Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

June 21st, 2012, 09:30 GMT · By

Experts Confronted by Malware Developer While Researching Diablo III Keylogger

SHARE:

Adjust text size:

Hacker talks to researchers while they were analyzing his creation
Enlarge picture
While attempting to study the keyloggers suspected of stealing the accounts of Diablo III players, an AVG researcher was actually confronted, in real time, by the developer of a malware.

It all started with a forum topic called “How to farm Izual in Inferno” that allegedly pointed to a video in which the method was demonstrated.

The so-called video was actually a RAR archive that contained a couple of executable files: one bearing a .txt icon and the other one a Windows Media Player icon.

Once executed, the malicious element attempted to connect to a remote server and download a new file.

While debugging the malware, a chat dialog popped up with the message “What are you doing? Why are you researching my Trojan? What do you want from it?”

“The dialog is not from any software installed in our virtual machine. On the contrary, it’s an integrated function of the backdoor and the message is sent from the hacker who wrote the Trojan. Amazing, isn’t it? It seems that the hacker was online and he realized that we were debugging his baby,” AVG’s Hynek Blinka explained.

From the discussion the experts learned that the malware’s mastermind could actually gain access to their screen, mouse, processes, modules and even the webcam.

The attempt to dupe the cybercriminal into thinking that they were potential buyers failed, so he remotely shut down their computer.

The conclusion of the research is that this particular Trojan, BackDoor.Generic, even though it’s advertised as something for Diablo III, isn’t actually a game keylogger, but a malware designed to steal dial-up connection usernames and passwords.

For regular users the advice is obvious: steer clear of shady content served via untrusted forums. For experts: watch out, because you never know when you might be confronted by a cybercriminal.


1,762 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Prepare Your Vulnerabilities, Exodus Has Launched Its Intelligence Program

Researcher Explains Why Scammers Say They Are from Nigeria

Money Should Be Spent on Internet Policing, Not Antiviruses, Researchers Say

Exodus Intelligence to Launch Vulnerability Research Acquisition Program

Fujitsu Shows Pairing-Based Cryptography System Is Vulnerable

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM