Good evening everyone. Well, for the people who doubted whether the rumors about NBM were true or not, I share with you something that has been spread through a reputable Spanish-speaking group called Tiflojuegos. I say nothing, yet I say everything. What the fuck is this? A backdoor virus in an NBM game? Well. 4 years exposing these people, and now they have the definitive proof.
With this introduction, I'm not trying to disrespect anyone. It's simply a general message, and my indignation isn't directed at the community.
Thanks to x0 and their message, I realized that the beginning was a bit aggressive and quite inappropriate. However, it was just a general comment that I had written for other people who actually fit into this discussion because of how they reacted, but I simply hadn't edited the message earlier.
WHAT WAS LOOKED AT
This folder holds source code that was recovered (decompiled) from ln.exe, the Windows program for the online audio game Life in Nature, run by AudioWander and NBM Studios. The recovery tool's manifest says the exe had the SHA-256 fingerprint 3a1ea0c1edeffbf991f6cacf94ef8dcaa06b93057938d353986e41a7862bf8b3, was built with the NVGT game engine version 0.90.0-dev, and was compiled on 15 September 2026 on a computer set to Turkish time.
Every one of the 120 source files was read, including every command the game server can send to the game. The included browse.html page and the manifest were also checked. Nothing was run. No files in the folder were changed except for adding this report.
THE SHORT ANSWER
This is not a classic virus. I found no code that steals browser data, saved passwords from other programs, documents, Discord tokens or crypto wallets. It does not spread to other computers, does not mine crypto, and does not set itself to start with Windows.
However, the game contains a real backdoor. It also has several behaviours that are sneaky or harmful to the rest of your computer. The most important points are:
1. The game server can make your computer run any command it wants, silently.
2. The game hides a tracking ID in ten places on your computer plus the Windows registry. Several of these use fake names made to look like Microsoft, Microsoft Edge, DirectX and NVIDIA files, so the ID survives even if you uninstall the game.
3. It sends your Windows user name, computer name, install folder and hardware identifiers to the server.
4. It deletes files that belong to other programs.
5. It refuses to run inside a virtual machine, which is a common trick to make the program harder to inspect.
6. The connection to the game server is not encrypted, and in some situations your password is sent in plain text.
My overall judgement is to treat this as potentially unwanted software with a remote command backdoor. Do not run it on a computer you care about unless you fully trust whoever controls the game servers, and anyone who could impersonate them.
MOST SERIOUS FINDINGS
1. Remote command execution (backdoor). Severity: critical.
In functions_031.nvgt, around lines 538 and 552, there are two server commands, "batcode" and "restart". When the server sends either one, the game takes the rest of the message, saves it as a Windows batch file at %USERPROFILE%\temp.bat (normally C:\Users\YourName\temp.bat), and runs it through explorer.exe.
There is no prompt, no warning and no check of any kind. A batch file can do anything your Windows account can do: download and run other programs, delete files, change settings, and so on. The batch file is not deleted afterwards, so if it exists on your computer, it is evidence that this command was used.
Because the game connection is not encrypted (see point 7), the danger is not limited to the official server. Anyone who can sit between you and the server could also send this command. That includes the operator of any relay server you choose in the game, one of which is built in and located in Iran.
2. Collecting system information, probably through the backdoor. Severity: high.
Around line 525 of the same file there is a server command, "systeminfo". It reads a file called info.txt from your temp folder and sends its whole contents to the server along with your character name.
The game itself never creates info.txt. The only way within the game for that file to appear is a batch script sent through the backdoor above. This strongly suggests the two commands are meant to be used together: one command writes information about your computer into the file, and the next one collects it. That is an inference, but it is the only use the code allows for.
3. Hidden tracking ID disguised as system files. Severity: high.
In functions_032.nvgt, lines 173 to 470, the game makes a random 24-character ID and writes it to all of these places:
%APPDATA%\AudioWander\.lfsig
%APPDATA%\.lfsig
%APPDATA%\Microsoft_Sync_Telemetry.dat
%TEMP%\.lfsig
%TEMP%\dxcache.tmp
%LOCALAPPDATA%\.lfsig
%LOCALAPPDATA%\msedge_update_cache.bin
%USERPROFILE%\.lfsig
%PROGRAMDATA%\.lfsig
%PROGRAMDATA%\nvcache.dat
It also writes the ID to the registry at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTelemetryCache, as a value named MachineCacheId. That key is not a real Windows key; it is named to look like one.
Each time the game starts, if any single copy still exists, it rewrites all the others. The names Microsoft_Sync_Telemetry, msedge_update_cache, dxcache, nvcache and WinTelemetryCache are chosen to look like files from Microsoft, Edge, DirectX and NVIDIA, so people will not delete them. To reach the registry, the code calls Windows functions directly (RegGetValueA, RegCreateKeyExA, RegSetValueExA and VirtualAlloc) instead of using normal game engine features. The clear purpose is a ban-evasion tracker that survives uninstalling the game and deleting its folders.
4. Hardware and personal identifiers sent to the server. Severity: medium to high.
Each time you log in or create a character, the game sends a bundle of identifiers. It contains:
a hardware node ID from the engine (on Windows this usually comes from a network card's MAC address)
the hidden tracking ID described above
your Windows user name
the name of your audio output device
The code also has functions that read your Windows MachineGuid from the registry and the serial number of your C drive. The spots where these should be added to the bundle came out blank in the decompiled code, so it is not certain they are actually sent. It is clear they were meant to be.
Separately, every time you enter the game (functions_036.nvgt, line 359), it sends a "compinfo" message with your Windows user name, your computer name, and the full folder path of the game (which usually contains your real name or user name). The "newplayer" message also sends that path and an engine-generated computer fingerprint.
5. Deleting files that belong to other programs. Severity: medium.
While you are in the game, once every second (functions_015.nvgt, lines 361 to 372), it deletes every file ending in .dmp from your temp folder. These are crash dumps and memory dumps, and they can belong to any program, not just this game. This is an anti-analysis measure: it stops people saving a copy of the game's memory to study it. It also destroys other programs' crash reports. In many menus and dialogs, the game also deletes a file called lf.dmp from your temp folder every few milliseconds.
At startup, and then every 5 seconds while playing, it checks for a folder called "Cheat Engine" inside your temp folder. If it finds one, it deletes the whole folder and its contents and closes the game. At startup it also lists your Program Files folder, looking for folder names containing "cheat" or "engine". In the decompiled code the result of that scan is not used for anything.
At startup, the non-beta version also deletes a file called GameEngine.dll from the game folder.
6. Refuses to run in a virtual machine. Severity: medium.
At startup the game checks whether it is inside a virtual machine. If it is, it says "this game can not run in virtual machines" and quits. Virtual machines are what security researchers use to examine suspicious programs safely, so this makes the game harder to inspect. The check is an engine function whose inner workings are not visible in this source.
7. Unencrypted connection and plain-text password. Severity: medium to high.
The game talks to its server at nbmstudios.com (IP 5.9.25.153, port 10001) using the NVGT network system, and I found no encryption on it.
The login first tries a safer method that sends hashed values. But if the server does not answer within 3 seconds, the game automatically falls back to sending your user name and password in plain text, together with all the identifiers from point 4 (functions_024.nvgt, lines 455 to 457 and 363). A slow connection, a malicious relay, or anyone intercepting the traffic can trigger this fallback simply by holding back the server's reply.
One of the two account creation routes in the code also sends the password in plain text along with your email address. Even the hashed login values travel unencrypted, so anyone who captures them can try to guess the password offline.
8. Relay servers. Severity: medium.
The game can connect through relay servers instead of directly. One relay is built in, labelled "Iran relay 1", at 5.160.197.212 port 32000. More relays are downloaded from
https://audiowander.com/ln/relayservers.txt, and you can also type in any server yourself. A relay is only used if you choose it.
A relay operator can see all your traffic, including a plain-text password if the fallback in point 7 happens. A relay operator could also send the backdoor command from point 1. Just opening the server list connects to every listed relay to measure ping, which shows your IP address to each relay operator.
9. Automatic updates run downloaded programs without checking them. Severity: medium.
At startup the game checks
https://nbmstudios.com/ln/version.txt (or the same path on audiowander.com). If there is a newer version, it shows a message saying to press Enter to download, with no option to decline. It then downloads ln.exe, saves it as lntemp.exe and runs it. Nothing checks a digital signature or a hash of the downloaded program. The download uses HTTPS, which helps, but whoever controls those web servers decides what program runs on your computer.
There is a second update path: when the server sends a "newupdate" message and you answer yes, the game runs lfupdater.exe. There is also leftover code: after you change the sound output device in the settings, the game runs a program called lf.exe from its own folder, whatever that file happens to be, and then quits.
OTHER THINGS THE SERVER CAN MAKE THE GAME DO
Change your clipboard: the "clip" and "clipraw" commands replace your clipboard contents without asking. The game only reads your clipboard when you paste into it yourself, and never sends clipboard contents anywhere.
Delete your settings: the "deleteconfig" command deletes the folder %APPDATA%\nbm-studios, including everything in it, and closes the game.
Create hidden marker folders: the "testban" command creates two folders named "windows2" and "system" inside %APPDATA%, then shows "you have been kicked from the game" and quits. The names look like Windows folders. Nothing in the game reads them, so they are probably markers for something else to look for later.
Change your stored login: the "accountswitch", "newname" and "newpassword" commands replace the account name and password the game has saved.
Make the game send messages it did not write: the "echo", "echopacket", "sendcommand", "inv", "use", "itemtopla" and "usealt" commands make your game send back whatever text the server chooses. This means the server can make it look as if your client sent something.
Write language files: the "switchlang", "updatelang" and "langfileend" commands save a language file using a file name chosen by the server, without checking that name. A malicious server could use a name like ..\..\something to place a file outside the lang folder. The damage is limited: the name must end in .lng, cannot contain spaces, and the contents are scrambled before saving.
Other file and program actions:
"playerlog" writes a file called players.log in the game folder.
"update" relaunches the game.
"downloadsounds" opens
https://soz-games.tk/tk/sounds.dat in your web browser.
"openurl" opens a web page, but only if it starts with
https://audiowander.com/.
"storeopen" opens the AudioWander credit shop.
"killclient" closes the game.
"sapimessage" briefly saves a sound file with a random name in your temp folder, plays it and deletes it.
"upload" opens a menu of sound files from the game's upsounds folder; only the file you pick is sent.
"sndlen_q" asks the game how long certain game sounds are.
Pop-up prompts: commands such as "input", "repass", "addline", "editline" and "rename" open text boxes or password prompts at any moment, and send whatever you type. A text box opened by "input" can also be set to send its contents automatically, without you pressing Enter.
No server command turns on your microphone.
PRIVACY AND WEAK SECURITY (NOT MALICIOUS, BUT WORTH KNOWING)
Saved password: your account name and password are saved in %APPDATA%\AudioWander\config.dat. The file is encrypted, but the key is written in the program itself ("turkeyarepowerthanallcountryesAudioWander"), so anyone or any malware with a copy of the game can decrypt it. If you use the same password anywhere else, change it there.
Other keys built into the program: "regpacket32" and "bombedoclahoma1995" for the old license system, "voice_vol_key_123" for voice volume settings, and another fixed key for language files. The game proves it is the "original" client by sending the fixed text "iamoriginal1234567890", which anyone can copy.
Typing signals: while you are connected, every key you type in a game text box sends a small "typing sound" message to the server. This is on by default, and it includes in-game password change boxes. The letters are not sent, but the message does show when you type, how much, and whether each key was a space, a number or something else.
Old license code: there is leftover license code copied from another game called "The Killer" by IMS Productions, using the license server AudioWander.cf port 45530. Its "email this key" option sends your email address, name and license key over plain, unencrypted HTTP to
http://breaker-originals.tk/lf/mail.php, a free .tk domain that has nothing to do with the game's main websites. The same code sends your computer name when it checks a license. The client also contains license admin commands (generate, list, ban and delete keys); whether the server checks who is allowed to use them cannot be seen here.
Old outside domains: when the game cannot reach its server in some menus, it fetches a message from breaker-originals.tk over plain HTTP and reads it to you. Free .tk domains are often abandoned and taken over by strangers, and whoever holds that domain now can show you any text and see your IP address. Unused code also points at soz-games.tk, ims-productions.com and two bare IP addresses, 91.224.23.174 and 2.59.117.88.
Voice chat: the microphone is only opened when voice chat is turned on. The setting that allows it is on by default. In the default toggle mode you press V to start, and the microphone then stays live, even when the game window is in the background, until you press V again. In push-to-talk mode, which you get by pressing Shift+V, it only records while V is held. If voice chat was on when you got disconnected, it turns back on automatically when you reconnect. Audio only goes to the game server or relay you are connected to.
Macro detector: if you press the arrow keys, T or I more than 15 times in a row, faster than 50 milliseconds apart, at an extremely regular rhythm, the game quietly reports "cheatengine" to the server. A very steady key repeat could in theory trigger it.
Music boxes: in-game music boxes stream audio over plain HTTP from nbmstudios.com port 7790.
Server code upload: the source contains a developer menu that uploads a replacement copy of the whole server program over the game connection. It cannot be reached in the released exe. If the server does not check who sends that upload, that is a hole on their side.
FILES AND SETTINGS THE GAME CREATES OUTSIDE ITS OWN FOLDER
The hidden tracking ID files and registry value listed under finding 3.
%USERPROFILE%\temp.bat, only if the server has used the backdoor command.
%APPDATA%\AudioWander, which holds config.dat (your settings and saved password), motdhash.dat and a few small settings files.
%APPDATA%\windows2 and %APPDATA%\system, only if the "testban" command was received.
Short-lived sound files named sapiMsg_ followed by random characters in %TEMP%.
Inside the game folder it may also create lang, sounds, logs and upsounds folders; sounds.dat and related download files; sndver.txt; voice_volumes.dat; and, only if you turn the matching options on, buffers.sav (saved chat history in plain text) and a few debug logs.