VIA Root
VIARoot Security News Security alerts Business IT security Services Security Tools About VIARoot
44 million stolen online games credentials
Search
Security News
security
Mathew J. Schwartz, InformationWeek
2010-08-27 14:11:17
Email and peer-to-peer networks also rank as significant venues for malware attacks, which have increased slightly in the U.S. but declined in Europe, according to Panda Security.
intel
Hugo Jean, Heptacube Inc.
2010-08-24 14:51:53
The motivation behind the $7.68 billion deal is unclear, but Intel says it wants to integrate computer security into its hardware.
IT Directory
Wiseleap Solutions Inc.
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
IT Ration Consulting Inc.
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]
HumanWare
Empowering People Focused on enhancing the lives of people with visual and learning disabilities, HumanWare provide [...]
By Hugo Jean, Heptacube Inc.
symantec
2010-06-01 14:44:42

Security firm Symantec has discovered a single server that holds the log-in credentials for 44 million online game accounts. What is impressive is not only the sheer amount of compromised game accounts, but also the way they are being gathered and verified by the ones controlling the server.

The stealing of online accounts, for games or others, is certainly not a new thing. With the use of keyloggers or other malware, it is not complicated for a person to obtain the log-in credentials of users. In this case, however, automated tools are being used to gather the credentials from vulnerable computers. The Trojan known as Infostealer.Gampass is being distributed to computers of targeted games' users.

This Trojan is mostly used for harvesting registration keys and account information for Massively Multiplayer Online Role-Playing Games (MMORPG). The games in question must be installed on the target computer in order for the Trojan to release its payload. It is often distributed as game "add-ons" or on online forums. When it is installed, it logs all user-entered account information and sends these credentials to the hacker.

At that point, the hacker can use the account information to log in to the account and do whatever he wants with it, usually gaining some profit. But in the case examined by Symantec, the strategy is much more elaborate than a single hacker doing some wrong with an illegally-accessed game account; the person or group behind this is obviously aiming for resale (which is usually made illegal by the games' EULA) of the accounts. But for that, they have to make sure the information they have gathered is valid.

Another Trojan horse, Trojan.Loginck, is distributed through a botnet by the hackers and validates the credentials by trying to log-in to the accounts. This strategy mitigates the problem of an IP address being blocked by the game provider after too many failed log-in attempts.

The scheme looks like it is quite effective so far and according to a research by Symantec, credentials could be worth up to $28,000 for an account with "several powerful characters". Prices are estimates based on asking prices by account sellers on specialized Web sites. The most affected game publisher is Chinese Web site Wayi Entertainment, with around 16 million compromised accounts. PlayNC, a service provided by NCsoft (publisher of games such as Lineage II, Guilwars and City of Heroes), is second with around 2 million compromised accounts. The popular World of Warcraft has only some 210,000 accounts in the database.

Symantec recommends to update anti-virus definitions and to change your account password as an added precaution if you have an account with one of the affected games.










Tags
botnet MMORPG Symantec Trojan