The Apex Legends Hack.

John Hammond · Intermediate ·🔐 Cybersecurity ·2y ago

Key Takeaways

The video discusses a cybersecurity incident involving Apex Legends professional players who had their games compromised with cheats during a tournament, and explores the possible causes and consequences of the hack, including the potential involvement of a Source engine bug and the importance of keeping antivirus software up to date. The video also mentions various tools and frameworks used in the investigation, such as Malwarebytes, EAC, and VirusTotal.

Full Transcript

all right let's talk about the Apex Legends thing so if you've been living under a rock quick context a few days ago at the Apex Legends game series two of the professional players had their games presumably compromised and enabled cheats live during the tournament I'm getting hacked I'm getting hacked but I know I know it's true can you play the game bro I'm getting hacked I know but can you play can you play yeah but I'm it's cheating gen Burton and Imperial how were of course taken by surprise and they couldn't really play because these active cheats like Aimbot or others would disqualify them from the event get them banned from online games and then of course there was an obviously growing concern that there was some vulnerability or exploit or hack that would make Apex Legends unsafe to play so in this video I'd like to chat about it or at least offer my take now I know there are a ton of people curious about this I've gotten a handful of messages and posts asking if I would end up discussing it in a video and I even had some questions from reporters and journalists at work now let me say outright I don't play Apex I'm not in the traditional Gaming Community but I am in the cyber security community in case you're new here just for credibility sake I worked at the defense threat reduction agency as a red teamer I taught as an instructor with the Department defense cyber training academy and right now I work as a practitioner and cyber security researcher at a managed security platform called Huntress I've been in the industry for a little bit have a few cves to my name and I try to share education here on YouTube I don't call myself a cyber security expert because honestly in my mind there are no experts in this field the industry this whole scene is just too big but the thing is the cyber security industry and the gaming industry do intertwine here and there for vulnerabilities just like it did when there was an HTML injection bug and Counter Strike or log forj weaknesses in Minecraft and so much more so I think it's really cool when we get to chat about this stuff and we have these Two Worlds Collide when there's a chance to bridge the gap and talk about this I think it is really worthwhile to do so with that said I'll be straight up I don't have any definitive or hardcore answers for you and no one does right now as far as I know thus far there haven't been any confirmed details on what the hack really was how it was performed or what the impact truly even is there's been loads of speculation lots of confusion jumping to conclusions and potentially blowing things out of proportion by the online gaming community the only core facts is that the player gen Burton was competing in the Apex Legends Global series or algs and suddenly chat messages were sent into the game lobby as Apex hacking Global series and buy Destroyer 2009 and random for a few frames a game rendered user interface pops up with a TSM Halal hook title with presumably settings to configure an Aimbot maybe visuals credits for the tool and miscellaneous other options now a lot of people are jumping in and calling this a remote code execution vulnerability here's the thing this rendered user interface looks like an in-game window you can see a little bit of transparency in the background and that at least looks to me like it resides in game not the full-blown machine or the computer that that player is using so with these observations alone they don't definitively mean remote code execution just off of these clips and footage it doesn't a, % guarantee that there is an rce vulnerability in the source engine the game engine behind Apex Legends or the anti-che engine it could suggest something of that scale but it's still uncertain and unconfirmed but it wasn't just G burden it wasn't just one player this incident happens at the same time for another player Imperial Hal shoot can we shoot height can we shoot height yeah yeah shoot now I'm I'm cheating I'm cheating I'm cheating I got Aimbot I have Aimbot oh no uh leave the game you got to leave the game bro you got to leave the game the door's lock break it break it break it I'm I have Aimbot right now the chat messages in the user interface don't appear on his screen but presumably the Aimbot sheet is turned on for him as well and again this is speculation but noting this only impacted two players in the competitive tournament perhaps it's an attempt to sabotage their performance in the event but this is surprising to me if this is an actual exploit that's used with a limited blast radius that just seems odd to me if an ill-intended adversary really wanted to do damage they would typically spread this as far and wide as possible and impact the maximum amount of users possible these two players that were impacted are live streamers with the highest view count during the event so a chat message like hacked by Destroyer 2009 in random might just be to get their name out there for kicks or for trolling or virality if it were real burning a remote code execution vulnerability in a driver level anti-che engine just to inject cheats into a streamer's game to mess with them or the tournaments it's just really unlikely in my mind I think this is especially true for like the pay to cheat business like if a game modder or a hacker were selling this as a tool if you're a broker you don't want this type of publicity for your cheats or other cheats being used in a game that you create these cheats for because that could potentially burn how your cheats get loaded and then regular people get discouraged from playing the game which in turn causes the game developers and companies to crack down on cheating even more so if I were to put my hacker hat on that just doesn't make a lot of sense to me I will note though the players Imperial Hal and gen Burton were banned from playing the Apex game online since they were forced to cheat and as far as I know they still are banned still nothing proves this to be a remote code execution vulnerability in either Apex itself or the anti-che engine or if the players just simply had Mau on their computers and they were compromised prior again I'm not in the Apex Legends community so I don't know all of the details but from what I understand Destroyer 2009 is a known video game modder and hacker within the Apex Legends Community other clips and footage of gameplay have surfaced online where other public lobbies have been seen with the distributed flood of messages referring to Destroyer 2009 but those chat messages alone aren't an indicator of either that individual as the bad actor or that this was remote code execution on Twitter or X Apex Legends shared a post stating that they were postponing the tournament finals due to the competitive Integrity being compromised now I'm an outsider looking in but in my opinion frankly this is a good decision regardless of the being an exploited vulnerability or not since the competition was tampered with in any way calling a timeout is probably prudent they state that they will release further information soon and we'll chat about that in just a sec but just following the easy anti-che framework used for Apex Legends online gameplay posted publicly their statement that there is no remote code execution vulnerability in their tooling now we might take that at face value and then think okay it could be either the The Source engine for Apex Legends itself that has a flaw or weakness or the end user in the player's computer could have been compromised but eac's tweet might not represent them having done a full and complete root cause analysis we don't have the inside info or knowledge on whether or not they have a full or comprehensive understanding of what happened and that's not me Throwing Shade that's just acknowledging that a public blanket statement might not have the full picture take that with of salt because I don't know with all this in mind while there could be a remote code execution bug in Apex Legends or the source engine nothing is confirmed if there really were this vulnerability it would be surprising to me and admittedly a little bit convoluted as to how that can make for a threat outside of the game and I mean running applications on the player's computer invoking malware or deploying ransomware it makes more sense to me if Destroyer 2009 or whatever actor had an exploit to make changes to a game Lobby server that might spawn other Bots or enemies Enable cheats flood or spam chat messages but all that relies within the game itself it could be access to the game server maybe or just hijinks with their API or more likely just automated tooling and I mean automated tooling like on the client side from the players perspective to maybe manipulate game objects for an online lobby but that does not prove remote code execution pushed through a game Lobby or an online server to compromise the whole computer or the Endo that players are using that seems like the most likely explanation in my mind maybe Destroyer 2009 or whatever actor manipulating the client to do any nefarious stuff on the game server that could adust the game environment or the game Lobby and the game players but that doesn't mean they have arbitrary code execution on the server machine itself or any of the computers so to answer the question of look is Apex Legends safe to play right now I don't know I I don't know for sure and I'm not going to pretend like I do but I would like to think and I'd hope that hey maybe it's not too much of a world shift or life change if you just sort of put it away for a little bit maybe wait until this whole Halo dies down and we get some real facts and information from the source and on that note hey the latest update at least at the time we recording this video is that the Twitter or X accounts from respawn and play Apex did acknowledge this with a statement they say on Sunday a few professional Apex Legends players were hacked during the algs event game and player security is our highest priorities which is why we paused the competition to address the issue immediately our teams have deployed the first of a layered series of updates to protect the Apex Legends community and create a secure and safe environment and experience for everyone thank you for your patients now I don't know about you but at least to me that is kind of a whole lot of nothing it doesn't really answer any questions or explain anything it just said we're on it so cool I see a lot of mixed reactions to this online like it's great that they acknowledge this but I think personally and maybe for a whole lot of other folks would really like to see maybe a little bit more behind the curtain now just before that public statement I did see this article pop up with alleged new findings in the Apex Legends hacking incident it discusses the conversation with Imperial Hal and pirate software which by the way hey Thor if you happen to be watching this I think you're super duper cool and would love to chat please hit me up anytime but the article focuses on how these two got to chat and Imperial Hal ran a malware bite scan and found hey one alert one notice for inbound network communication and to be clear this is communication to the windows service host.exe process which is usually a default and natural process on Windows but it can be spoofed and this is communication on Port 135 which is typically for RPC or the remote procedure call additionally this IP address 107.170 2365 is a digital ocean IP address for folks not familiar that's not the actor's home IP address that's a cloud instance which means it could be a totally temporary an ephemeral IP address that could rotate over time as that cloud hosting provider digital ocean just hands that IP address out to anyone spinning up a machine on the internet the 135 RPC Port is really interesting because sure that could mean command and control instructions sent to how's machine though it is odd to me that that would just naturally work if an inbound connection unless you had that Port publicly exposed and you weren't behind a router's gat like Network address translation any other source Port from the remote machine could communicate to that destination port and Port 135 RPC is always listening by default on Windows if we do take a look at this IP address on virus total and even showan and census there aren't a ton of hits for this even historically though there are some really interesting domain names attached to this I won't fall down that rabbit hole here because honestly candidly there's not enough information to go off of just from this Mau by screenshot alone if there were more alerts or more triggered notifications and just some other details that could help color the picture I'd be fine with more to run with here but I don't think that there was network communication is enough to definitively say oh that person's compromised now on the other end of this digital ocean the cloud hosting provider could check in and see and investigate what account has that IP address in their machine pool and that could help further the investigation but we got to keep in mind even this isn't all that definitive so here is my TLD r or tldw too long didn't watch look something weird happened we have limited info the info that we have is conflicting people are making many exaggerated claims without verifying or knowing which certainty if they're true and look game exploits have existed in the past so this could be real but we won't really know anything until that root cause analysis is done and we have some more of the tangible details that bubble up to the surface I know it sucks but honestly waiting for more info is the real answer right now and it's totally possible maybe we'll never get that full root cause analysis or all the Gory details maybe we could look ourselves do some independent research and hey I'll be the first to admit I haven't gotten a chance to dig in or explore this yet I'm not a game hacker I don't know if there's some complex Elite super convoluted chaining of different attack vectors and vulnerabilities for a fullon remote code execution Downstream all-c connected Cent but that just seems unlikely to me but hey take this with a grain of salt because this is totally all anecdotal and just hearsay but one of my good colleagues that's more focused in the game hacking World said that it was real and this is all third hand but they said it's a source engine bug that they had dug up and they've been working on for a while but look again with all that said I don't know how realistic it is to load a game hack or do any of these cheat enablement things during runtime but I don't play Apex I don't know I have not personally validated or confirmed anything this is all just talk and until we hear that deep dive analysis and real details from the people involved that's all it's going to be just talk so hey I wish I could give you a sharper or more definitive answer right now but look the the best answer is to keep your ear to the ground maybe take a break from playing Apex Legends for a little bit make sure you're installing updates patches for your devices keep that antivirus cruising then just don't download and run stupid stuff hey I'd love to get your thoughts in the comments please let me know if you agree or you just think I'm wildly off course look I'm totally cool with that I'm happy to be schooled seriously genuinely I think when the gaming world and the cyber security World get a chance to blend and merge a little bit we all get to improve and fix security weaknesses whatever they are together so thanks for watching

Original Description

Seriously big HUG OPS and support to all the developers and security team working behind the scenes on this. It might be a booboo in whatever way shape or form, but improving security is always a good thing. Free Cybersecurity Education and Ethical Hacking with John Hammond 📧JOIN MY NEWSLETTER ➡ https://jh.live/email 🙏SUPPORT THE CHANNEL ➡ https://jh.live/patreon 🤝 SPONSOR THE CHANNEL ➡ https://jh.live/sponsor 🌎FOLLOW ME EVERYWHERE ➡ https://jh.live/twitter ↔ https://jh.live/linkedin ↔ https://jh.live/discord ↔ https://jh.live/instagram ↔ https://jh.live/tiktok 💥 SEND ME MALWARE ➡ https://jh.live/malware 🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 0 of 60

← Previous Next →
1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

The video teaches viewers about the importance of cybersecurity in online gaming and the potential consequences of hacking incidents, and provides tips on how to prevent and investigate such incidents. Viewers can learn about the tools and frameworks used in the investigation and how to keep their devices and software up to date to prevent hacking. The key insight is that cybersecurity is an ongoing process that requires constant vigilance and updating of software and systems.

Key Takeaways
  1. Investigate the incident and gather information
  2. Analyze the potential causes of the hack
  3. Implement anti-cheat measures and update software
  4. Keep antivirus software up to date and install updates for devices
  5. Avoid downloading and running suspicious files
💡 Cybersecurity is an ongoing process that requires constant vigilance and updating of software and systems to prevent hacking incidents.

Related Reads

📰
Understanding MSFVenom: How to Generate Metasploit Payloads | By Dharavath Nagaraju
Learn to generate Metasploit payloads using MSFVenom for efficient cybersecurity testing
Medium · Cybersecurity
📰
Edge-First Revolution: Reclaiming Data Sovereignty in Cybersecurity
Learn how edge-first security architecture can help small businesses reclaim data sovereignty and improve cybersecurity with affordable hardware and AI-driven threat detection
Dev.to · Andrei Toma
📰
How to Actually Protect Your Online Accounts From Hackers: A 2026 Guid
Learn how to protect your online accounts from hackers with practical steps and tools in 2026
Medium · Cybersecurity
📰
Making Data Transmission Truly Secure in Spring Boot: A Complete Guide to Frontend–Backend…
Learn how to secure data transmission in Spring Boot beyond just using HTTPS, crucial for enterprise systems like banking and healthcare
Medium · Programming
Up next
NordVPN Coupon Code 2026 | Exclusive Discount + 4 FREE Months
Tutorial Stack
Watch →