About RSS
Search for: in 

Windows Watch - an XP & Vista blog

R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Rootkit software infects gamblers' computers

Playing online increasingly a gamble as hackers hijack PCs

Dinah Greek, Computeract!ve 17 May 2006
ADVERTISEMENT

Gamblers on an online gaming site have had their PCs infected with a rootkit.

Malicious rootkit software , known as RBCalc.exe - or the Rakeback calculator -  has been distributed from Checkraised.com's website to its customers' PCs. Rootkits are used by malware authors to hide malicious software.

This attack was found by security company F-Secure's rootkit detection technology, Blacklight. The software dropped four executable files into the gamers' computers and used the rootkit to hide its presence.

The malware then covertly stored gamblers' information and the executable files allowed hackers remote access to the victims' computers.

The stolen information has been used to log into various online poker websites including Partypoker, Empirepoker, Eurobetpoker and Pokernow. Having gained access, the hacker can then play poker against himself, losing on purpose and reaping the rewards.

Shortly after the discovery, Checkraised.com removed the offending exe file from its website and issued an official statement on its website advising users to change their poker site passwords as well as offering instructions for manually removing the malware.

Kimmo Kasslin, a researcher at F-Secure's data security laboratory, said: " Following the exponential rise of interest in online poker, it is inevitable that malware authors would follow suit with programmes to separate players from their money.

"What is significant is the fact that this particular scam was hosted, albeit unwittingly, on a legitimate site, using rootkit technology to cloak itself."

Kasslin continued: "Malware authors are increasingly wise to standard anti-virus and intrusion techniques and are constantly looking for a new exploits. Having standard data security software from the bigger vendors would not have protected you against this rootkit exploit. F-Secure's software does."

F-Secure has advised that people visiting the Checkraised.com site to ensure their PCs are not infected. A free scan is available from the F-Secure Online Scanner Next Generation Beta , which also now has rootkit detection capabilities through the F-Secure BlackLight engine.

People can also read  updates on this story from F-Secure' Data Security Lab weblog as the news unfolds.


All Hacking and Cyber-crime

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Foster Wheeler
Analyst Programmer - Applix TM1 -Competitive Salary - ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals ... more >
| Foster Wheeler
Analyst Programmer - JDEdwards- ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals lt;/p> Our UK-headquartered operations ... more >
| Google
The area: DoubleClick DoubleClick, a Google company, enables top marketers, publishers and agencies to utilize DoubleClick's expertise in ad serving, rich media, video and affiliate marketing to help them make the most of the digital ... more >
| Google
The area: Engineering Management Google's engineering teams exhibit high energy, deep technical skills and a drive to get things done. Our Engineering Managers need to be technical leaders and motivators who are comfortable leading these ... more >
More job opportunities
ADVERTISEMENT