Personal tools
You are here: Home WiKIDBlog more-on-two-factor-authentication-for-gamers

more-on-two-factor-authentication-for-gamers

by admin posted on Jan 21, 2009 03:46 PM last modified Apr 03, 2009 11:56 AM —

But this time it is poker players. F-Secure has analysis of a trojan that targets online poker accounts The purpose of ...

But this time it is poker players.

F-Secure has analysis of a trojan that targets online poker accounts

The purpose of the dropped executables is to collect login information for various online poker websites from the user's computer and send them back to the malware author. In addition, the main malware component was protected by a rootkit driver that hid its process and launch point from registry.

The serious thing here was that RBCalc.exe was distributed by checkraised.com - a website that provides tools, articles and other various applications to all poker players. As a result, many online poker players could have been affected by this targeted attack.

Checkraised.com has removed the file and posted a page about the attack:

In December 2005 we contracted a programmer to create a rake calculator for us. The rake calculator (known as rbcalc, rbcalc.exe) was an executable file that a player would run on his machine to calculate rake from hands he previously played (stored in hand history files or a poker tracker database).

It has recently come to our attention that early versions of this program that we received contained a virus that installs itself every time the user runs rbcalc.

I'm curious to know whether the original programmer is to blame or if it was added later. Also, it has been up for 6 months so I'm surprised no one has been hit yet or at least reported it.

Document Actions

two-factor-authentication-for-gamers

Posted by Candid Wueest at Feb 23, 2009 09:36 AM

That's actually nothing new, Trojans which steal login data for games have been around for years. Specially in the Asian market for example with Legend of Mir. The greymarket for those items is big. The question is if two-factor authentication would solve the problem or if the Trojans would adapt like they do for online banking.