What Game Hackers teach us about Offensive Security & Red Teaming

Joe 'Juno' Aurelio (Security Researcher)

DEF CON 33 · Day 1 · Main Stage

Overview

In this DEF CON talk, security researcher Joe 'Juno' Aurelio explores the intricate world of game hacking, drawing compelling parallels between the techniques employed by game cheats and those utilized in offensive security and red teaming operations. Aurelio, who specializes in mobile application security and has a background in malware analysis, argues that game hacking is far more than mere cheating; it is a sophisticated domain of reverse engineering, exploitation, and evasion that mirrors the challenges faced by cybersecurity professionals.

Watch on YouTube

Visual summary for What Game Hackers teach us about Offensive Security & Red Teaming by Joe 'Juno' Aurelio
Visual summary for What Game Hackers teach us about Offensive Security & Red Teaming by Joe 'Juno' Aurelio

Key moments

  1. 0:00 Introduction, speaker, and talk disclaimer
  2. 1:40 Defining game hacking: modding, speedrunning, cheating
  3. 2:20 Examples of common game cheats: wall hacks, aimbots
  4. 3:50 Cheat software vs. the crucial installation/evasion methods
  5. 4:10 Understanding internal versus external types of cheats
  6. 5:30 First malware parallel: Process migration techniques
  7. 6:10 Shared characteristics: Game cheats, malware, stealth, sophistication

What Game Hackers teach us about Offensive Security & Red Teaming

Speakers: Joe 'Juno' Aurelio, Security Researcher

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=zfhiZnjJLT4

Overview

In this DEF CON talk, security researcher Joe 'Juno' Aurelio explores the intricate world of game hacking, drawing compelling parallels between the techniques employed by game cheats and those utilized in offensive security and red teaming operations. Aurelio, who specializes in mobile application security and has a background in malware analysis, argues that game hacking is far more than mere cheating; it is a sophisticated domain of reverse engineering, exploitation, and evasion that mirrors the challenges faced by cybersecurity professionals.

The talk delves into the technical depth of various cheat mechanisms, from software-based process injection to advanced hardware-assisted memory access, and discusses the constant cat-and-mouse game between cheat developers and anti-cheat systems. By dissecting these methods, Aurelio reveals how the pursuit of an unfair advantage in gaming cultivates advanced skills and novel techniques that are directly applicable to understanding and countering real-world malware and attacker methodologies. This presentation is crucial for anyone interested in the bleeding edge of offensive security, as it highlights an often-overlooked arena where cutting-edge evasion and exploitation tactics are forged and refined.

Background

▶ Watch: Introduction, speaker, and talk disclaimer (0:00)

Game hacking, as defined by Aurelio, extends beyond simple cheating to encompass a broad range of activities including modding, speedrunning, and game preservation through reverse engineering. However, the core focus of this talk is on game cheating, particularly in competitive online games like Counter-Strike, Fortnite, and Escape from Tarkov, where even minor information advantages can dramatically alter gameplay outcomes. Cheats often manifest as wallhacks (also known as ESP or Extra Sensory Perception), which display enemy locations through obstacles, aim hacks that automatically adjust crosshairs, and radar hacks that provide map intelligence.

The fundamental challenge in game cheating, much like in malware development, lies not just in creating the cheat's functionality (e.g., a spin bot or an aimbot) but in the sophisticated methods used to load and run the cheat undetected. This constant evolution of evasion techniques against increasingly robust anti-cheat systems creates a rich environment for technical innovation. The speaker emphasizes that the stealth and anti-detection mechanisms are the truly difficult and rapidly changing aspects of game hacking, drawing a direct line to the continuous arms race in cybersecurity.

Key Findings

▶ Watch: Examples of common game cheats: wall hacks, aimbots (2:20)

Aurelio's central thesis is that game hacking and offensive security are "two different sides of the same coin," sharing fundamental goals, techniques, and evolutionary pressures. The key findings revolve around several core parallels:

  1. Shared Technical Methodologies: Both game cheats and malware extensively use similar low-level Windows APIs and system-level manipulation techniques, such as process injection, memory reading/writing, and obfuscation. These are often legitimate operating system functions that are abused for malicious or unauthorized purposes.
  2. Stealth and Evasion as Primary Goals: The success of both a game cheat and a piece of malware hinges on its ability to remain undetected by defensive mechanisms. This drives the development of sophisticated anti-analysis, anti-debugging, and anti-forensics techniques in both domains.
  3. Sophistication and Evolution: The ongoing cat-and-mouse game between attackers (cheaters/malware developers) and defenders (anti-cheat/EDR developers) forces continuous innovation. Techniques become increasingly advanced, layering obfuscation and combining various undocumented API calls to achieve unique and stealthy execution.
  4. Profit-Driven Innovation: Aurelio highlights that both game cheating and malware development are often profit-motivated industries. Cheat developers sell subscriptions to their products, and the immense financial incentives drive them to invest heavily in R&D for new evasion techniques, often with more resources and motivation than game developers themselves. This financial incentive accelerates the development of novel offensive techniques that can then cross-pollinate into general offensive security.
  5. Information Exchange and Learning: Game hacking forums and communities, despite their illicit nature, often contain well-documented examples and discussions of advanced system interaction. Aurelio suggests these resources can be valuable learning grounds for red teamers and offensive security professionals seeking to understand Windows APIs and low-level system behavior.

Technical Deep Dive

▶ Watch: Cheat software vs. the crucial installation/evasion methods (3:50)

The technical depth of game hacking reveals a striking resemblance to advanced malware and offensive security techniques, primarily categorized into internal and external cheats.

Internal Cheats

Internal cheats are designed to load their code directly into the target game's process, effectively becoming an integral part of the game's execution while it runs. This approach is akin to process injection or DLL injection, a common malware technique where malicious code is inserted into a legitimate, running process to evade detection and maintain persistence.

The lifecycle of an internal cheat typically involves two components:

  1. The Cheat Loader: This is a separate piece of software responsible for injecting the cheat's code into the game process.
  2. The Cheat Payload: This is the actual code containing the hacks (e.g., aimbot, wallhack logic).

Once the cheat loader successfully injects the payload, the loader process can terminate, leaving the cheat running stealthily within the game's memory space. This technique directly mirrors process migration in malware, where an attacker moves their malicious code from an initial, potentially unstable or suspicious process (e.g., an exploited web server process) into a more stable, long-running, and seemingly legitimate process (e.g., a system service). The goal in both scenarios is identical: to hide under the guise of an existing, trusted process, making detection significantly harder for anti-malware or anti-cheat solutions.

Characteristics shared with advanced malware include:

  • Stealth: The primary objective is to avoid detection by anti-cheat engines, much like malware aims to evade Endpoint Detection and Response (EDR) systems.
  • Technical Sophistication: Both fields involve a continuous cat-and-mouse game, leading to increasingly complex techniques. This includes leveraging undocumented APIs, combining multiple evasion strategies, and employing intricate obfuscation to hide code logic and execution paths.
  • Anti-Analysis Measures: Cheat developers, like malware authors, implement anti-debugging and anti-analysis techniques to prevent reverse engineers (whether game developers or security researchers) from understanding how their products work. This protects their intellectual property and prolongs the efficacy of their cheats.

External Cheats

External cheats operate as separate entities from the game process, interacting indirectly with the game's memory or inputs. Aurelio divides these into software-based and hardware-based approaches.

Software-Based External Cheats

These cheats run as a distinct process and interact with the game by reading and writing to its memory space. A common example is Cheat Engine, which allows users to scan for and modify in-game values. This method uses standard Windows APIs like OpenProcess, ReadProcessMemory, and WriteProcessMemory—functions that are provided by the operating system for legitimate purposes but are frequently abused by both cheats and malware.

Aurelio draws a direct comparison to Mimikatz, a well-known red teaming tool. Mimikatz operates externally to the Local Security Authority Subsystem Service (LSASS) process on Windows, reading its memory to extract passwords and credentials. While Microsoft has implemented protections to secure critical system processes like LSASS from direct external memory access, these protections often don't extend to game processes, or can be bypassed. EDR and anti-malware solutions actively monitor the abuse of these Windows APIs to detect malicious activity, highlighting the shared detection challenges.

Hardware-Based External Cheats (Direct Memory Access - DMA)

This represents the pinnacle of anti-detection for game cheats due to its extreme stealth and the difficulty of software-based detection. Direct Memory Access (DMA) cheats utilize specialized hardware devices to bypass the operating system entirely and directly access the main system memory.

A prime example is a PCIe device like the Screaming Squirrel. This card plugs into a PCIe slot on the target gaming PC, often disguised as a legitimate device (e.g., Wi-Fi card, Bluetooth adapter). An external "attack" computer then connects to this PCIe device, gaining direct, raw access to the gaming PC's RAM. From the perspective of the gaming PC, the hardware device appears benign, making software-based detection nearly impossible.

Implementing hacks with DMA involves several sophisticated steps:

  1. Memory Reading: The external computer reads the game's memory via the DMA device to identify player locations, item spawns, and other critical game state information. This requires extensive reverse engineering of the game's memory structures.
  2. Visual Overlay (Fuser): To display information like wallhacks (ESP), a video fuser is employed. The video output from the gaming PC's graphics card is routed through the fuser. Simultaneously, the external cheat computer generates a separate video feed (e.g., outlines of enemies on a black background) based on the memory data it reads. The fuser then combines these two video streams in real-time before sending the composite image to the player's monitor. Crucially, the gaming PC itself only ever outputs a clean, legitimate video feed, making the visual overlay undetectable by recording software or anti-cheat programs running on the gaming machine.
  3. Input Manipulation: For aim assistance, a hardware device is placed between the player's mouse and the gaming PC. This device intercepts mouse inputs, applies subtle corrections based on the external cheat's calculations (e.g., adjusting for recoil or snapping to a target), and then passes the modified input to the gaming PC. Again, the gaming PC only sees legitimate mouse input from a standard device, making detection extremely challenging.

The fundamental reason DMA cheats are so hard to detect is that the malicious activity occurs entirely outside the monitored environment of the gaming PC's operating system and software. The physical access to the machine, much like in an advanced persistent threat scenario, grants the attacker unparalleled control and stealth.

Demo / Proof of Concept

▶ Watch: First malware parallel: Process migration techniques (5:30)

While Joe Aurelio's talk does not feature a live, interactive coding demonstration, he effectively illustrates the concepts through visual aids and detailed technical diagrams. He presents screenshots of various game cheats in action, such as Counter-Strike wallhacks displaying enemy outlines through walls, and Fortnite and Escape from Tarkov cheats showing similar visual enhancements. These screenshots serve as concrete examples of the visual output and functional capabilities of the cheats being discussed.

Furthermore, Aurelio uses comprehensive diagrams to explain the architectures of both internal and external cheats. For internal cheats, he depicts the flow of a "cheat loader" injecting code into a "game process," drawing direct comparisons to process migration in malware. For external cheats, particularly the hardware-based DMA methods, detailed diagrams illustrate the setup involving a Screaming Squirrel PCIe device, an external "attack" computer, a video fuser for overlaying cheat visuals, and a hardware device for mouse input correction. These visual representations effectively demonstrate the complex technical mechanisms and their operational stealth, serving as a conceptual proof of how such systems function and evade detection.

Defensive Implications

▶ Watch: Shared characteristics: Game cheats, malware, stealth, sophistication (6:10)

The insights from game hacking offer crucial lessons for defensive security, particularly regarding the challenges of detecting sophisticated threats and the limitations of software-only defenses.

  1. Kernel-Level Anti-Cheat and EDRs: The talk highlights the necessity of kernel-level anti-cheat solutions. Just as EDRs operate at a deep system level to detect advanced malware, anti-cheat systems often require kernel privileges to effectively monitor game processes, detect injection attempts, and prevent memory manipulation. However, this raises significant privacy and trust concerns, as kernel-level access grants the anti-cheat system full control over the user's computer. Aurelio himself notes that he uses a dedicated gaming PC to mitigate these risks.
  2. Secure Boot: The discussion on preventing kernel-level cheats points to Secure Boot as a potential defense. By enforcing a chain of trust from the BIOS to the operating system and subsequently to the anti-cheat driver, Secure Boot ensures that no unauthorized or malicious code can load before the anti-cheat, thus preventing rootkit-like cheat loaders.
  3. Challenges of Hardware Cheats (DMA): DMA-based cheats pose the most significant detection challenge. Since the malicious activity occurs outside the gaming PC's software environment, traditional anti-cheat measures are ineffective. Detection strategies must shift towards:
  • Physical Inspection: Detecting the presence of anomalous PCIe cards or external hardware devices.
  • Behavioral Analysis (AI): Developing AI and machine learning models to identify highly anomalous player movements or aiming patterns that are statistically impossible for a human, even a professional. This is an active area of research but is complex to implement without false positives.
  • HDMI/Display Monitoring: As raised in the Q&A, leveraging protocols like HDCP (High-bandwidth Digital Content Protection) or monitoring display device IDs might offer limited avenues for detecting video fusser devices, though this is not a comprehensive solution.
  1. Resource Disparity: Game developers often face a significant resource and motivation disparity against cheaters. Cheating is a multi-billion dollar industry, with highly organized rings making vast profits from selling subscriptions to cheats. This financial incentive drives continuous innovation in offensive techniques, often outpacing the defensive capabilities of game companies, especially smaller ones.
  2. Jurisdictional Challenges: The global nature of the internet means cheat developers can operate from jurisdictions where legal enforcement is difficult or non-existent. This makes it challenging for game companies, often based in Western countries, to pursue legal action against cheat creators worldwide. This mirrors the global challenge of combating cybercrime and malware operations.
  3. Cloud Gaming as a Solution: Aurelio suggests that cloud gaming services like GeForce Now or Stadia (though Stadia is defunct) could offer a more secure competitive environment. By removing physical access to the game's execution environment and centralizing it on a remote, controlled server, the avenues for client-side cheating (both software and hardware) are drastically reduced, albeit at the cost of potential latency.

Key Takeaways

  • Game hacking is a sophisticated field that extends far beyond simple in-game exploits, encompassing advanced reverse engineering, process manipulation, and hardware-level exploitation.
  • Offensive security and game hacking share core methodologies, with techniques like process injection, memory manipulation, and anti-analysis measures being common to both malware and game cheats.
  • Stealth and evasion are paramount for both game cheats and malware, driving a continuous "cat-and-mouse" game that fosters rapid innovation in offensive techniques.
  • Hardware-assisted cheats (DMA), utilizing devices like PCIe cards and video fusers, represent an extremely challenging frontier for detection due to their ability to bypass software-based anti-cheat systems entirely.
  • The profit motive of cheat developers fuels a multi-billion dollar industry, often providing more resources and incentive for offensive R&D than many game developers can muster for defense.
  • Learning from game hacking can provide offensive security professionals and red teamers with valuable insights into low-level system interaction, undocumented APIs, and advanced evasion techniques that may cross-pollinate into general cybersecurity threats.

About the Speaker(s)

Joe 'Juno' Aurelio is a security researcher whose day job primarily focuses on mobile application security. His background includes diverse experiences in application security, API security, and backend security. Notably, he worked in a malware lab during college, which provided him with foundational experience in understanding malicious software and its evasion techniques. This background informs his unique perspective on the parallels between game hacking and offensive security. Aurelio also expresses a personal enjoyment for competitive gaming played legitimately, highlighting his perspective that while cheating is unfair, the technical ingenuity behind it is undeniably fascinating.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent survey talk that maps game-hacking tradecraft — DLL injection, DMA cheats, video fusers — onto offensive security and red teaming concepts. The parallels are real and the technical grounding is solid, but this is fundamentally a conceptual bridge-building exercise rather than original research, and the audience most likely to be wowed is mid-level practitioners who haven't already spent time in game-hacking forums.

Heather Calloway (CISO) — WEAK

Technically competent survey of game hacking mechanics with a legitimate conceptual parallel to offensive security — but it stops at the parallel. There is no governance angle, no institutional accountability, and no usable decision path for defenders or leaders operating in the real world.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33