World of Warcraft add-on trojan steals account, authenticator info

4.8
Fake version of Curse Client responsible for compromised accounts

A Trojan masquerading as a popular add-on for World of Warcraft was responsible for compromising user accounts even with authenticators, Blizzard revealed today.

According to a post on the MMORPG's support forum, a fake version of the Curse Client contained the trojan. The spoofed client appeared on a forged version of Curse's website, which ranked highly on major search engines for the term "curse client."


The hacked Curse Client transmitted account information, passwords, and even authenticator keys to the attackers as part of the login process, but otherwise functioned normally.

Blizzard recommends that users who believe they may have been compromised delete the client and run the latest version of Malwarebytes, then follow the steps listed on its support page.

"For those of you interested in these [man-in-the-middle] style attacks, this is the only confirmed case we've seen in several years outside of the 'Configuring/HIMYM' trojan in early 2012 that hit a handful of accounts," a Blizzard support agent wrote. "These sort of outbreaks are annoying, but an Authenticator still protects your account 99% of the time. Stay safe!"

World of Warcraft had 7.6 million subscribers as of November 2013, making it the most popular subscription based MMO nine years after its launch. Blizzard's Battle.net service was targeted for denial-of-service attacks this week allegedly intended to disrupt a single Twitch streamer.

As a reminder, the only place you should download the Curse Client is from http://www.curse.com/client/ to ensure it is the real client.

Posted:
Related Forum: PC Gaming Forum

Source: http://www.computerandvideogames.com/443860/world-of-warcraft-add-on-trojan-steals-account-authenticator-info/

Comments

"World of Warcraft add-on trojan steals account, authenticator info" :: Login/Create an Account :: 58 comments

If you would like to post a comment please signin to your account or register for an account.

gmlukensPosted:

Wow, it's a bad thing to do but a smart way of doing it.

HuniPosted:

got to be honest ive have never played WoW and dont plan on playing it. but it would be annoying

WishPosted:

I've never played WoW, but I can imagine this being a real annoyance for people who do play it.

KatsumiPosted:

Lia
Katsumi This would of really sucked for someone who is an avid WoW player. Thank god that i don't use curse or anything


Curse add-ons really do improve the gaming experience for WoW, at least when I played a few years back. It's still a risky site though, and that's why I always researched my add-ons before actually downloading 'em.


I may be getting back into WoW in the near future so it's nice to know. Thanks for the advice :)

CaszechPosted:

Its sad that people do this..

600Posted:

Good thing I don't use curse, I would hate this to happen to me.

j8kePosted:

hope nobody lost there account, that wouldn't be good.

DissPosted:

Katsumi This would of really sucked for someone who is an avid WoW player. Thank god that i don't use curse or anything


Curse add-ons really do improve the gaming experience for WoW, at least when I played a few years back. It's still a risky site though, and that's why I always researched my add-ons before actually downloading 'em.

basedtelliPosted:

Katsumi This would of really sucked for someone who is an avid WoW player. Thank god that i don't use curse or anything


Lets hope it didnt happen -Tyler, TDK and Forest (Only people I know that play WoW)

KatsumiPosted:

This would of really sucked for someone who is an avid WoW player. Thank god that i don't use curse or anything