Malwarebytes Warns of New 'Steam Guard' Phishing Scam

June 25, 2014 - GamePolitics Staff

Malwarebytes researchers have discovered yet another phishing scheme related to gaming. The latest is a Steam Guard phishing scam that steals users SSFN files and Steam log-in credentials, according to Malwarebytes researchers.

Previous Steam Guard scams would prompt users to upload their SSFN files to a fishing page, but this latest scam goes to great lengths to automate the process. The enticing bait for gamers is a community profile full of items ready for trading.

Once users show some interest in the scam, they are redirected to a fake log-in page, asked to enter Steam credentials, and then asked to run a Steam Guard file. That Steam Guard file is a fake and instead uploads the unsuspecting victim's SSFN file and log-in credentials to a domain in Russia. Armed with the files and the personal information, the phisher will have easy access to the victim's account.

"This is the first fake Steam Guard and SSFN file swiper I've come across so far," says Chris Boyd, malware intelligence analyst at Malwarebytes.

Malwarebytes will have a full report on this latest phishing scheme soon on its official blog.


Re: Malwarebytes Warns of New 'Steam Guard' Phishing Scam

Good thing I never upload shit to any site unless I check it first.


Plus if Steam needs it they can get it, easily.

Re: Malwarebytes Warns of New 'Steam Guard' Phishing Scam

This is especially bad since now Steam Paypal payments no longer route to Paypal's site for login.

Too bad people thought my suggestion about allowing users to locvation lock the IPs that have access to their account (or even whitelist only specific IPs) was bad.

Re: Malwarebytes Warns of New 'Steam Guard' Phishing Scam

Wow... they "discovered" it just mere weeks after the community.

Forgot your password?
Username :
Password :

Be Heard - Contact Your Politician