Jump to content

New malware named Joao is discovered, targeting gamers worldwide.


Recommended Posts



ESET researchers have discovered a new sneaky malware threat named Joao, targeting gamers worldwide. Spread via hacked Aeria games offered on unofficial websites, the modular malware can download and install virtually any other malicious code on the victim’s computer.


To spread their malware, the attackers behind Joao have misused massively-multiplayer online role-playing games (MMORPGs) originally published by Aeria Games. At the time of writing this article, the Joao downloader was being distributed via the anime-themed MMORPG Grand Fantasia offered on gf.ignitgames[.]to.

Our research has shown that several other Aeria games have been misused in the same way in the past, however, their corresponding unofficial websites have either gone inactive or had the malicious downloads removed in the meantime.


ESET blocks the website serving Joao malware and has informed Aeria Games about the matter.


How does it work?

The affected games have been modified to run Joao’s main component – a malicious library mskdbe.dll, detected by ESET’s systems as Win32/Joao.A. When users run the game launcher, Joao is launched along with it. Upon launching, the Joao downloader first sends basic information about the infected computer – device name, OS version and information on user privileges – to the attacker’s server because the malware keeps its operations “silent” and since the game works as expected, there’s nothing suspicious about the whole infection process from the user’s point of view.


Figure 2: Joao downloader in the game’s installation folder

After the communication with the server has been established, server-side logic decides whether and which components will be sent to the victim’s computer. The Joao components we discovered during our research had backdoor, spying, and DDoS capabilities.


Has my computer been infected? How do I clean it?

Downloading lots of games from different sources and unsure if any of this applies to you? For a quick check of Joao’s presence on your computer, you can try running a search for “mskdbe.dll” – if the search returns a result, your computer has most likely been infected with the Joao malware. If no such file is found, it doesn’t automatically mean you haven’t crossed paths with the malware – the crooks can rename the file at any moment.

Compared to downloading and launching a legitimate Aeria game, the only visible difference is an extra .dll file in the game’s installation folder.  Therefore, it’s best to use a reliable security solution to detect the threat and remove it for you – you can also use ESET’s Free Online Scanner.


Additional information

ESET’s systems have detected Joao all around the world. The following map shows which countries have been most affected:



Link to comment
Share on other sites

  • Replies 0
  • Views 705
  • Created
  • Last Reply


This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...