Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Hacking News

March 3rd, 2010, 15:05 GMT · By Catalin Cimpanu

Man-in-the-Middle Attacks Hit WoW Gamers

SHARE:

Adjust text size:


WoW gamers have their login credentials stolen
Enlarge picture
World of Warcraft users won't be happy to hear that hackers have managed to pull a man-in-the-middle attack on several servers hosted in Europe. This happened even with the extra security barriers added by the use of an external authenticator. The attack is suspected to have came from China or/and Malaysia.


The attack basically happened like this: while a regular user accessed a WoW-themed infected site on the web, they installed a trojan, named Malware.NSPack, thinking that they were installing a game add-on. That trojan would then go to install suspicious files on the user's computer (emcor.dll copied to ../users/username/appdata/Temp) and log all key strokes, sending back data related to WoW authentication credentials.

The data acquired was then employed by attackers to circumvent WoW's login system and empty the user's account of all of their in-game (“fake”) money. Subsequently, those sums can be transferred to other accounts, which then can be put up for sale and turn real profit for the hackers.

The keylogger trojans that infected the users were hosted on Chinese-based websites, were graphically cloned after the WoWMatrix website and advertised using Google AdWords service. The spoofed data was relayed using a server hosted in Malaysia. Websites reported by users as being attack sources are cursea.com, deadlybossmodss.com, gamesacca.com and wowmatrixf.com. The sites were taken down, along with the Google AdWords banner.

WoW tech admins were quick to reply and investigate, offering this answer within 24 hours of the first report, “After looking into this, it has been escalated, but it is a Man in the Middle attack. This is still perpetrated by key loggers, and no method is always 100% secure,“ trying to excuse the authenticator's failure in supplying full protection.

The attacks themselves don't differ very much from other man-in-the-middle hacks on banking sites, the only difference being that this latest target wasn't harboring real money like banks do, but fake in-game gold.

TELL US WHAT YOU THINK:

3,022 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Rogue PayPal SSL Certificate Available in the Wild

New Phishing Attack Features Live Chat

Man-in-the-Middle HTTPS Attack Weak Point in Major Browsers

Five Years Behind Bars for DarkMarket Founder

Research Highlights Top 25 Programming Errors

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM