Edit : The latest mutation appears to be targetting profile comments, claiming to be an inventory screenshot of someone who wants to set up a trade, but still operates in the same way. Be careful!
~~

There is a recent trojan with a little twist going around like wildfire at the moment.
Instead of the usual dumb link to an obvious malware site or infected file, this trojan instead travels through your steam friends lists, and appears as a direct link to an image file on a normal image hosting site. Now, think about this for a moment, if a close friend of yours sent you a message saying "Wow, some people : http://photo-wrangler.net/12513.JPG" you probably wouldn't think twice about clicking it, would you?

When you try to access the site, it attempts to stealth-download something (usually an .scr) into your computer without giving the user any prompts such as the usual "save to" dialog box, immediately infecting you and relaying the same message to everyone on your steam friends list. People have said that this trojan is designed to get access to your steam inventory and gift your gear away to a bot, but I cannot confirm that. I would be more worried about it leaving keyloggers or taking your account password. If you have a good antivirus or anti-malware installed, you will probably get an interrupt-alert that prevents it if you try to visit in a browser window external to steam, but I would still be careful because these kinds of things tend to try adapt over time.

For reference, the message itself (at this point) appears to be : "WTF?????? [evil link].JPG"
If you got this message, don't click it, alert the sender that they're infected, and advise them to scan for malware / look for keyloggers in their active processes, and then to change their password.

.

TL;DR VERSION :
There is a trojan going around the steam friends lists that is using a direct image link instead of a suspicious file. It is literally a link to a .JPG file that looks like a random piece of humour/news.

Here's a quick summary image I made myself of what to look out for : http://i59.tinypic.com/2mg2uth.jpg
Seriously. Yes. It is that easy to get caught by it. No, it isn't a joke. That image I just posted is a reminder that if you think your shit doesn't stink just because you don't open random .XLS and .EXE files, consider how the average steam conversation goes, and how innocent image links can seem and slip by your guard.

9 years ago*

Comment has been collapsed.

God, I had like 10 of these just today

9 years ago
Permalink

Comment has been collapsed.

"immediately infecting you"

SCR files exactly same as EXE files. Only difference is extension and it will be coded to accept CLI parameters for screen saver functionality in real screen savers.

So as long as you not open them, it can't infect you.

9 years ago
Permalink

Comment has been collapsed.

Funny, that. The person who gave me the first message (to let me know the thing even existed) told me he caught it through just clicking on an image link. No prompt to save a file to anywhere, no need to even open it. The only reason his antivirus didn't intercept it was because he had it temporarily disabled while he was downloading a huge patch for some game or other (I think it was interfering or slowing the process, or so he claims? I dunno).

He clicked the link, got a blank page, then realised what just happened when people started replying to the automated message it gave out. When I received the message, I was suspicious, so opened it in a browser separate from steam, and NOD32 caught and prompted me if I wanted it scrubbing. I can't verify if what this guy said was accurate, but hasn't there been malware that transmit itself through adbars, that didn't require manual opening?

I mean, christ, as I mentioned elsewhere, self-running executables have been around since the days of hclean32. I won't claim to know how all varieties of malware operate, but user interaction is not always required. In this case, all it needs the user to do is navigate to the site serving as a vector.

9 years ago
Permalink

Comment has been collapsed.

Someone posted a link on my profil ( I deleted it), here the guy who posted on my profile has the same (twice) on his profile:

I havent clicked it so i don't know if it's related to this Trojan of yours. But better be on the watch out as well.

9 years ago
Permalink

Comment has been collapsed.

I saw that one around too! FYI I'd suggest you to remove the link to the profile of that user since calling out is against the rules of the website.

If anyone wonders the message is: Hi bro you need it? [Phishing/virus/trojan etc. link here]

9 years ago
Permalink

Comment has been collapsed.

It's getting really annoying. Now I get one of those comments every few hours.

9 years ago
Permalink

Comment has been collapsed.

I warned some friends about it. I did hear about our Payday 2 group mass clicking that link, because someone said it was trusted.

9 years ago
Permalink

Comment has been collapsed.

An unknown Steam lvl 0 user posted on my profile .png link, I deleted it at once, so watch yourselves, guys. It was 2-3 days ago.

9 years ago
Permalink

Comment has been collapsed.

i got it about 20 times so far.
also i got 2 - 5 new comments monthly also lv 0 user.

9 years ago
Permalink

Comment has been collapsed.

bump this up.
also

  • get high class antivirus
  • ad block / ghostery make sure u use secure browser with antivirus firewall
  • antimalware (i got asc for my self)
  • remove,block,report the suspect.
9 years ago
Permalink

Comment has been collapsed.

I'm not so sure about reporting. The people who send you the links aren't hijacked, simply infected. It would likely place more of a burden on the already overstretched and slow-responding steam support.

9 years ago
Permalink

Comment has been collapsed.

Simple rule of thumb, NEVER click any link you get sent through Steam regardless of who its from.

9 years ago
Permalink

Comment has been collapsed.

9 years ago
Permalink

Comment has been collapsed.

had like 15 of that annoying phishing stuff posted on my profile comments during the last few days. Turned them to friends only now, for the first time ever.

vOLVO really has to do something about it...

9 years ago
Permalink

Comment has been collapsed.

As far as phishing goes, they do tend to target people who actively trade more often. Thankfully people tend to be more aware of how phishing works.

Still, it's not quite the same thing as what I was discussing. Just saying~

9 years ago
Permalink

Comment has been collapsed.

you should rename topic to "trojan spreading through stupid people downloading and running it"

9 years ago
Permalink

Comment has been collapsed.

Given the fact that people supposedly aren't manually downloading and running anything in regards to this trojan, why would I?
Maybe you should edit your comment to say "I didn't read the thread"

9 years ago
Permalink

Comment has been collapsed.

I got again a scam attempt from a private profile, with the usual scr file.
Played with the link inside a virtual machine: the scr file is hosted at a googleusercontent site, which is obviously owned by Google. The file name is usually a "screen_#####.scr".
I peeked inside the contents, and I assume it probably creates a new (admin?) user under the "Users" directory...
https://dl.dropboxusercontent.com/u/9813034/K%C3%A9perny%C5%91k%C3%A9p%20%E2%80%93%202015-01-16%2018%3A44%3A36%20censored.png

9 years ago
Permalink

Comment has been collapsed.

Thanks for the info regarding this other trojan.

9 years ago
Permalink

Comment has been collapsed.

I just got two extra lv 0 invitation thanks to this post!
Yay!

9 years ago
Permalink

Comment has been collapsed.

yep, I'm being spammed by them.

9 years ago
Permalink

Comment has been collapsed.

Closed 7 years ago by Uroboros.