Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Potential explanation for recent (couple months ago) hacking outbreak
#1
http://www.nationmultimedia.com/home/201...31457.html

Article Wrote:One entry of note in the end-user Top Twenty malware list was a Trojan that steals account logins and passwords for popular online games. Players of CabalOnline, Metin2, Mu Online and various games developed by Nexon.net have all been affected by Trojan-GameThief.Win32.Magania.dbtv.

So yeah...
Reply
#2
Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.

Unless... this trojan hit nexon directly ;] then that explains it.
Reply
#3
Seanny Wrote:Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.

Unless... this trojan hit nexon directly ;] then that explains it.

Well, it's just something I came accross that felt was relevant. It is almost assuredly not the entire cause, but may very well have been a large portion.
Reply
#4
Seanny Wrote:Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.

Unless... this trojan hit nexon directly ;] then that explains it.

It does explain it. They have the logins, the passwords... BUT they don't know who's who. You just got unlucky, same with a lot more.
Reply
#5
The question is now how was it spread.
Reply
#6
Alloy Wrote:It does explain it. They have the logins, the passwords... BUT they don't know who's who. You just got unlucky, same with a lot more.

No, it wouldn't explain it because they'd have the logins and passwords for everyone you used during the infected period, and no one else.
There were way too many people who were hit on accounts that were completely inactive, or were using accounts on one nexon game that didn't have all the required pieces to let you login to Maple, like my guild - We were all strictly mabinogi during this period and had been for months but they didn't have to change our PINs which aren't used in mabi and several of us were hit on maple accounts that were different from our mabi ones anyhow.
Reply
#7
Eosian Wrote:No, it wouldn't explain it because they'd have the logins and passwords for everyone you used during the infected period, and no one else.
There were way too many people who were hit on accounts that were completely inactive, or were using accounts on one nexon game that didn't have all the required pieces to let you login to Maple, like my guild - We were all strictly mabinogi during this period and had been for months but they didn't have to change our PINs which aren't used in mabi and several of us were hit on maple accounts that were different from our mabi ones anyhow.

Like I said, it might explain a few, but not all. Regardless, it was worth bringing to everyone's attention.
Reply
#8
I'm not too good on this internet stuff, just wondering, how could someone sneak a trojan into a program like that?
Reply
#9
No one has said what the trojan was attached to. There was no implication it was embedded in the actual applications named, only that it targeted them.
Reply
#10
Oh I see, sorry for the misunderstanding. I wonder what could have given the mass of people hacked that trojan, my guess is it probably was some popular website filled with malicious ads, alot of the sites I visit are having those "malicious ads" lately.
Reply
#11
My guess is it's completely unrelated because there is and has been no trace of this or any other trojan, virus, worm, or other malware on any machine in my network.
Reply
#12
Eosian Wrote:My guess is it's completely unrelated because there is and has been no trace of this or any other trojan, virus, worm, or other malware on any machine in my network.

Supposing it's a newly written malware, how do you tell if it is one?
Reply
#13
Kalovale Wrote:Supposing it's a newly written malware, how do you tell if it is one?

Not having downloaded or installed anything new, and having had nothing new show up in Process Explorer are pretty good give aways.

It autoloads in all my machines and I tend to watch the full command line and parameters of all running processes the way normal people use screen savers.
Although If it's truly newly written it couldn't be responsible for four months ago anyhow, now could it?
Reply
#14
Even hidden processes, like HackShield/Maple, show up on the Process Explorer too? I thought it'd be all too easy to hide a process.
Reply
#15
Rootkit Revealer prevents that, and before it can rootkit itself it'd still show up the initial stuff that's doing the naughty bits. Can't hide itself before it's done the hiding directives.

Hackshield and Maple both show up, that's why they refuse to run while process explorer is running. If they're able to detect it. Rootkits work both ways Biggrin
Reply
#16
Eosian Wrote:Rootkit Revealer prevents that, and before it can rootkit itself it'd still show up the initial stuff that's doing the naughty bits. Can't hide itself before it's done the hiding directives.

Hackshield and Maple both show up, that's why they refuse to run while process explorer is running. If they're able to detect it. Rootkits work both ways Biggrin

pineapple I should've read this sooner, Maple just closed down on me. Hoping I'm not autobanned for having "hacking tools detected".
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)