Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
By All Means, Save Princess Peach; But Not By Playing This Game
Facebook   X   LinkedIn   Email

By All Means, Save Princess Peach; But Not By Playing This Game

October 12, 2023

Would you like to play a game? If you’re considering taking a turn at playing one on your Windows PC, you should also consider the findings of a recent report from researchers at Cyble. Following the Super Mario Brothers movie and ahead of the release of the new Nintendo Super Mario Bros: Wonder game for the Nintendo Switch, they uncovered a version of the Super Mario 3: Mario Forever installer being abused by hackers to infect systems with all kinds of bad guy cheats.

Upon downloading and extracting the game to a user's PC, a package contains three executables. One of them installs the legitimate game, while the other two, named "java.exe" and "atom.exe," are surreptitiously installed in the user's AppData directory without their knowledge. Once it’s penetrated the fortress of your systems, it gets to work not to save Princess Peach, but to wreak havoc on your device.

The first executable is used to mine Monero cryptocurrency, utilizing the infected PC's resources for the hackers' benefit. The second executable, called "SupremeBot," downloads an additional payload named "winme.exe" from a command and control (C&C) server operated by the hackers. This additional payload poses a more significant threat as it contains the Umbral Stealer, which is capable of extracting passwords and cookies containing session tokens from the user's browser. That means, it can steal your stuff!

But wait! It doesn't stop there; it can also pilfer funds from cryptocurrency wallets and steal authentication tokens for popular platforms like Discord, Minecraft, Roblox, and Telegram.

What makes Umbral Stealer even more concerning is its ability to capture screenshots of a Windows desktop and access the user's webcam, effectively spying on them without detection by Windows Defender anti-malware software; which by the way, you should have active and updated on your Windows systems.

Finally, the malware may thwart the best of all the antivirus (AV) software by blocking communication with the developers’ sites, thereby reducing the effectiveness of their protection.

What can you do? First, don’t download the game. While earlier versions of this fan-made remake of the 2003 game are fine, it’s been taken over by the bad guys lately. So, avoid it on the PC. Instead, if you really want to try it, use it on a Nintendo Switch.

If you have downloaded it to your PC lately, do a thorough malware scan and remove files found by your AV software. Don’t forget to update your AV first to make sure you have the latest version. Even if you downloaded it ages ago, it’s still a good idea to scan and make sure all is well.

If you find that your PC was compromised, you should change your gaming passwords. Make sure each account you have, whether gaming or not, has its own unique password with a combo of letters, numbers, and special characters.

Because gamers have long been and will continue to be targets for cybercriminals, stick to downloading games from trustworthy sources and the official app stores for your devices.


Children As Online Targets--What Every Parent Needs To Know

Your Security

Children As Online Targets--What Every Parent Needs To Know

Adults should be well-aware of hacking and the risks involved when traversing online. But what many don’t know is the sad truth that children are also targets of online abuse. Sadly, this includes infants. The good news is that parents aren’t helpless when it comes to protecting their child’s online activities and real-world identities. Knowing the signs of child identity theft, other harmful vulnerabilities and how you can help prevent them is a great way to start. READ FULL STORY

Activision Gaming Breached When Employee Gets Phished With SMS Text

Your Security

Activision Gaming Breached When Employee Gets Phished With SMS Text

In their own words, Activision explains what they do as “We connect and engage the world through epic entertainment.” Late last year, the gaming powerhouse with hits like “Call of Duty” and “Candy Crush” underwent an assault on their data systems. What started the attack was an employee who answered an SMS text, a phishing text. That’s all it took to steal sensitive company data: one phishing text + one response = a data breach. Activision says their information security team immediately settled the situation before any sensitive data was lost. But not everyone agrees it was that clear-cut. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...