PDA

View Full Version : STEAM users be on your guard [Trojan Warning]


HunterICX
01-09-15, 07:34 PM
Just want to give off a warning to anyone using Steam.

There seems to be a Phising trojan spreading like wildfire lately that comes in the form of a link towards an image via chat or profile comments. This link however doesn't go or downloads an image but a .scr file (commonly used for windows screensaver) this fools some AV/IS applications untill it's too late.

Once infected the trojan has acces to your account and within seconds it robs your steamwallet and inventory of items. Some report it even bypasses Steamguard as it steals the verification file but this I'm not sure off or how it works.

Also the infection causes your account to send chat messages to everyone or most people in your friendlist or posts a comment on their profile page too fool others that the link can be trusted.

I happen to be aware of this by having red the steam forums from time to time but seems others where not as today I got 3 - 4 messages with that malicious link from members of subsim that I have in my friendlist.

it comes with messages like this:

WTF?!?! [insert random named imagehost].com/screenshot.png
Check this out [insert random named imagehost].com/screenshot.png
Want to trade? [insert random named imagehost].com/screenshot.png

Do NOT click the link, ignore it when in chat and if it's on the profile page delete the comment.

So heads up and don't click any link that you can't confirm it can be trusted.

Skybird
01-09-15, 07:39 PM
Thanks. For the time being: all Steam gaming switched to offline. Their forums really is no big loss, except for masochists maybe.

ReallyDedPoet
01-09-15, 07:51 PM
Thanks :up:

Betonov
01-10-15, 03:48 AM
WTF?!?! [insert random named imagehost].com/screenshot.png
Check this out [insert random named imagehost].com/screenshot.png
Want to tradehttp://cdncache-a.akamaihd.net/items/it/img/arrow-10x10.png (http://www.subsim.com/radioroom/#)? [insert random named imagehost].com/screenshot.png



Those kinds of messages are a no-no everywhere.
Thanks for the heads up

Lord_magerius
01-10-15, 04:31 AM
If you're stupid enough to fall for this sort of stuff, you deserve a trojan on your damn PC.

Lionclaw
01-10-15, 04:44 AM
Luckily Malwarebytes Premium blocked it when I clicked the link.

Lesson learned nonetheless.

Cybermat47
01-10-15, 04:48 AM
Damn thing hijacked someone on my friends list for a little while :nope:

It's not just chat you have to look out for, the virus also posts comments on your profile page, so delete those.

Herr-Berbunch
01-10-15, 05:37 AM
It's not just chat you have to look out for, the virus also posts comments on your profile page, so delete those.

Just like HunterICX said. :D

Thanks for the heads up. I was going to put something similar to Lord_M's post but then felt bad for Lionclaw. :-?

Lionclaw
01-10-15, 06:41 AM
Just like HunterICX said. :D

Thanks for the heads up. I was going to put something similar to Lord_M's post but then felt bad for Lionclaw. :-?

I'm pretty sure Malwarebytes did its job, I got a screen in the browser saying that it was a malicious link when I clicked the link.

I meant that I was lucky that the protection kicked in and blocked it. :)

I still have all the stuff in my inventory in Steam.

Stealhead
01-10-15, 10:17 AM
If you're stupid enough to fall for this sort of stuff, you deserve a trojan on your damn PC.


I'll take heads up on a virus any day especially one that possibly has infected friends as HunterICX had explained.

Thanks for the heads up Hunter for us stupid folks :sunny:

Red October1984
01-10-15, 02:34 PM
Thanks for the heads up.

My steam is usually offline throughout the day and online at night...so as long as nobody uses my PC at 3AM i'll be fine. :hmmm:

nikimcbee
01-10-15, 05:41 PM
Thanks. For the time being: all Steam gaming switched to offline. Their forums really is no big loss, except for masochists maybe.

Thanks :up:

Thanks for the heads up.

My steam is usually offline throughout the day and online at night...so as long as nobody uses my PC at 3AM i'll be fine. :hmmm:

Ditto.:salute:

Oberon
01-10-15, 07:39 PM
http://hitscom.com/main/wp-content/uploads/2014/08/shut-down-everything.jpg

darius359au
01-11-15, 06:33 PM
would appear steams aware of the problem and been working on a fix http://games.on.net/2015/01/steam-trading-now-requires-a-captcha-authentication/

Aktungbby
01-12-15, 05:45 PM
would appear steams aware of the problem and been working on a fix http://games.on.net/2015/01/steam-trading-now-requires-a-captcha-authentication/

Congrats on your 1000th post!:woot:

NeonSamurai
01-12-15, 06:24 PM
You would think that steam itself would be able to trace the culprits pretty damn fast though, since this is an in steam transfer. There are bound to be logs of all this stuff.