{"id":18555,"date":"2022-03-21T14:10:06","date_gmt":"2022-03-21T22:10:06","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/03\/21\/news-12288\/"},"modified":"2022-03-21T14:10:06","modified_gmt":"2022-03-21T22:10:06","slug":"news-12288","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/03\/21\/news-12288\/","title":{"rendered":"Fake Esports voting sites looking to phish Steam users"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 21 Mar 2022 21:41:07 +0000<\/strong><\/p>\n<p>We\u2019ve seen Esports occasionally become the focus of gaming or Steam scams. One particular tactic of note was to claim joining an official league is an easy process. Links to third-party hosted files would offer up a supposedly cracked ESEA Esports league client. In reality, it was a <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2015\/01\/good-at-games-steam-scammers-suggest-you-join-a-league\/\">data stealing Trojan<\/a>.<\/p>\n<p>One current twist on Esports where Steam scams are concerned is the \u201cvote for my team\u201d fakeout. <\/p>\n<h2>Crying foul on bogus voting<\/h2>\n<p>This trick has been around for a while now, but shows no signs of going away. As some have noticed, it is indeed \u201c<a href=\"https:\/\/www.reddit.com\/r\/SteamScams\/comments\/s8l9d8\/i_have_lost_quite_a_few_friends_because_of_this\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">flaring up again<\/a>\u201d. The scam routinely separates unwary gamers from their logins. It\u2019s also used to spam people from compromised accounts. On top of all that, the social pressure of \u201cPlease help me out\u201d is often too good to let go.<\/p>\n<p>An additional headache here is that people change usernames on Steam all the time. As a result, some people assume the <a href=\"https:\/\/www.reddit.com\/r\/SteamScams\/comments\/slyqbr\/i_fell_for_the_vote_my_team_esports_hack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">message sender is actually a friend<\/a> and not a stranger. This makes it even more likely they\u2019ll feel obliged to assist.<\/p>\n<p>People want to be helpful, and this slice of social engineering takes full advantage of this.<\/p>\n<h2>How does it work?<\/h2>\n<p>A Steam user receives an unsolicited message from a stranger. It may be sent via Steam\u2019s own messenger service, or it could be in a Steam-themed Discord channel. The scammer presents the \u201coffer\u201d as a way to help a fellow Steam enthusiast out, or tie it to fictional rewards if the message recipient takes part. The message may <a href=\"https:\/\/www.reddit.com\/r\/SteamScams\/comments\/tix5oi\/what_a_unique_chinese_scam\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">also be sent in a different language<\/a>. Some scammers simply won\u2019t care about this, on the basis they can just send it to a seemingly never-ending pool of other recipients.<\/p>\n<p>After some <a href=\"https:\/\/www.reddit.com\/r\/SteamScams\/comments\/s6ahyl\/dont_fall_for_the_tournament_scam_its_not_even_a\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">small talk<\/a>, the scammer will ask the message recipient if they want to join their Esports team. More likely, they\u2019ll ask them to vote for their team in an upcoming competition, or do some form of nomination to take part.<\/p>\n<p>Clicking into the site and hitting the specified team vote button will typically open up a phishing page or window. If the intended victim uses some form of account protection such as Steam Guard, they\u2019ll be asked to switch it off. Once this is all done and dusted, the account is officially phished and at the mercy of the phisher(s).<\/p>\n<h2>What&#8217;s the impact from being phished in this manner?<\/h2>\n<p>We\u2019ve touched on a few of the impacts, but they include:<\/p>\n<ul>\n<li>Spamming your friends. Not great, and they\u2019ll likely unfriend you once they see suspicious messages rolling in.<\/li>\n<li>Losing your digital items. Hard-earned items will vanish, after being sent to other accounts. If you paid real money for those items then they\u2019re at risk too. The scammer may even just choose to sell the entire account in one go. If you used money in your Steam wallet to purchase a valuable item, both money and item <a href=\"https:\/\/www.reddit.com\/r\/SteamScams\/comments\/rrjs2v\/i_lost_200\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">may be lost<\/a>.<\/li>\n<li>Loss of access. Perhaps an obvious one, but you probably don\u2019t need the hassle of trying to get through to customer support when the pandemic continues to cause significant delays on, well, everything.<\/li>\n<\/ul>\n<h2>Protecting your Steam account from esports voting scams<\/h2>\n<p>You&#8217;ll probably be familiar with some of these Steam security suggestions:<\/p>\n<ul>\n<li>Add additional protection to the email account tied to Steam. If 2FA style safeguards are available, be sure to use them. If you have a second, backup email account tied to the primary account, then make sure that\u2019s locked down too.<\/li>\n<li>Enable Steam Guard. It\u2019ll mean the scammers have to work harder to access your account. While it won\u2019t tip everyone off, having to awkwardly ask you for your 2FA code may be enough to set alarm bells ringing.<\/li>\n<li>Unsure if an account is one of your friends sporting a new username? Hover over the username of the person messaging you on their profile. It\u2019ll reveal a list of all the old names they\u2019ve gone by. If you\u2019re unable to view their profile at all, add that to the \u201cprobably suspicious\u201d pile.<\/li>\n<li>Never, ever log into anything related to Steam via messages from friends or strangers. Even if you know the person sending the message, it\u2019s possible they\u2019ve been compromised and are being used to send more spam.<\/li>\n<\/ul>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/03\/fake-esports-voting-sites-looking-to-phish-steam-users\/\">Fake Esports voting sites looking to phish Steam users<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/03\/fake-esports-voting-sites-looking-to-phish-steam-users\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 21 Mar 2022 21:41:07 +0000<\/strong><\/p>\n<p>We take a look at a popular Steam phish tactic involving fake Esports voting sites which refuses to go away.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/03\/fake-esports-voting-sites-looking-to-phish-steam-users\/\">Fake Esports voting sites looking to phish Steam users<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[13645,11539,10511,3924,3985,10510,11227,25451],"class_list":["post-18555","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-esports","tag-fake","tag-phish","tag-phishing","tag-scam","tag-social-engineering","tag-steam","tag-team"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18555"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18555\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}