World of Warcraft add-on trojan steals account, authenticator info

4.8
Fake version of Curse Client responsible for compromised accounts

A Trojan masquerading as a popular add-on for World of Warcraft was responsible for compromising user accounts even with authenticators, Blizzard revealed today.

According to a post on the MMORPG's support forum, a fake version of the Curse Client contained the trojan. The spoofed client appeared on a forged version of Curse's website, which ranked highly on major search engines for the term "curse client."


The hacked Curse Client transmitted account information, passwords, and even authenticator keys to the attackers as part of the login process, but otherwise functioned normally.

Blizzard recommends that users who believe they may have been compromised delete the client and run the latest version of Malwarebytes, then follow the steps listed on its support page.

"For those of you interested in these [man-in-the-middle] style attacks, this is the only confirmed case we've seen in several years outside of the 'Configuring/HIMYM' trojan in early 2012 that hit a handful of accounts," a Blizzard support agent wrote. "These sort of outbreaks are annoying, but an Authenticator still protects your account 99% of the time. Stay safe!"

World of Warcraft had 7.6 million subscribers as of November 2013, making it the most popular subscription based MMO nine years after its launch. Blizzard's Battle.net service was targeted for denial-of-service attacks this week allegedly intended to disrupt a single Twitch streamer.

As a reminder, the only place you should download the Curse Client is from http://www.curse.com/client/ to ensure it is the real client.

Posted:
Related Forum: PC Gaming Forum

Source: http://www.computerandvideogames.com/443860/world-of-warcraft-add-on-trojan-steals-account-authenticator-info/

Comments

"World of Warcraft add-on trojan steals account, authenticator info" :: Login/Create an Account :: 58 comments

If you would like to post a comment please signin to your account or register for an account.

j8kePosted:

not really player WOW for a while, this is another reason why i dont.

DissPosted:

Katsumi
VPN
Katsumi
bej4yem wooooooowwwwwwww lmfao, the things people get them self into


I'm sure that the hackers where pretty smart when making this program. I could easily see some less experienced users fall into this trap


Yep, that will be the majority of the people falling for this.


It kind of sucks for them to get their account stolen, then again people who fell for this could of been more careful and downloaded this from an official source


The number one rule on downloading stuff you are unsure about, is to research it before you download it. I wouldn't want to lose all of my hard work on a game from someone stealing my account due to a silly mistake.

KatsumiPosted:

VPN
Katsumi
bej4yem wooooooowwwwwwww lmfao, the things people get them self into


I'm sure that the hackers where pretty smart when making this program. I could easily see some less experienced users fall into this trap


Yep, that will be the majority of the people falling for this.


It kind of sucks for them to get their account stolen, then again people who fell for this could of been more careful and downloaded this from an official source

HOFPosted:

VPN
Katsumi
bej4yem wooooooowwwwwwww lmfao, the things people get them self into


I'm sure that the hackers where pretty smart when making this program. I could easily see some less experienced users fall into this trap


Yep, that will be the majority of the people falling for this.


It would stink if you had maxed characters and you lost your account completely.

VPNPosted:

Katsumi
bej4yem wooooooowwwwwwww lmfao, the things people get them self into


I'm sure that the hackers where pretty smart when making this program. I could easily see some less experienced users fall into this trap


Yep, that will be the majority of the people falling for this.

KatsumiPosted:

bej4yem wooooooowwwwwwww lmfao, the things people get them self into


I'm sure that the hackers where pretty smart when making this program. I could easily see some less experienced users fall into this trap

MachampPosted:

Eta Good thing I don't bother with World of Warcraft.


My thoughts exactly, Although a lot of my friends play it im not much of a PC gamer myself.

EtaPosted:

Good thing I don't bother with World of Warcraft.

BeJ4YeM-Posted:

wooooooowwwwwwww lmfao, the things people get them self into

CulpritPosted:

Ahh and this is why you don't go to youtube and trust those people that barely speak English and make those type of videos.