World of Warcraft add-on trojan steals account, authenticator info

4.8
Fake version of Curse Client responsible for compromised accounts

A Trojan masquerading as a popular add-on for World of Warcraft was responsible for compromising user accounts even with authenticators, Blizzard revealed today.

According to a post on the MMORPG's support forum, a fake version of the Curse Client contained the trojan. The spoofed client appeared on a forged version of Curse's website, which ranked highly on major search engines for the term "curse client."


The hacked Curse Client transmitted account information, passwords, and even authenticator keys to the attackers as part of the login process, but otherwise functioned normally.

Blizzard recommends that users who believe they may have been compromised delete the client and run the latest version of Malwarebytes, then follow the steps listed on its support page.

"For those of you interested in these [man-in-the-middle] style attacks, this is the only confirmed case we've seen in several years outside of the 'Configuring/HIMYM' trojan in early 2012 that hit a handful of accounts," a Blizzard support agent wrote. "These sort of outbreaks are annoying, but an Authenticator still protects your account 99% of the time. Stay safe!"

World of Warcraft had 7.6 million subscribers as of November 2013, making it the most popular subscription based MMO nine years after its launch. Blizzard's Battle.net service was targeted for denial-of-service attacks this week allegedly intended to disrupt a single Twitch streamer.

As a reminder, the only place you should download the Curse Client is from http://www.curse.com/client/ to ensure it is the real client.

Posted:
Related Forum: PC Gaming Forum

Source: http://www.computerandvideogames.com/443860/world-of-warcraft-add-on-trojan-steals-account-authenticator-info/

Comments

"World of Warcraft add-on trojan steals account, authenticator info" :: Login/Create an Account :: 58 comments

If you would like to post a comment please signin to your account or register for an account.

KatsumiPosted:

Kex
Katsumi
Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics


Same. People probably got their accounts stolen because they fail to download programs from the official source.


I could see it being due to something like this. I always try to find an official source for game clients and such

DissPosted:

Katsumi
Lia
Katsumi
Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics


Most people would of got their accounts back though, since Blizzard is aware of this.


Yeah.. Blizzard would of worked to get their accounts back after they where hacked. I could picture all the items and stuff already being taken off them though


Especially very rare items. It would suck if you worked forever to obtain a certain piece of gear and then have it taken a way from you because of this.

MawderzPosted:

Katsumi
Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics


Same. People probably got their accounts stolen because they fail to download programs from the official source.

KatsumiPosted:

Lia
Katsumi
Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics


Most people would of got their accounts back though, since Blizzard is aware of this.


Yeah.. Blizzard would of worked to get their accounts back after they where hacked. I could picture all the items and stuff already being taken off them though

DissPosted:

Katsumi
Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics


Most people would of got their accounts back though, since Blizzard is aware of this.

KatsumiPosted:

Genetics dang that sucks a lot... I wonder what the close estimate of accounts stolen there was


I would think that a fair few would of been stolen through this, i wouldn't mind to see some statistics

neboPosted:

dang that sucks a lot... I wonder what the close estimate of accounts stolen there was

VeraPosted:

So much problems have been happening for the gaming community in the last week.
Nobody can get peace to game.

MwahPosted:

I have never ever played WoW and dont ever intend in playing it but thats smart!

iriisqxPosted:

How did none notice it? A fake site should be noticeable easy.