The day after the North American finals of the Apex Legends Global Series was postponed because of a mid-match hack against two players, Easy Anti-Cheat has issued a statement saying «there is no RCE vulnerability» in its software that was exploited to carry out the attack.
The first hack, against Noyan «Genburten» Ozkose of DarkZero, took place during the third match of the day: He was suddenly able to see every other player on the map, even through walls, and was ultimately forced to drop out of the match, although his teammates managed to claim second place even though they were a man down. The second hack occurred in the next match: Phillip «ImperialHal» Dosen of TSM suddenly found himself saddled with an aimbot. That match was ultimately abandoned, and the North American finals were postponed «due to the competitive integrity of this series being compromised.»
Shortly afterward, the Anti-Cheat Police Department, a volunteer group that specializes in «gathering intelligence on cheats to detect and disrupt cheating vendors,» issued a statement saying that an RCE (remote code execution) was being abused in the game, and that it was unclear «whether it comes from the game or the actual anti-cheat (software).»
Remote code execution exploits enable attackers to run software on remote machines, and they are bad news: An RCE was responsible for the suspension of PC PvP servers for Dark Souls games in 2022. A similar vulnerability was discovered in GTA Online in 2023.
In this case, as Anti-Cheat PD put it, «the RCE is being abused to inject cheats into streamers machines, which means they have the capabilities to do whatever, like installing ransomware software locking up your entire PC.»
How this attack happened still isn't known, but earlier today Easy Anti-Cheat issued a statement disavowing responsibility. «We have investigated recent reports of a potential RCE issue within Easy Anti-Cheat,» it tweeted. «At this time—we are confident that there is no RCE
Read more on pcgamer.com