Gamers Seek Beta Versions, Download Malware Instead
Tracking the increasingly common use of PC games as an infection vector, researchers at the Microsoft Malware Protection Center (MMPC) discovered a couple of malicious programs making the rounds on torrent and file sharing sites.
Social engineers are disguising their malware by labeling it as the beta-versions of unreleased games or upgrades to popular ones. With the following files, “dota 2 Betakeys.txt.exe" and “diablo3-crack.exe", attackers prey on gamers anxious to test out Defense of the Ancients 2 (a custom scenario map for Warcraft III) and Diablo III, respectively, which aren’t slated for release until later in 2012.
In the first case, users attempting to snag a beta version of Defense of the Ancients 2 are actually just downloading the Pontoeb malware (detected as Backdoor:MSIL/Pontoeb.J). Once executed, Pontoeb begins gathering critical system information with the ultimate goal of morphing the computer into part of a zombie network. It eventually installs a backdoor through which attackers can communicate to execute various commands.
Editor's Pick
In the second case, the Fynloski remote access tool (detected as Backdoor:Win32/Fynloski.A) is installed. Fynloski is a backdoor trojan that gains access to nearly all the information and resources within a given computer, logging keystrokes, downloading and running arbitrary files, and disabling security settings. The MMPC wrote an interesting follow-up piece detailing Fylonski’s obfuscation techniques, which can be found here.
The MMPC recommends visiting the official Defense of the Ancients and Diablo websites if you want to securely try out the actual beta versions.
Commenting on this Article is closed.
Today's Most Popular
- Yahoo Includes Private Key in Source File For Axis Chrome Extension
- Researchers Unveil New Way to Trust Certificates
- FBI Warns Top Firms Of Anonymous Protest Hacks on May 25
- DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S.
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Most Commented Stories
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




Comments
lol this is nothing earth shatteringly new.. soon as most releases leave the hands of reputable cracking sources and hit the mainstream they usually get loaded up with baddies and reposted.. on torrent sites, newsgroups etc.. you pretty much have to expect a payload if you are getting your rips from sources everyone and thier dog gets them from.