Jump to content

New Ransomware Targets PC Games

Cryptolocker-like malware maliciously encrypts savegames and other data for a number of popular titlesIf you're a gamer, be on the lookout for a nasty new piece of malware that will make your mods, savegames, and other game data inaccessible via encryption. The cybercriminals behind the scheme are seeking to extort users by forcing those unlucky enough to be infected to make a large payment in Bitcoin in order to receive an unlock key.

The malware, which is a variant of the crypt-ransomware called TeslaCrypt, superficially looks like CryptoLocker. But according to a number of security researchers who have analyzed the malware, it shares little code with CryptoLocker or its more well-known successor CryptoWall. And while it will also will target photos and documents, as well as iTunes-related files, as Bromium security researcher Vadim Kotov noted in an analysis on Bromium Labs' blog, TeslaCrypt also includes code that specifically looks for files related to more than 40 specific PC games, gaming platforms, and game developer tools. The games include both single player and multiplayer games, though it isn't clear how targeting some of the multiplayer games would affect users other than requiring a re-install.

The games targeted include a mix of older and newer titles— for example, Blizzard's StarCraft II and WarCraft III real-time strategy games and its World of Warcraft online game are targeted. Also on TeslaCrypt's hit list: Bioshock 2, Call of Duty, DayZ, Diablo, Fallout 3, League of Legends, F.E.A.R, S.T.A.L.K.E.R, Minecraft, Metro 2033, Half-Life 2, Dragon Age: Origins, Resident Evil 4, World of Tanks, Metin 2, and The Elder Scrolls (specifically, Skyrim-related files), as well as Star Wars: The Knights Of The Old Republic. There's also code that searches for files associated with games from specific companies that affect a wide range of titles, including a variety of games from EA Sports, Valve, and Bethesda, and Valve's Steam gaming platform. And the game development tools RPG Maker, Unity3D and Unreal Engine are targeted as well."

These files are all targeted by their file extension, Kotov reported. "Concretely these are user profile data, saved games, maps, mods, etc," he said. "Often it’s not possible to restore this kind of data even after re-installing a game via Steam."

Source:http://arstechnica.com/security/2015/03/cryptolocker-look-alike-searches-for-and-encrypts-pc-game-files/]http://arstechnica.com/security/2015/03/cryptolocker-look-alike-searches-for-and-encrypts-pc-game-filesOther Sources:

Click here to view the article

<p> AMD Ryzen 7 5800x l ASUS TUF X570-PLUS l G.Skill Trident Z Neo Series RGB 32GB l Sapphire Pulse RX 7900 XTX

Link to comment
Share on other sites

Link to post
Share on other sites

I know not everyone can afford to do it, but this is why I have three computers, One for gaming and general pissing about (if it gets a virus like this I just format and backup to a 3monthly image), my work laptop which never sees a game, I sometimes runs linux on this machine.  And my last one is for my tools (oscilloscope, room analysis software etc) it is hardly on the net (just for drivers and windows update.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

What is "Cryptolocker"? Is it really that much of a threat?

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

What is "Cryptolocker"? Is it really that much of a threat?

It's the media coined term for malware that encrypts your hard drive and charges you a ransome to decrypt it. It's been around for years, but recently been a popular attack on those who have files they can't afford to lose, because there is money to be made

The actual "cryptolocker" was a trojan from email attachments in 2013 on, and it got big enough to be reconised in the media and thus the term was coined for a practice cryptovirology that charges a ransom for your files. Whole "kleenex" situation there in a way for naming. 

 

I got something similar on one of my systems in like 2007 myself, it just did it to cause damage, didn't offer an rnsom to unlock files, but it's definitely been around. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

well this is great.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

Malwarebytes and AVG cover this right?

Nope

 

How do you get infected? @OP Read the sticky thread on this subforum btw

Well. No one knows how. It can come through 60 different ways.

X-10 - 7980XE - Gigabyte Aorous Gaming 9 - 128GB GSkill TridentZ RGB - SLI Asus GTX 1080 TI Strix
Easy Desk GuideMalware Removal Guide - New mobo, Same OS Guide

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

AAAAAAAND this is why i have 2 harddrives.windows on one i can easily restore and baselocked 1tb other hdd

"1 shot 1 kill. or in my case 500 shots and a questionable death" ~ Carlos Hathcock + Ryouichi

"Because its windows... it just happens..." ~ G33k 4 L1F3

My Build....sorta. close enough http://pcpartpicker.com/p/YMG4mG

Link to comment
Share on other sites

Link to post
Share on other sites

Is there a way to encrypt your files after your files have been encrypted. Or is there a way of getting past this like contacting the police or something for help as it's illegal activity and damage to your stuff.

 (\__/)

 (='.'=)

(")_(")  GTX 1070 5820K 500GB Samsung EVO SSD 1TB WD Green 16GB of RAM Corsair 540 Air Black EVGA Supernova 750W Gold  Logitech G502 Fiio E10 Wharfedale Diamond 220 Yamaha A-S501 Lian Li Fan Controller NHD-15 KBTalking Keyboard

Link to comment
Share on other sites

Link to post
Share on other sites

Is there a way to encrypt your files after your files have been encrypted. Or is there a way of getting past this like contacting the police or something for help as it's illegal activity and damage to your stuff.

Good encryption can't be broken without the resources well beyond what would be allocated to one persons files. 

And encrypted encrypted files are just encrypted encrypted files. Like double condoms, multiple layers of encryption can backfire. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

How do you get infected? @OP Read the sticky thread on this subforum btw

I wasn't able to give much details since my source and other sources I read didn't shed much light. I did think cause of the list of games that can be infected that it is important for people to know even if the specifics of this attack aren't in the news yet.

<p> AMD Ryzen 7 5800x l ASUS TUF X570-PLUS l G.Skill Trident Z Neo Series RGB 32GB l Sapphire Pulse RX 7900 XTX

Link to comment
Share on other sites

Link to post
Share on other sites

I always backup my entire hard drive every month. So its not a big deal.

PC Spec :

Processor : AMD Ryzen 5 3400G  ; Motherboard : MSI B450 A-Pro MAX ; RAM : Corsair Vengeance LPX White 2 x 8Gb

GPU : Sapphire RX 5500 XT 8GB Pulse ; PSU : Cooler Master MWE Gold 750W, 80+Gold ; SSD : Samsung 860 EVO 250GB ; HDD 2 x WD Blue 1TB 3.5" ; Toshiba 1TB 2.5"

 

Link to comment
Share on other sites

Link to post
Share on other sites

There are other cryptolockers out there as well that attack personal files such as photos and documents. I've heard that these even went as far as locking the files on your dropbox and other computers that you may have on the network. So the only save way of keeping your data safe is to backup regularlly and physically unplug the drive.

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

Good encryption can't be broken without the resources well beyond what would be allocated to one persons files. 

And encrypted encrypted files are just encrypted encrypted files. Like double condoms, multiple layers of encryption can backfire. 

I see, so this effectively bricks your storage device. Would you be able to wipe HDD or SSD and then start all over again or would the encryption prevent that.

 (\__/)

 (='.'=)

(")_(")  GTX 1070 5820K 500GB Samsung EVO SSD 1TB WD Green 16GB of RAM Corsair 540 Air Black EVGA Supernova 750W Gold  Logitech G502 Fiio E10 Wharfedale Diamond 220 Yamaha A-S501 Lian Li Fan Controller NHD-15 KBTalking Keyboard

Link to comment
Share on other sites

Link to post
Share on other sites

What kind of douche bag comes up with shit like this?

ultra douchbags.

Intel i7 4702MQ| Nvidia GTX 850M| Kingston 16GB DDR3 1600Mhz| Acer VA70_HW (mobo)| 1TB WD Blue| MATSHITA DVD-RAM UJ8E0|1600x900 display|Win 8.1

Intel i5 4690K @Stock| Sapphire 390 Nitro| Hyper X Fury 2x4GB| MSI SLI Krait z97| Noctua Nh-U12S | 850 EVO 256GB| 2TB WD Black | CM V 850w| Enthoo Luxe

If you want to tag me or any person with periods do: @[Member='Name]

Link to comment
Share on other sites

Link to post
Share on other sites

Im sorry, but what exactly is this supposed to do and how it appears? I have played some of those games and i havent seen anything of the sort like that to appear to me o-o.

Groomlake Authority

Link to comment
Share on other sites

Link to post
Share on other sites

Nope

 

Well. No one knows how. It can come through 60 different ways.

So it goes to Steam, Origin, and U-AlreadyCan't-Play game files and then to the user.

Solution? Buy the Disk version, or pay on steam but pirate the download.

I run my browser through NSA ports to make their illegal jobs easier. :P
If it's not broken, take it apart and fix it.
http://pcpartpicker.com/b/fGM8TW

Link to comment
Share on other sites

Link to post
Share on other sites

So it goes to Steam, Origin, and U-AlreadyCan't-Play game files and then to the user.

Solution? Buy the Disk version, or pay on steam but pirate the download.

because torrenting them woild be way safer right? :P

Case: NZXT Phantom PSU: EVGA G2 650w Motherboard: Asus Z97-Pro (Wifi-AC) CPU: 4690K @4.2ghz/1.2V Cooler: Noctua NH-D15 Ram: Kingston HyperX FURY 16GB 1866mhz GPU: Gigabyte G1 GTX970 Storage: (2x) WD Caviar Blue 1TB, Crucial MX100 256GB SSD, Samsung 840 SSD Wifi: TP Link WDN4800

 

Donkeys are love, Donkeys are life.                    "No answer means no problem!" - Luke 2015

 

Link to comment
Share on other sites

Link to post
Share on other sites

Good thing my Quantum computer can decrypt these.  :ph34r:

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

Can't you just boot into a Linux USB, copy files off and erase the HDD? Though I guess that comes with the risk of the malware being copied over as well...I find it hard to believe there is no work-around.

 

What I said was silly, just make regular backups instead. Things like CryptoLocker are why you should invest in a 1-2TB External HDD and make regular backups. It isn't like an external HDD costs that much...

Link to comment
Share on other sites

Link to post
Share on other sites

Can't you just boot into a Linux USB, copy files off and erase the HDD? Though I guess that comes with the risk of the malware being copied over as well...I find it hard to believe there is no work-around.

I think the way these things work is by encrypting the files on your PC. So you would be able to copy the files. You would have to find out how to decrypt those files you pulled.

<p> AMD Ryzen 7 5800x l ASUS TUF X570-PLUS l G.Skill Trident Z Neo Series RGB 32GB l Sapphire Pulse RX 7900 XTX

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×