Bypass Record
Masquerading × Easy Anti-Cheat (EAC)
A publicly-reported instance of Masquerading bypassing Easy Anti-Cheat (EAC), recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
The patch alters QEMU's emulated device data—renaming the QEMU keyboard to 'ASUS keyboard', spoofing SMBIOS fields (manufacturer, product, version), disabling the hypervisor CPUID bit, and modifying UEFI variables—to defeat VM detection checks used by anti-cheat and DRM/packer software. It does not mitigate timing side-channels like RDTSC.
Detection & mitigation
Monitor for anomalies in hardware identifiers (e.g., SMBIOS fields, device names) that deviate from known legitimate patterns, using endpoint telemetry or asset inventory comparisons. Mitigate by enforcing integrity checks on firmware and hardware configurations, and deploying behavior-based detection that does not rely solely on VM presence.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.