World of Warcraft Trojan spreads from Asia

By on

Password stealing malware hits US and Turkey and accounts for almost 13 per cent of malware activity detected in a recent survey.

Password-stealing programs affecting online games such as World of Warcraft accounted for almost 13 per cent of malware activity detected in a recent survey.

While China and Taiwan are most seriously affected, infections appear to be spreading out of the region, initially into Turkey, according to a report from security firm Fortinet.

"While the main activity remains in China and Taiwan, activity has risen in Turkey," said Fortinet security researcher Derek Manky.

China suffered 36.5 per cent of all attacks from online game Trojans in June, followed by Taiwan with 31.1 per cent, Turkey with 15.4 per cent and the US with 7.4 per cent.

Fortinet recorded a particularly sharp rise in attacks by the 'W32/OnlineGames!tr' malware, which steals passwords and other account data from online games including World of Warcraft and sends them to a remote server.

More than 7.5 per cent of all recorded attack attempts were generated by this Trojan, which was first identified in April 2007.

The malware also attempts to grab log-in details from YouXiChaYuan and Perfect World, two online games popular in China and some other Asian countries.

It is not clear from Fortinet's description whether 'W32/OnlineGames!tr' is limited to specific language versions of Windows or the World of Warcraft client. The company does not explain how PCs become infected.

Once the malware is executed, it adds an instruction to run itself on Windows startup to the Windows registry and also injects code into the explorer.exe process, as well as attempting to steal the game passwords.

"With the online gaming market thriving with consumers, malicious activity will very likely continue for some time in this emerging sector as it forms a viable target," said Manky.

Fortinet gathers statistics by monitoring malware activity reported by its security hardware and software installed at client sites.
Copyright ©v3.co.uk
Tags:

Most Read Articles

You must be a registered member of iTnews to post a comment.
| Register

Poll

New Windows 10 users, are you upgrading from...
Windows 8
Windows 7
Windows XP
Another operating system
Windows Vista
How should the costs of Australia's piracy scheme be split?
Rights holders should foot the whole bill
50/50
ISPs should foot the whole bill
Government should chip in a bit
Other
View poll archive

Whitepapers from our sponsors

What will the stadium of the future look like?
What will the stadium of the future look like?
New technology adoption is pushing enterprise networks to breaking point
New technology adoption is pushing enterprise networks to breaking point
Gartner names IBM a 'Leader' for Disaster Recovery as a Service
Gartner names IBM a 'Leader' for Disaster Recovery as a Service
The next era of business continuity: Are you ready for an always-on world?
The next era of business continuity: Are you ready for an always-on world?

Log In

Username:
Password:
|  Forgot your password?