{"id":15624,"date":"2019-06-25T20:47:24","date_gmt":"2019-06-26T04:47:24","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/06\/25\/news-9373\/"},"modified":"2019-06-25T20:47:24","modified_gmt":"2019-06-26T04:47:24","slug":"news-9373","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/06\/25\/news-9373\/","title":{"rendered":"Fresh \u201cvideo games\u201d site welcomes new users with Steam phish"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Fri, 21 Jun 2019 16:51:22 +0000<\/strong><\/p>\n<p>Over the weekend, I received this unsolicited message from an acquaintance on Steam:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39197\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/01-steam-spam\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam.png\" data-orig-size=\"758,666\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"01-steam-spam\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam-300x264.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam-600x527.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam-600x527.png\" alt=\"\" class=\"wp-image-39197\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam-600x527.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam-300x264.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/01-steam-spam.png 758w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<blockquote class=\"wp-block-quote\">\n<p>1 free game for new users!<br \/>Take the game you want https:\/\/t.co\/{redacted} <\/p>\n<\/blockquote>\n<p>Fortunately, other friends on Steam were quick to publicly warn others about potentially hacked accounts spamming dubious messages to anyone (if not all) in their network. I was reading these warnings hours before receiving a sample of the spam message to my own account.<\/p>\n<p>A shallow online search reveals that this campaign has been going on since mid-March of this year. Because it\u2019s quite low-profile, not a lot were able to dig deeper into it. We\u2019ll attempt to do that here.<\/p>\n<h3><strong>Latest Steam phishing campaign: a walk-through<\/strong><\/h3>\n<p>Steam users were right to point out that this shortened URL indeed redirects to a phishing domain\u2014but not at once.<\/p>\n<p>Clicking the <em>t.co<\/em> link, which is a Twitter shortened URL, in the chat takes users to the site behind it: <em>steamredirect[dot]fun<\/em>. This is the re-director domain that takes users to the \u201cproper\u201d phishing page, which pretends to be a site where one can win free games.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39198\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/02-gift4keys-free\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free.png\" data-orig-size=\"1195,670\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"02-gift4keys-free\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-300x168.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-600x336.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-600x336.png\" alt=\"\" class=\"wp-image-39198\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-600x336.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-300x168.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-900x506.png 900w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free-400x225.png 400w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/02-gift4keys-free.png 1195w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>Screenshot of the site called Gift4Keys, just one of the many identical websites out there that the shortened URL points users to.<\/figcaption><\/figure>\n<\/div>\n<p>In the middle of the site is the \u201cTry your luck\u201d section, a roulette game where users can get their (supposed) free game. All they have to do is press the blue Play button.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39199\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/03-gift4keys-roulette-play\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play.png\" data-orig-size=\"1202,494\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"03-gift4keys-roulette-play\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-300x123.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-600x247.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-600x247.png\" alt=\"\" class=\"wp-image-39199\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-600x247.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-300x123.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play-965x395.png 965w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/03-gift4keys-roulette-play.png 1202w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39200\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/04-gift4keys-roulette-win\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win.png\" data-orig-size=\"1199,601\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"04-gift4keys-roulette-win\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win-300x150.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win-600x301.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win-600x301.png\" alt=\"\" class=\"wp-image-39200\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win-600x301.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win-300x150.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/04-gift4keys-roulette-win.png 1199w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption><em>Whoo! I won PUBG!<\/em> <br \/><\/figcaption><\/figure>\n<\/div>\n<p>The page then shows to the user that they have less than 30 minutes to claim the complete key by logging into their Steam account via the website. At the same time, the page also shows that the user would need to wait for 24 hours before they can roll the roulette again and get another free game.<\/p>\n<p>Clicking the Login via Steam button here\u2014or at the upper right-hand corner of the site\u2014opens a page that looks like the bog-standard unaffiliated third-party Steam login page. This is either as a pop-up window or a new tab. The site did both during several tests.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39201\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/05-gift4keys-fake-steam\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam.png\" data-orig-size=\"1126,899\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"05-gift4keys-fake-steam\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam-300x240.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam-600x479.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam-600x479.png\" alt=\"\" class=\"wp-image-39201\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam-600x479.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam-300x240.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/05-gift4keys-fake-steam.png 1126w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>The fake Steam login<\/figcaption><\/figure>\n<\/div>\n<p>Here are a few reasons why, at this point, Steam users should start considering bailing from this site all together and not hand over their credentials:<\/p>\n<ul>\n<li>The links on the page, such as \u201cProfile Privacy Setting\u201d and \u201ccreate an account\u201d don\u2019t work.<\/li>\n<\/ul>\n<ul>\n<li>The URL address bar is blank. Legitimate unaffiliated third-party sites display an <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/extended-validation-ssl-certificate-ev-ssl\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">EV certificate<\/a> for Valve Corp, and the URL in the address bar says that the signing in takes place in <em>steamcommunity.com<\/em>.<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39202\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/06-legit-3rd-party-steam-login\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login.png\" data-orig-size=\"991,306\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"06-legit-3rd-party-steam-login\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login-300x93.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login-600x185.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login-600x185.png\" alt=\"\" class=\"wp-image-39202\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login-600x185.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login-300x93.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/06-legit-3rd-party-steam-login.png 991w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<ul>\n<li>The Language drop-down box at the upper right-hand corner doesn\u2019t work. It also appears to be in Russian even when visitors are outside of Russia.<\/li>\n<\/ul>\n<p>Supplying credentials to this phish page, as we know, will result in accounts getting hijacked to further proliferate the phishing links.<\/p>\n<p>Links in identical campaigns in the past were not hidden behind a URL shortener. It\u2019s also no surprise that these links kept changing. In this case, the shortened URLs have redirected to the following domains, which are less than four months old, at some point:<\/p>\n<ul>\n<li>easyk3y[dot]com<\/li>\n<li>ezzkeys[dot]com<\/li>\n<li>g4meroll[dot]com<\/li>\n<li>g4me5[dot]com<\/li>\n<li>gift4keys[dot]com<\/li>\n<li>gifts-key[dot]com<\/li>\n<li>ong4me[dot]com<\/li>\n<li>tf2details[dot]com<\/li>\n<li>yes-key[dot]com<\/li>\n<\/ul>\n<p>Be forewarned that a number of these sites are still online, and if you visit them, they all look like this:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39203\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/attachment\/07-g4me5-splash\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash.png\" data-orig-size=\"916,683\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"07-g4me5-splash\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash-300x224.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash-600x447.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash-600x447.png\" alt=\"\" class=\"wp-image-39203\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash-600x447.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash-300x224.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/07-g4me5-splash.png 916w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<p>As of this writing, the only way to access the actual \u201cfree games roulette\u201d page we have been showing above is by appending certain strings at the end of the URLs. That\u2019s probably a good thing.<\/p>\n<h3><strong>Keep calm and be vigilant<\/strong><\/h3>\n<p>Steam has always been the platform of choice of fraudsters for a long time because of its millions of active users. This isn\u2019t the first time that users have met and reacted to such a phishing campaign. In fact, this latest one has all the telltale signs of previous campaigns: Steam friend sends a message with link out of nowhere, link leads to a fake Steam login page, collected Steam credentials are used to hijack accounts and spam their friends.<\/p>\n<p>Yes, there are still Steam users falling for old tricks. Yet, it\u2019s also good to see Steam users realizing the danger early on, giving their friends a heads-up about it, and, should they suspect that they are affected, try to contain their zombified accounts to prevent other users from getting compromised.<\/p>\n<p>So be calm, keep on the lookout, stay informed, and continue to look after each other.<\/p>\n<p>Stay safe!<\/p>\n<p>Other related blog(s):<\/p>\n<ul>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/04\/how-gamers-can-protect-against-increasing-cyberthreats\/\" target=\"_blank\">How gamers can protect against increasing cyberthreats<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/steam-spammers-night-movies\/\" target=\"_blank\">Steam spammers have a night at the movies<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2016\/03\/latest-steam-malware-shows-sign-of-rat-activity\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Latest Steam malware shows signs of RAT activity<\/a><\/li>\n<\/ul>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/\">Fresh \u201cvideo games\u201d site welcomes new users with Steam phish<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Fri, 21 Jun 2019 16:51:22 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/' title='Fresh \u201cvideo games\u201d site welcomes new users with Steam phish'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2015\/12\/steam-logo.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A recent Steam phishing campaign caught our eye, but looking deeper, we found it&#8217;s been around for a few months. We investigate the phish to show users how to spot the telltale signs of social engineering.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/social-engineering\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/account-hijack\/\" rel=\"tag\">account hijack<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/ev-certificate\/\" rel=\"tag\">ev certificate<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fake-steam-login\/\" rel=\"tag\">fake steam login<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gaming\/\" rel=\"tag\">gaming<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gaming-security\/\" rel=\"tag\">gaming security<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/steam\/\" rel=\"tag\">steam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/steam-phishing\/\" rel=\"tag\">steam phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/steam-scam\/\" rel=\"tag\">steam scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/valve\/\" rel=\"tag\">valve<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/video-games\/\" rel=\"tag\">video games<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/zombie-account\/\" rel=\"tag\">zombie account<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/' title='Fresh \u201cvideo games\u201d site welcomes new users with Steam phish'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2019\/06\/fresh-video-games-site-welcomes-new-users-with-steam-phish\/\">Fresh \u201cvideo games\u201d site welcomes new users with Steam phish<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[22079,22080,22081,1445,22082,3924,10510,11227,22083,22084,13496,4433,22085],"class_list":["post-15624","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-account-hijack","tag-ev-certificate","tag-fake-steam-login","tag-gaming","tag-gaming-security","tag-phishing","tag-social-engineering","tag-steam","tag-steam-phishing","tag-steam-scam","tag-valve","tag-video-games","tag-zombie-account"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15624"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15624\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}