Duet Night Abyss: When Your Free Loot Boxes Come with a Side of Digital Disaster... Twice!
AI Gaming News Author · kotaku ·
A gacha game called *Duet Night Abyss* has issued an apology after its launcher distributed password and crypto-stealing malware to players, marking the *second* such incident in a month – making their offer of ten free skins as compensation feel like a rather poor trade-off for potential digital compromise.
Right, so you know that feeling when you're just trying to enjoy a new game, maybe snagging some freebies, and then suddenly your PC starts acting like it's been possessed by a mischievous digital imp? Yeah, well, for players of the free-to-play gacha RPG *Duet Night Abyss*, that digital imp turned out to be a full-blown Trojan horse, and it wasn't even a surprise party trick for some.
I've been tinkering with this story all morning, and bloody hell, it’s wilder than it first appeared. According to a recent report by Lewis Parker for Kotaku, the developers of *Duet Night Abyss*, Pan Studio and publisher Hero Games, have been forced to issue a rather sheepish apology. Why, you ask? Because on March 18th, a 'cybersecurity incident' – which is corporate speak for 'we done goofed' – saw their game launcher pushing out actual malware to countless player PCs. Mate, talk about a loot box surprise nobody asked for!
The particular nastiness delivered via this unwanted update was identified by sharp-eyed players (and their trusty antivirus software) as 'Trojan:MSIL/UmbralStealer.DG!MTB.' I did a bit of light research on this digital menace, and fair dinkum, it’s not just some minor glitch. Umbral Stealer is an infostealer virus, designed to creepily record your keystrokes, snap screenshots of your desktop, and generally poke its digital nose where it absolutely doesn’t belong. Its primary directive? To hoover up sensitive info like your passwords and, crucially for our corner of the gaming world, your cryptocurrency. That’s right, folks. Just when you thought your biggest risk was pulling another duplicate character, you’re now potentially staring down a compromised crypto wallet. Lovely, isn't it?
This malicious update, apparently a patch for the game’s launcher, went live on Steam at an ungodly hour of 7:39 am UTC. The developers quickly (or perhaps not quickly enough, depending on your perspective) took to their X (formerly Twitter) account to issue a statement, calling it a 'malicious attack' and claiming 'persistent attempts to continue the attack and spread misinformation have occurred.' They strongly condemned these actions, as you'd expect. And then came the classic corporate mea culpa: 'As security is a vital pillar of a live product, this incident has served as a serious wake-up call for our team.' You don’t say, chaps? One might almost wonder what *else* could be a 'serious wake-up call' besides distributing a password and crypto-stealing Trojan.
Now, for the 'apology' itself. The *Duet Night Abyss* team decided to bestow upon their now-suspicious player base some in-game goodies: 'Commission Manual: Volume III*5, Prismatic Hourglass*10.' Which, if my translation from Gacha-speak to Human is correct, amounts to ten free random skins. Ten. Free. Skins. For potentially having your digital life rifled through by a sneaky Trojan. Call me old-fashioned, but that feels less like a fair exchange and more like offering a band-aid after someone's been hit by a magic missile to the face. It’s certainly not going to magically restore trust, especially when it comes to the security of one's digital assets. And for those of us deeply entrenched in Web3 gaming, where our in-game items *are* our assets, this kind of security slip-up is a particularly chilling thought. If a game launcher can be compromised to steal crypto, it certainly puts a stark spotlight on the vulnerabilities of our digital inventories.
But here's where it gets truly wild, like a spell casting gone completely sideways. This isn't *Duet Night Abyss*'s first rodeo with malware. Oh no, mate. This is actually the *second* time in a single month that their launcher has been compromised! Back in late February, another malware attack was pushed out. The previous one, thankfully, was less malicious, seemingly designed more as a cheeky warning shot to the developers. That one simply instructed players to—wait for it—play *Genshin Impact* instead. Honestly, you can't make this stuff up! It’s like a digital prankster wizard trying to teach them a lesson, only this time the lesson came with a real risk of your bank account being emptied.
So, it’s no surprise that fans aren’t exactly queuing up to praise the 'security enhancements' the developers claim to have implemented. When your 'wake-up call' comes twice in a month, courtesy of two separate malware attacks via your own distribution platform, you've got bigger problems than just convincing players to accept some cosmetic items. This incident isn't just about *Duet Night Abyss*; it's a sobering reminder for the entire gaming industry, particularly those relying on proprietary launchers and constant updates. What happens when our trusted portals to virtual worlds become vectors for real-world digital threats?
This whole kerfuffle really makes you wonder, doesn't it? Is the drive for free-to-play engagement leading to lax security protocols? Are smaller studios, or perhaps even larger ones, simply not investing enough in safeguarding player data and devices? It's easy for companies to trot out buzzwords like 'vital pillar' and 'serious wake-up call,' but for the players, it's their personal information, their digital assets, and their peace of mind on the line. I reckon we gamers deserve better than a 'sorry, here's some skins' after a data-stealing Trojan has been passed around like a dodgy party favour. Here's hoping this *actual* wake-up call leads to some genuine, robust changes, and not just another apology for the next round of digital shenanigans. Maybe next time, they'll offer an actual anti-virus subscription instead of a few virtual trousers.
Original article by Lewis Parker for Kotaku.
Tags: gacha game, malware, cybersecurity, free-to-play, player safety
Original article: kotaku