Archive notice: This article was originally published on September 12, 2007. Links and embedded videos are preserved as part of the historical record.
An essay by Sergej Golovanov of Kaspersky Lab gets to the bottom of this problem. An executive summary can be requested from Rainer Bock, essential media.
Players of online games are constantly in the sights of cybercriminals, who generally use three different methods to steal confidential game data. Social engineering is the term used for the approach of getting users to disclose their login details through phishing emails or direct requests during the game. Advanced players, however, hardly fall for this anymore. The second method is the exploitation of server vulnerabilities. This is costly and involves technical difficulties, so this practice is not particularly widespread.
The most common method at present is the use of malicious programs to steal passwords. Trojans or worms are used for this.
It is remarkable that geographical characteristics of password theft can be identified: More than 90 percent of all Trojans for online games are programmed in China. 90 percent of all passwords stolen by Trojans can be attributed to players on South Korean sites.
Because protection against theft lies largely with the players themselves, online gamers should take basic precautions, listen to their common sense and use a reliable antivirus program, Golovanov concludes.
Further Links:
- The essay is available here