

The specific version of the tool observed here drops three files, one of which is a backdoor Trojan. The tool, however, uses techniques that are also being used by malicious programs and can be easily exploited for malware. The tool is called Synapse X, which has a legitimate purpose and has safe files. Hackers are exploiting a scripting engine used for Roblox to insert malicious files, one of which is a backdoor trojan. The threat report shows the characteristics that make this file dangerous. This video shows how the program, called Synapse X, installs itself. In this attack, threat actors are injecting three files, one of which is a backdoor, into a scripting engine used by Roblox. Techniques: Backdoor Trojan, Malicious file injection.The file was originally found in OneDrive–Avanan then scanned and blocked the file. In this attack, hackers are installing a self-executing program in Windows, via a Roblox scripting engine. In this attack brief, Avanan will analyze how hackers are installing backdoor Trojans via Roblox scripts. The tool installs an executable file that installs library files into the Windows system folder, giving the program the potential to break applications, corrupt or remove data, or send information back to the hacker. Starting in March 2022, Avanan researchers uncovered a Trojan file that was hidden within a legitimate scripting engine that’s used for cheat code in Roblox. According to Check Point Research, Roblox was the 8th-most impersonated brand in the first quarter of 2022, ahead of Paypal and Apple. It’s no surprise, then, that hackers are looking to attach themselves to this service. Beyond that, two-thirds of all kids in the U.S. At one point, over half of American kids were playing Roblox.

In 2021, this gaming platform grew from 32.6 million daily active users to nearly 50 million, across 180 countries. Roblox is one of the most popular game systems in the world.
