Simple clear advice in plain English

Rootkit software infects gamblers' computers

Playing online increasingly a gamble as hackers hijack PCs

Gamblers on an online gaming site have had their PCs infected with a rootkit.

Malicious rootkit software , known as RBCalc.exe - or the Rakeback calculator -  has been distributed from Checkraised.com's website to its customers' PCs. Rootkits are used by malware authors to hide malicious software.

This attack was found by security company F-Secure's rootkit detection technology, Blacklight. The software dropped four executable files into the gamers' computers and used the rootkit to hide its presence.

The malware then covertly stored gamblers' information and the executable files allowed hackers remote access to the victims' computers.

The stolen information has been used to log into various online poker websites including Partypoker, Empirepoker, Eurobetpoker and Pokernow. Having gained access, the hacker can then play poker against himself, losing on purpose and reaping the rewards.

Shortly after the discovery, Checkraised.com removed the offending exe file from its website and issued an official statement on its website advising users to change their poker site passwords as well as offering instructions for manually removing the malware.

Kimmo Kasslin, a researcher at F-Secure's data security laboratory, said: " Following the exponential rise of interest in online poker, it is inevitable that malware authors would follow suit with programmes to separate players from their money.

"What is significant is the fact that this particular scam was hosted, albeit unwittingly, on a legitimate site, using rootkit technology to cloak itself."

Kasslin continued: "Malware authors are increasingly wise to standard anti-virus and intrusion techniques and are constantly looking for a new exploits. Having standard data security software from the bigger vendors would not have protected you against this rootkit exploit. F-Secure's software does."

F-Secure has advised that people visiting the Checkraised.com site to ensure their PCs are not infected. A free scan is available from the F-Secure Online Scanner Next Generation Beta , which also now has rootkit detection capabilities through the F-Secure BlackLight engine.

People can also read  updates on this story from F-Secure' Data Security Lab weblog as the news unfolds.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Lenovo Lephone K2 Android Smartphone

Porn app hides Trojan to target Android smartphones warns F-Secure

App hides a Trojan that hijacks phones to send premium rate sms

internet-banking-login-button

More people are banking online, but also failing to secure their PCs

Consumers banking online fail to realise they have responsibility to ensure their PCs are free of malicious software

Desktops screenshot

25 free Microsoft Windows Tools

Microsoft has many free downloads, but they're sometimes tricky to find. Here's a round-up of some of the most useful tools in the Sysinternals Suite

Question & Answer

Q.Why can't my browser find the website address I typed...

> Read the answer

Q.All updates have been downloaded, so why won't Windows...

> Read the answer

Q.How do I stop Windows 7 search?

> Read the answer

Best deals on the web

img

Apple MacBook Pro (MC724LL/A)

£999.99- Buy it now

img

Sony Vaio VPCF23P1E/B

£679.98- Buy it now

img

Samsung 300E5A-A01DX

£449.99- Buy it now

Great benefits for subscribers!

Most popular articles

Poll

Which is your preferred web browser

Jargon Buster

Computing terms explained in plain English

VGA

Video Graphics Array. Standard socket for connecting a monitor to a computer.

Great shopping deals from Computeractive