Ramblings of an old Doc

 

Gamers…this just in: You’re being targeted…this new CryptoLocker variant (only 8% of the code the same) encodes your gaming files and mods.

“This crypto-ransomware variant has been getting distributed from a compromised web site that was redirecting the visitors to the Angler exploit kit by using a Flash clip. Bromium Labs notified the owner of the web site, but they haven’t responded. At the time of writing this blog, the website was still serving malware. The web site is based on WordPress and could have been compromised by any one of the numerous WP exploits. Additionally, the URL where the malicious Flash file is hosted keeps changing.” Bromium Labs

Attackers used an unconventional way of redirecting the users. Instead of a typical iframe (or an iframedynamically generated by JavaScript) they used a Flash clip wrapped in an invisible <div> tag.

“The list of games that are affected by the malware program includes Call of Duty, StarCraft, Diablo, Fallout, Minecraft, Assassin's Creed, Half Life 2, and Bioshock 2, among others. Digital game distribution platform Steam is allegedly targeted, as well as game development software such as RPG Maker, Unity3D, and Unreal Engine.” – Neowin

But there are more affected. To read more, go here: http://www.neowin.net/news/new-cryptolocker-variant-targets-gamers-encrypts-game-files

More detailed explanations are given here: http://labs.bromium.com/2015/03/12/achievement-locked-new-crypto-ransomware-pwns-video-gamers/

So, beware…

Sources:

http://labs.bromium.com/2015/03/12/achievement-locked-new-crypto-ransomware-pwns-video-gamers/

http://www.neowin.net/news/new-cryptolocker-variant-targets-gamers-encrypts-game-files


Comments
on Mar 13, 2015

update your Microsoft Product and your Adobe products from the source page and you should be fine.
Very important if you install Unreal Engine based demos make sure you download them from a trustworthy source.
And of course keep your AV up to date as always.
Happy Gaming 

on Dec 14, 2015

Good thing I'm not a gamer. 

on Dec 14, 2015

just another example of why one should just not run any flash at all....

on Dec 14, 2015

Nexus site was (possibly) hacked a while back.  They encourage all users to reset their passwords to a new password. 

on Dec 15, 2015

Didn't hear anything about that.

on Dec 15, 2015

First posted 13th March 2015, reply 2 on 14th December 2015, internet lag?

on Dec 15, 2015

It was necrospammed. Uvah replied before it sank back where it came from.

on Dec 16, 2015

Oops!

on Dec 17, 2015

My bad.  Saw the article at the nexus site, thought it was new (was new to me - lol) Opps..

on Dec 17, 2015

It's good Idea as far as your PC to get Bitdefender Anti-Ransomeware here- http://labs.bitdefender.com/2015/11/russian-hackers-are-behind-cryptowall-4-0-bitdefender-creates-vaccine/

Kaspersky CoinVaultDecryptor- http://www.majorgeeks.com/files/details/kaspersky_coinvaultdecryptor_tool.html

How to PDF file- https://noransom.kaspersky.com/static/CoinVault-decrypt-howto.pdf

Be Proactive!