VB2016 paper: Steam stealers: it's all fun and games until someone's account gets hijacked

Posted by   Martijn Grooten on   Jun 23, 2017

The online games market is huge, and the Steam platform is a huge player in that market. Users registered on the Steam platform use their credit cards to buy content, and willingly provide personal information to and exchange items with other network participants. Rather unsurprisingly, this has not gone unnoticed by cybercriminals, and a while ago they started to target Steam and its often valuable user accounts. Aside from (spear-)phishing, cybercriminals are also using malware variants known as 'Steam stealers' to seek out and harvest users' Steam credentials.

Last year, Kaspersky Lab researcher Santiago Pontiroli and PwC's Bart Parys presented a VB2016 paper analysing the malicious threats faced by Steam users and highlighting how organized criminals are making money with these profitable schemes. Today, we publish the paper in both HTML and PDF format. (Unfortunately, a video of their talk is not available.)

Steam-Stealers-Fig3.jpg


At VB2017 in Madrid, Bart Parys will be back with a look at the threat landscape from a very different perspective, when he will describe the threats faced by a multinational company like PwC. Meanwhile, for those with a particular interest in the area of gaming, another VB2017 paper, by Malwarebytes researcher Chris Boyd, will look at in-game advertisements, another possible threat faced by gamers.

VB2017 takes place 4-6 October in Madrid, Spain. Register before 1 July to receive a 10% Early Bird discount on full-price conference tickets.

 

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.