Published: 2008-06-24
Trojan horse programs designed to steal online-game credentials have spread widely, infecting more than 2.6 million systems, Microsoft said on Friday.
The data comes from the latest release of Microsoft's Malicious Software Removal Tool, which the software giant had modified to detect and remove the most widespread keylogging programs. In a week, the tool had cleaned more than 2.6 million discrete systems with the top program, dubbed Taterf by the company, accounting for 1.3 million infected machines. The second most widespread program was Frethog, an ancestor of Taterf, which accounted for about 650,000 infected machines, according to Microsoft's data.
The numbers far outpace the Storm Worm, also known as Nuwar, which totaled 537,000 infected machines found and cleaned by Microsoft's MSRT in the first week after releasing the tool.
"These are ridiculous numbers of infections, my friends, absolutely mind-boggling," wrote Matt McCormack, a security research for Microsoft, wrote in an analysis of the latest results.
The Trojan horse attacks appear to center mainly on Asian countries, where massively multiplayer online roleplaying games -- such as Lineage -- are extremely popular. China, Taiwan and Korea accounted for 900,000 of the cleaned machines. The United States came in fourth on the list, accounting for 210,000 machines. Programs on the list of eight game-credential stealers also targeted the popular World of Warcraft game.
"Once they have your details, they are sent back to a remote location and are eventually sold to the highest bidder," McCormack wrote. "After that, you may find your gold gone and (be) toon naked upon your next login."
Microsoft recommended that gamers use up-to-date antivirus software, patch their browser, and disable the autoplay feature. Also, the software giant warned that downloading "cracks" -- programs designed to circumvent certain limits in games -- is dangerous behavior.
If you have tips or insights on this topic, please contact SecurityFocus.
Posted by: Robert Lemos
