Flight Simulator expansion installed password-stealing malware as DRM

There have been some pretty heavy-handed DRM schemes cooked up over the years, but off the top of my head I can't think of any sketchier than the one built into FSLabs' A320-X expansion for Microsoft Flight Simulator X. As noted recently on Reddit, the installer includes a "Chrome Password Dump" tool that can be used to surreptitiously swipe usernames and passwords. It's the sort of thing that sounds like it has to be a mistake, but FSLabs founder Lefteris Kalamaras confirmed in the company's forums that it's meant to be there. 

Kalamaras denied that the software "indiscriminately" dumps Chrome passwords, saying that "there are no tools used to reveal any sensitive information of any customer who has legitimately purchased our products." He explained that it's actually being used to alert the company when the expansion is installed using serial numbers known to be pirated. 

"'Test.exe' is part of the DRM and is only targeted against specific pirate copies of copyrighted software obtained illegally. That program is only extracted temporarily and is never under any circumstances used in legitimate copies of the product," he wrote. "The only reason why this file would be detected after the installation completes is only if it was used with a pirate serial number (not blacklisted numbers)." 

That assessment was largely confirmed in an analysis by cybersecurity firm Fidus Information Security. "Whilst a lot of information is provided, it does not include any references to the password dumping tool," it wrote. "We can conclude the password dumping tool (test.exe) is only called when a fraudulent serial is used." 

Nonetheless, Fidus pointed out a few "serious issues" involved in the scheme, including questions about the security of stored data, why the information is being sent over HTTP when it's only encoded with B64, and of course whether or not it's actually legal to do this in the first place. 

"The inclusion of a malware, in the form of a password dumper, in a trusted installer for the sake of combating piracy is absolute insanity," Andrew Mabbitt, founder of Fidus Information Security, told Motherboard. "When run, the program extracts all saved usernames and passwords from the Chrome browser and appears to send them to FSLabs. This is by far one of the most extreme, and bizarre, methods of Digital Rights Management (DRM) we've ever seen." 

Kalamaras said FSLabs would be happy to provide more information about the system to anyone who wants it, and added that it has already provided information that will be used in legal action against pirates. Nonetheless, the studio has now released an updated installer without the malware component, although Kalamaras insisted in a followup statement that there was nothing untoward about its presence. 

"While the majority of our customers understand that the fight against piracy is a difficult and ongoing battle that sometimes requires drastic measures, we realize that a few of you were uncomfortable with this particular method which might be considered to be a bit heavy handed on our part," he wrote. "It is for this reason we have uploaded an updated installer that does not include the DRM check file in question." 

The clean installer is available here.

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Latest in Sim
An ancient, angry stone mech from No Man's Sky's new Relics update
No Man’s Sky lets you unearth ancient, angry mechs in the astro-archaeology filled Relics update
Dwarf Fortress adventure mode art
After 23 years of making Dwarf Fortress, even its creator is still 'terrified' of drowning all his dwarves with aquifers: 'Part of the problem is we are just not good at videogames'
Tarn Adams, who cofounded Bay 12 Games with his brother Zach, talks about their single-player simulation game "Dwarf Fortress" during an interview at their home office in Poulsbo, Washington, west of Seattle, on December 9, 2022. - A cult favorite among indie game fans, "Dwarf Fortress" has been available for purchase on the Steam online store since December 6, a first for this title that has been distributed for free since its debut in 2006. The real-time management game, set in a medieval-fantasy world and involving overseeing a group of dwarves seeking to build a mighty fortress, has climbed to the fourth best-selling weekly title on Steam. (Photo by Jason Redmond / AFP) (Photo by JASON REDMOND/AFP via Getty Images)
Dwarf Fortress' creator is so tired of hearing about AI: 'Press a button and it writes a really sh*tty, wrong essay about something—and they still take your job'
Decorations in TCG Card Shop Simulator
TCG Card Shop Simulator finally adds the ability to decorate our stores, and suddenly all my profits are being spent on adorable Pigni posters
A person on a snowmobile riding a track in the forest in game Sledders.
Powder enthusiasts seem pretty pleased with new physics-based realistic snowmobile sim Sledders
Dean Hall at GDC 2025.
Outer space inspired DayZ's Dean Hall to become a modder and game developer, and now he's making a Kerbal successor called Kitten Space Agency
Latest in News
An Enshrouded player in a recreation of Erebor from The Lord of the Rings
Kings under the Mountain! 33 Enshrouded players spent 10,000 hours to recreate this iconic location from The Lord of the Rings
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened