COMMENTARY: Here’s the problem MSPs run into all the time: the damage often happens before a device is ever managed. Gaming mods, cracked software, and “free” tools aren’t edge cases. They’re normal on personal devices that also hold work logins. Attackers don’t need to break in anymore. They wait for users to bring compromised identities with them. That’s why security has to start with identity, not just endpoints. If credentials and sessions are already exposed, fixing things after onboarding only goes so far.
Gaming is now the single largest malware trap on the internet. Research released in November finds that gaming-related files drive 41.47% of malware infections, and much of it lands on the same personal devices people use to access work accounts.With the surge in BYOD schemes and personal device use in the office, it’s a pattern that’s showing up extensively. Verizon’s 2025 DBIR notes that nearly half of the systems tied to compromised corporate accounts were personal or otherwise unmanaged devices. In practice, that means many company logins now reside in places with little oversight. MSPs then inherit users whose credentials and session data have already been exposed, often long before those devices enter a managed environment.Infostealers are driving widespread identity exposure across the board. The first half of 2025 saw an 800% increase in credential theft via infostealers. That scale alone means MSPs will increasingly encounter clients whose logins were compromised before any formal management.MSPs and IT professionals must consider where attackers have shifted their focus and update their playbooks accordingly.When nearly half of all infections originate from gaming files, and another third from cracked creative tools, it’s a strong indicator that many employees are unintentionally picking up malware. MSPs and IT professionals must account for this and take extra precautions to reduce risk. Pre-onboarding checks for infostealer exposure, compromised credentials, and risky session data are becoming as important as endpoint policies. User education must also evolve to warn clients about these types of attacks.Activation bypasses promise to unlock paid or licensed software like WinRAR, Microsoft Office, or Windows for free. The infection isn’t coming from the software itself; it’s coming from the attempt to avoid licensing it.MSPs should assume users’ off-hours behaviors create persistent credential exposure, and their policies and risk models must account for the economic incentives driving unsafe downloads. They can do this by shifting security controls to where the risk originates, such as identity, browser data, and unmanaged devices. Some practical steps include:We’re in an era of logging in, not hacking in. Attackers have moved away from exploiting software vulnerabilities and toward a more lucrative path: targeting the tools and games people rely on while exploiting economic gaps and community trust. IT professionals and MSPs who adopt pre-enrollment infostealer scanning, treat every new endpoint as potentially compromised, and add identity-theft management to their stack will reduce liability and strengthen compliance. They’re effectively keeping pre-infected identities out of the tenant before those risks become a larger problem.
MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].
Cultural Engineering
The gaming world, where “cracked” versions and free add-ons are normalized, has become an ideal ecosystem for spreading malware under the radar. That includes payloads hidden in cheats, modifications, aimbots, and skin changers. Unofficial mods and cheats for Grand Theft Auto, Roblox, Valorant, Counter-Strike: Global Offensive, and Fortnite were the top five sources of gaming-related infections, according to the November study.Also rising sharply were infections tied to “free” versions of expensive creative software. Users are voluntarily downloading what they believe are benign tools from Discord servers, creator forums, modding communities, GitHub clones, and YouTube tutorial descriptions.Since these circles trade files constantly and rely on word of mouth more than formal vetting, it’s easy for bad actors to blend in. They use months-old accounts or cloned identities with good reputation scores to appear reliable. Imitating trusted users in a space where everyone is used to downloading unofficial add-ons means a malicious one doesn’t stand out, allowing hackers to weaponize that trust. When a downloaded “mod menu” doesn’t work, users typically assume it’s faulty and move on to find another one, rather than suspecting a malware infection.Key statistics in the report illustrate the spaces hackers are targeting most:- 41.47% of all infections were from gaming-related files.
- Over 50% of gaming-specific infections came from mods, cheats, mod menus, and aimbots.
- Creative communities also show high exposure: 32.72% of infections came from cracked creative tools.
The Affordability Gap
The common thread behind luring employees with games, creative tools, and system utilities is economic pressure. Unlicensed software was worth an estimated $18.7 billion in new license revenue opportunities, according to the most recent BSA Global Software Survey. Attackers are positioning malware not as a technical threat, but as a “solution” to a financial problem by offering free creative tools and game enhancements.The November report found:- 17.65% of all infections involved cracked or pirated software, making it the single largest lure category across the dataset.
- Even tools designed to protect users, such as antivirus programs and VPNs, were turned against them: over a quarter (25.86%) of Privacy & Security infections involved a “cracked” version of the targeted software.
- For Essential and System & Utility software, infections were driven by activation bypasses (29.25% and 26.13%, respectively).
- Treat identity as contaminated until proven otherwise. When onboarding a user or device, assume saved passwords, session tokens, and OAuth grants may already be compromised. Pre-enrollment infostealer exposure checks can be run the same way MSPs run EDR scans.
- Include unmanaged-device patterns in threat modeling. Many users install cracked tools, game mods, and “free” utilities at home. Those same devices sync corporate logins through browsers and password managers. MSP policies should model this as a predictable, recurring exposure rather than an anomaly.
- Add economic-risk indicators to the policy framework. If a user’s role requires expensive creative or productivity software, MSPs should assume they may be tempted by free alternatives at home. Browser sync restrictions and session-token hygiene can help build controls around that reality. For example, enforcing regular session resets and token rotation ensures a stolen cookie from a personal device becomes useless.




