help further the investigation but we got to keep in mind even this isn't all that definitive so here is my TLD r or tldw too long didn't watch look something weird happened we have limited info the info that we have is conflicting people are making many exaggerated claims without verifying or knowing which certainty if they're true and look game exploits have existed in the past so this could be real but we won't really know anything until that root cause analysis is done and we have some more of the tangible details that bubble up to the surface I know it sucks but honestly waiting for more info is the real answer right now and it's totally possible maybe we'll never get that full root cause analysis or all the Gory details maybe we could look ourselves do some independent research and hey I'll be the first to admit I haven't gotten a chance to dig in or explore this yet I'm not a game hacker I don't know if there's some complex Elite super convoluted chaining of different attack vectors and vulnerabilities for a fullon remote code execution Downstream all-c connected Cent but that just seems unlikely to me but hey take this with a grain of salt because this is totally all anecdotal and just hearsay but one of my good colleagues that's more focused in the game hacking World said that it was real and this is all third hand but they said it's a source engine bug that they had dug up and they've been working on for a while but look again with all that said I don't know how realistic it is to load a game hack or do any of these cheat enablement things during runtime but I don't play Apex I don't know I have not personally validated or confirmed anything this is all just talk and until we hear that deep dive analysis and real details from the people involved that's all it's going to be just talk so hey I wish I could give you a sharper or more definitive answer right now but look the the best answer is to keep your ear to the ground maybe take a break from playing Apex Legends for a little bit make sure you're installing updates patches for your devices keep that antivirus cruising then just don't download and run stupid stuff hey I'd love to get your thoughts in the comments please let me know if you agree or you just think I'm wildly off course look I'm totally cool with that I'm happy to be schooled seriously genuinely I think when the gaming world and the cyber security World get a chance to blend and merge a little bit we all get to improve and fix security weaknesses whatever they are together so thanks for watching
Original Description
Seriously big HUG OPS and support to all the developers and security team working behind the scenes on this. It might be a booboo in whatever way shape or form, but improving security is always a good thing.
Free Cybersecurity Education and Ethical Hacking with John Hammond
📧JOIN MY NEWSLETTER ➡ https://jh.live/email
🙏SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/discord ↔ https://jh.live/instagram ↔ https://jh.live/tiktok
💥 SEND ME MALWARE ➡ https://jh.live/malware
🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
Tutorials? MySQL connection with PHP and Bash!
John Hammond
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
JavaScript Splits The URL!
John Hammond
HTML Tables in Python!
John Hammond
HTML, Net Shares, GML!
John Hammond
Python 08 Programming Style and Comments
John Hammond
Python 26 Object Oriented Programming
John Hammond
75 Python Tutorials, Out Now!
John Hammond
Batch 14 Mathematical Expressions
John Hammond
Batch 85 Array Append
John Hammond
Batch 86 Array Count
John Hammond
Batch 87 Array Index
John Hammond
Batch 88 Array Insert
John Hammond
Batch 89 Array Remove
John Hammond
Batch 90 Array Reverse
John Hammond
Python [colorama] 00 Installing on Linux
John Hammond
Python [colorama] 09 Cursor Position
John Hammond
Python [hashlib] 02 Algorithms
John Hammond
Python 00 Installing IDLE on Linux
John Hammond
Python [pygame] 11 Rectangular Collision Detection
John Hammond
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
Python [XML-RPC] 01 Research
John Hammond
Python [pyenchant] 03 Personal Word Lists
John Hammond
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
Python 04: PEP8 Coding
John Hammond
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
John Hammond
Google CTF 2016: Spotted Quoll
John Hammond
Google CTF 2016: Can you Repo It?
John Hammond
Google CTF 2016: No Big Deal
John Hammond
Google CTF 2016: In Recorded Conversation
John Hammond
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
Homemade CTF Challenge: 04 "UPX"
John Hammond
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
Juniors CTF 2016 :: Six Strange Tales
John Hammond
Juniors CTF 2016 :: Lost Code
John Hammond
Juniors CTF 2016 :: Here Goes!
John Hammond
Juniors CTF 2016 :: Southern Cross
John Hammond
Juniors CTF 2016 :: Clone Attack
John Hammond
Juniors CTF 2016 :: Dirty Repo
John Hammond
Juniors CTF 2016 :: Hackers Blog
John Hammond
Juniors CTF 2016 :: Voting!!!
John Hammond
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
Juniors CTF 2016 :: Stop Thief!
John Hammond
Juniors CTF 2016 :: ROFL
John Hammond
Juniors CTF 2016 :: Restriced Area
John Hammond
Juniors CTF 2016 :: Oh SSH!
John Hammond
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
HackCon CTF 2017 "Bacche" Challenges
John Hammond
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
Understanding MSFVenom: How to Generate Metasploit Payloads | By Dharavath Nagaraju
Medium · Cybersecurity
Edge-First Revolution: Reclaiming Data Sovereignty in Cybersecurity
Dev.to · Andrei Toma
How to Actually Protect Your Online Accounts From Hackers: A 2026 Guid
Medium · Cybersecurity
Making Data Transmission Truly Secure in Spring Boot: A Complete Guide to Frontend–Backend…
Medium · Programming
🎓
Tutor Explanation
DeepCamp AI