Trojan program hijacks World of Warcraft accounts despite two-factor authentication

The malware is bundled with a fake Curse Client, the game developer said

A new Trojan program is targeting users of the popular online role-playing game World of Warcraft and is capable of hijacking accounts even if their owners use two-factor authentication.

"We've been receiving reports regarding a dangerous Trojan that is being used to compromise players' accounts even if they are using an authenticator for protection," a technical support representative from Blizzard Entertainment, the game's developer, said Friday in a message on the Battle.net forums. "The Trojan acts in real time to do this by stealing both your account information and the authenticator password at the time you enter them."

Battle.net is Blizzard's online gaming service and the Battle.net Authenticator is a physical token or a mobile application that generates unique codes used as a second factor of authentication in addition to the user password.

By intercepting Battle.net log-in attempts on infected computers, the Trojan program can capture both the regular user names and passwords and the unique codes generated by authenticators. Since the latter are essentially one-time passwords that expire after being used, the legitimate log-in attempts are blocked by the malware, so while victims try to figure out what went wrong, the captured information is sent to the attackers who can then hijack the accounts.

This is similar to how other Trojan programs allow attackers to defeat two-factor authentication used by Internet banking sites.

Signs of infection with this new malware include the presence of a program called "Disker" or "Disker64" in the Windows start-up list. Users can view this list by generating a MSInfo report using instructions on the Battle.net site and then look under the "Startup Program" section.

In a later update on the Battle.net forum, another Blizzard tech support representative said that the company tracked down the source of infection to a fake, but working Curse Client distributed from a fake website. The Curse Client is a third-party application that can be used to install add-ons and modifications for several games including World of Warcraft.

Users who suspect their computers have been infected with this Trojan program were advised to uninstall the Curse Client and then run a scan with Malwarebytes, an anti-malware tool that has a free version. However, most security products should be able to detect the Trojan program by now, the Blizzard representative said.

Uninstalling the rogue Curse Client is an important step because the client is actively trying to hide the malware's presence.

"For those of you interested in these MitM [man-in-the-middle] style attacks, this is the only confirmed case we've seen in several years outside of the 'Configuring/HIMYM' trojan in early 2012 that hit a handful of accounts," the Blizzard representative said. "These sort of outbreaks are annoying, but an Authenticator still protects your account 99% of the time."

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags Blizzard Entertainmentonline safetysecurityAccess control and authenticationmalware

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?