Gamers…this just in: You’re being targeted…this new CryptoLocker variant (only 8% of the code the same) encodes your gaming files and mods.
“This crypto-ransomware variant has been getting distributed from a compromised web site that was redirecting the visitors to the Angler exploit kit by using a Flash clip. Bromium Labs notified the owner of the web site, but they haven’t responded. At the time of writing this blog, the website was still serving malware. The web site is based on WordPress and could have been compromised by any one of the numerous WP exploits. Additionally, the URL where the malicious Flash file is hosted keeps changing.” Bromium Labs
Attackers used an unconventional way of redirecting the users. Instead of a typical iframe (or an iframedynamically generated by JavaScript) they used a Flash clip wrapped in an invisible <div> tag.
“The list of games that are affected by the malware program includes Call of Duty, StarCraft, Diablo, Fallout, Minecraft, Assassin's Creed, Half Life 2, and Bioshock 2, among others. Digital game distribution platform Steam is allegedly targeted, as well as game development software such as RPG Maker, Unity3D, and Unreal Engine.” – Neowin
But there are more affected. To read more, go here: http://www.neowin.net/news/new-cryptolocker-variant-targets-gamers-encrypts-game-files
More detailed explanations are given here: http://labs.bromium.com/2015/03/12/achievement-locked-new-crypto-ransomware-pwns-video-gamers/
So, beware…
Sources:
http://labs.bromium.com/2015/03/12/achievement-locked-new-crypto-ransomware-pwns-video-gamers/
http://www.neowin.net/news/new-cryptolocker-variant-targets-gamers-encrypts-game-files