Hackers spread malware via Call of Duty

Worm malware was discovered in the lobbies of Call of Duty: Modern Warefare 2

Add bookmark
A computer against a dark background parially lit by purple lights. The loading screen for Call of Duty: Modern Warfare is on the screen.

Malicious actors are using the player lobbies of Call of Duty: Modern Warfare 2 to spread self-replicating malware.

Players were alerted to the malware spread on July 26 via a post on gaming platform Steam. A user of the site made a post warning Call of Duty: Modern Warfare 2 players that hackers were “attack[ing] using hacked lobbies”. They suggested that players run antivirus software before playing.

Self-replicating malware, also known as worms, is a type of malicious program that is deployed with the aim of spreading it to more devices. Unlike other forms of malware, worms do not need a human or host program to run, which means it executes its programming itself once downloaded onto a device, allowing it to spread independently. 

By itself, a worm can impact devices in a number of ways, including taking up disk space and even deleting files in order to make more copies of itself. If the worm is equipped with a payload, this can allow the malicious actors to inflict even more damage.

In the same forum thread as the warning about the malware, one play analyzed the worm and found that it seemed to have been specifically coded for Call of Duty: Modern Warfare 2. Other players speculated as to the worm’s purpose, noting that its dynamic-link library (DLL), “seems to check for custom lobbies and prevent you from joining/hosting one”. Users also noted that the worm itself functioned via remote code execution (RCE), yet also prevented any RCE from being executed on its host.

The official Call of Duty Updates X (formerly Twitter) account posted about the malware, saying the game had been taken offline while the game’s producer Activision “investigate[s] reports of an issue”.

Learn more about malware with Cyber Security Hub’s Ultimate guide to malware. 


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended