Welcome Guest. | Log In| Register | Membership Benefits
Dark Reading's CSIsland Weblog
Topics:   SophosLabs Insights

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share

Phishing In A World Of Warcraft


Posted by Graham Cluley, Aug 25, 2009 10:19 AM

Hackers are once again targeting players of the fantasy game "World of Warcraft" in an attempt to steal passwords and other game credentials.

Emails intercepted by researchers at SophosLabs, pose as official communications from World of Warcraft developer Blizzard Entertainment but are really intended to lead players to a phishing website.

Phishing email claiming to come from the makers of World of Warcraft

Players of what is claimed to be the world's most popular MMORPG (Massively Multiplayer Online Role-Playing Game) may be tempted into clicking on a link to receive a sneaky preview of new game functionality.

By the way I was a little perplexed as to what the "mounts" referred to in this attack might mean. It turns out that in the fantasy online universe of World of Warcraft, you're not just limited to riding on horseback. If it takes your fancy (and if your online character has the right attributes) you might choose to ride a wolf, a ram, a gryphon or some other fantastical creature.

Of course, clicking on the link is not a sensible move as game players will be taken to a bogus website asking for their World of Warcraft login details.

Fake World of Warcraft website

Keyloggers and password-stealers targeting on players of World of Warcraft are definitely not a new phenomenon. The techniques may change, but the effect is still the same.

Last year, in a trick pinched from an increasing number of online banks, Blizzard introduced an authentication fob that produces a one-time six-digit number that can be entered at login alongside the user's regular username and password. But until use of such devices is mandatory there will still be many online accounts putting themselves at risk of compromise.

Game players would be wise to remember that if something sounds too good to be true (free gold, free weapons, free expansions), it invariably is too good to be true.

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his other blog on the Sophos website, you can find him on Twitter at @gcluley. Special to Dark Reading.

« When Mass SQL Injection Worms Evolve...Again | Main | Attacking Customers, Employees With SQL Injection »



Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




Related Content

Sponsored by:
sponsor logo
Not All Malware Detection Is Created Equal
The internet is now the number-one conduit for infecting users with malware. Sophos detects a new infected web page every few seconds. This white paper outlines the terms you need to know and the steps you should take to stay safe.

How To Protect Your Critical Information Easily
Safeguarding massive amounts of sensitive, confidential data--from legally protected personal information to intellectual property and trade secrets--from malicious attacks and accidental loss is one of IT's biggest challenges. With employees having greater mobility than ever before to work outside the office, the job of protecting data has never been more difficult.

Buyers Guide to Endpoint Protection Platforms
Discover how you can leverage endpoint security and data protection to provide simplified cross-platform security, centralized management, and control of devices, apps, and network access.