The main infection source of the recent anti-authenticator keylogger/trojan appears to have been shut down. The main places of infection - the fake site wowmatrixf._com and other associated fake addon sites, including cursea._com and deadlybossmodss._com - are no longer online. (Victims were lured to these fake sites via Google advertisements)
We can breathe a sigh of relief but don't become complacent. This trojan/keylogger is likely to spring up somewhere else. Be cautious of what you download and execute from any web site. Addons should not require an installer package to execute. Be very suspicious of anything that asks you to "run a program". Follow our 10 Easy Steps to increase protection.
If you notice that these fake sites pop up in another spot then let us know.
Monday, March 1, 2010
Sunday, February 28, 2010
Authenticator hack - is your account still safe?
The big security news of the weekend is that Blizzard has confirmed a man-in-the-middle attack that is being used to hack accounts that are using an authenticator.Let me state up front that this is not a reason to throw your authenticator away nor should it be an excuse for not getting one. The authenticator is a very sound device - but it is, and will always be, just one of many security mechanisms that you should use to help secure your account. It is what us IT security guys call "layered security" - more on this in a moment.
The attack itself requires a keylogger/trojan. The keylogger, once installed on your system, logs your game user name, password AND authenticator code. It proceeds to post this information off to a rogue server so that the attacker can use this information in near real-time to access your game account. In the meantime, it sends an incorrect code to the battle.net authentication server from your machine - resulting in an "incorrect login" type message from the game. It does this so that you don't consume the one-time-use code that the authenticator provides.
Now it was only a matter of time before we saw this kind of attack. More and more people have been using authenticators. In a survey of over 90 gamers at securingwow.blogspot.com, 84% of them claim to have an authenticator attached to their game account. This tells us that more and more people are now running with an authenticator - reducing the pool size of "easy" victims.
The bad guys are now being forced to step up the sophistication of their attacks and have started targeting those with authenticators. We are bound to see many more keyloggers with this capability in the near future. Additionally, phishing attacks will also begin to operate in the same fashion - asking you to type in your authentication code, along with your other game account details, posting the info off to the attacker - who uses them in real time - leaving you with a "system unavailable" message and a soon-to-be-stripped game account. If we don't have these mechanisms in WoW phishing sites already then I can assure you that they are not far away.
So how do you prevent it from happening? It all comes down to minimizing the chance of being infected with a keylogger in the first place. One of the many tenets of IT Security is that "no sercurity system is 100% effective". Anyone that tells you otherwise does not know what they are preaching or they are trying to sell you some snake-oil. In this case, we can't rely on authenticators to be the only defense mechansim - here are ten simple steps you can do to reduce the chance of your game account being compromised:
- Don't share your game password with anyone and pick a password that is not easily guessed
- Don't use the same password for subscribing to fan sites
- Keep your operating system, browser and other software (especially Adobe Flash) fully patched - start with Windows Update
- Run a reputable antivirus product, preferably a full internet security suite with a firewall and keystroke encryption
- Don't click on email attachments, especially when you don't know the sender
- Don't download and run executable files from web pages
- Don't enter your game password into any web site other than the official game sites
- Don't enter your game password to a legitimate Blizzard web site from a PC that may be compromised
- Be very suspicious if an addon requires some form of install package to be run
- Invest in a Blizzard authenticator or install the Battlenet authenticator application on your phone
In this specific case, the keylogger was reportedly delivered via a fake site for the Wowmatrix addon manager. The site was created to look and feel like wowmatrix.com but, instead of downloading and installing the addon manager, the keylogger was installed instead. Our recommendations #6 and #9 talk about being "very suspicious" of add-ons that require an installer to run and avoid running executable files from web sites.
The bottom line is that keyloggers and phishing sites are here to stay. Don't rely on your authenticator to protect you 100% of the time - but don't throw it out either. It still forms a very strong part of your layered defense against the bad guys.
Post a comment - we would like to hear from you if you have fallen victim to this attack.
Friday, February 12, 2010
Adobe Flash Vulnerability Fix
Adobe has released a patch for the latest Flash vulnerability. Adobe Flash is used by the majority of browsers to display dynamic content on web pages. This vulnerability can potentially lead to automatic keylogger downloads by visiting a web site that has a specially crafted flash file embedded in its pages. This is known as a 'drive-by download' - one in which malware can be downloaded and installed without you knowing.While I am yet to see this specific vulnerability exploited, it is only a matter of time before it is. I have seen previous Flash vulnerabilities exploited to download keyloggers from popular WoW fan sites.
So - play it safe - visit the official Adobe Flash download site and update your flash player.
Be sure to visit our 10 Easy Steps page to further protect your WoW account.
Labels:
adobe,
drive-by,
flash,
keylogger,
vulnerability
Friday, January 29, 2010
Blizzard Launches Battle.Net Security Site
The specifically provide:
- A Security Checklist - covering preventative measures that you should be taking
- Type of Account Thefts - listing the common methods used to hack accounts
- Advice on what to do if you get hacked
As always, having a Blizzard Authenticator is one of the best methods of hack prevention.
Labels:
account,
account theft,
battle.net,
blizzard,
hacked,
security,
security checklist
Friday, January 15, 2010
The Armory Phishing Scam
The new and improved wowarmory has brought with it opportunity for scammers seeking to trick you into disclosing your wow game passwords. Check out the full coverage at wow.com on this latest scam:
http://www.wow.com/2010/01/15/beware-of-wow-armory-phishing-scams/
As always, never enter your game username/password into a site that is not "blizzard.com" or "worldofwarcraft.com" and get yourself an authenticator today!
If you have had a close encounter with a wow phishing scam then post and comment and let us know about it.
http://www.wow.com/2010/01/15/beware-of-wow-armory-phishing-scams/
As always, never enter your game username/password into a site that is not "blizzard.com" or "worldofwarcraft.com" and get yourself an authenticator today!
If you have had a close encounter with a wow phishing scam then post and comment and let us know about it.
Tuesday, January 12, 2010
Beware of Cataclysm Phishing Scams
With the recent announcement of the Catalysm alpha, users are warned not to fall victim to phishing scams.Be aware that if you receive an email inviting you to join the Cataclysm testing cycle then it will most likely be a scam. Cataclysm open beta does not exist as yet.
Do not enter your game username and password into any sites that may link from any email claiming to be an official Blizzard invite to Cataclysm.
If you see a Cataclysm phishing scam then feel free to share your comments on it.
Friday, December 11, 2009
Latest phishing scam
The latest phishing scam is an email titled "Battle.net Account – Password Change Notice" telling you that your password has been changed and if you did not make the change then you should visit the blizzard FAQ at a URL of:
http_://www.worldofwarcrarrft.net/
Spot the scam? I hope so (emphasis added).
This is a traditional wow phishing scam.
http_://www.worldofwarcrarrft.net/
Spot the scam? I hope so (emphasis added).
This is a traditional wow phishing scam.
Subscribe to:
Posts (Atom)