Search! What You See

Friday, March 5, 2010

Man-in-the-Middle Attacks Hit WoW Gamers

Logging in with the authenticator couldn't stop it

World of Warcraft users won't be happy to hear that hackers have managed to pull a man-in-the-middle attack on several servers hosted in Europe. This happened even with the extra security barriers added by the use of an external authenticator. The attack is suspected to have came from China or/and Malaysia.
The attack basically happened like this: while a regular user accessed a WoW-themed infected site on the web, they installed a trojan, named Malware.NSPack, thinking that they were installing a game add-on. That trojan would then go to install suspicious files on the user's computer (emcor.dll copied to ../users/username/appdata/Temp) and log all key strokes, sending back data related to WoW authentication credentials.

The data acquired was then employed by attackers to circumvent WoW's login system and empty the user's account of all of their in-game (“fake”) money. Subsequently, those sums can be transferred to other accounts, which then can be put up for sale and turn real profit for the hackers.

The keylogger trojans that infected the users were hosted on Chinese-based websites, were graphically cloned after the WoWMatrix website and advertised using Google AdWords service. The spoofed data was relayed using a server hosted in Malaysia. Websites reported by users as being attack sources are cursea.com, deadlybossmodss.com, gamesacca.com and wowmatrixf.com. The sites were taken down, along with the Google AdWords banner.

WoW tech admins were quick to reply and investigate, offering this answer within 24 hours of the first report, “After looking into this, it has been escalated, but it is a Man in the Middle attack. This is still perpetrated by key loggers, and no method is always 100% secure,“ trying to excuse the authenticator's failure in supplying full protection.

The attacks themselves don't differ very much from other man-in-the-middle hacks on banking sites, the only difference being that this latest target wasn't harboring real money like banks do, but fake in-game gold.

No comments:

Post a Comment