{"id":8238,"date":"2012-10-12T12:00:35","date_gmt":"2012-10-12T19:00:35","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=8238"},"modified":"2018-05-29T12:15:48","modified_gmt":"2018-05-29T18:15:48","slug":"new-russian-service-sells-access-to-compromised-steam-accounts","status":"publish","type":"post","link":"https://www.webroot.com/blog/2012\/10\/12\/new-russian-service-sells-access-to-compromised-steam-accounts\/","title":{"rendered":"New Russian service sells access to compromised Steam accounts"},"content":{"rendered":"<p>For years, cybercriminals have been trying to capitalize on the multi-billion dollar PC gaming market. From active development of game cracks and patches aiming to bypass the distribution protection embedded within the games, to today&#8217;s active data mining of a botnet&#8217;s infected population looking for gaming credentials in an attempt to resell access to this asset, cybercriminals are poised to capitalize on this market.<\/p>\n<p>What are some current trends within this market segment, and how are today&#8217;s modern cybercriminals monetizing the stolen accounting data belonging to gamers internationally? Pretty simple &#8211; by automating the data mining process and monetizing the results in the form of E-shops selling access to these stolen credentials.<\/p>\n<p>In this post, I&#8217;ll profile a recently launched Russian service selling access to compromised <a href=\"http:\/\/en.wikipedia.org\/wiki\/Steam_(software)\"><strong>Steam accounts<\/strong><\/a>.<\/p>\n<p>More details:<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8243\" title=\"Russia_Hacked_Steam_Accounts\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts.png\" alt=\"\" width=\"614\" height=\"277\" \/><\/a><\/p>\n<p>The service offers access to Standard accounts, Elite Steam IDs, activation keys, and most interestingly, the opportunity to resell access to these fraudulently obtained assets, through an affiliate network. Let&#8217;s take a peek at its inventory of fraudulently obtained assets.<\/p>\n<p><strong>Second screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_01.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8244\" title=\"Russia_Hacked_Steam_Accounts_01\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_01.png\" alt=\"\" width=\"614\" height=\"353\" \/><\/a><\/p>\n<p><strong>Third\u00a0screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_02.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8245\" title=\"Russia_Hacked_Steam_Accounts_02\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_02.png\" alt=\"\" width=\"614\" height=\"320\" \/><\/a><\/p>\n<p><strong>Fourth screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_03.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8246\" title=\"Russia_Hacked_Steam_Accounts_03\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_03.png\" alt=\"\" width=\"367\" height=\"331\" \/><\/a><\/p>\n<p><strong>Fifth screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_04.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8247\" title=\"Russia_Hacked_Steam_Accounts_04\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_04.png\" alt=\"\" width=\"375\" height=\"373\" \/><\/a><\/p>\n<p><strong>Sixth screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_05.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8248\" title=\"Russia_Hacked_Steam_Accounts_05\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_05.png\" alt=\"\" width=\"614\" height=\"298\" \/><\/a><\/p>\n<p><strong>Seventh screenshot of the Russian service selling access to compromised Steam accounts:<\/strong><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_061.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-8250\" title=\"Russia_Hacked_Steam_Accounts_06\" src=\"http:\/\/webrootblog.files.wordpress.com\/2012\/09\/russia_hacked_steam_accounts_061.png\" alt=\"\" width=\"614\" height=\"296\" \/><\/a><\/p>\n<p>This service is a great example of a concept called &#8220;malicious economies of scale&#8221;. Thanks to the purchase automation of fraudulently obtained assets, next to a fully working affiliate network, the cybercriminals behind the service demonstrate a decent understanding of the monetization tactics applied by fellow cybercriminals.<\/p>\n<p>We&#8217;ll continue monitoring the development of the service.<\/p>\n<p><em>You can find more about Dancho Danchev at his\u00a0<a href=\"http:\/\/linkedin.com\/in\/danchodanchev\"><strong>LinkedIn Profile<\/strong><\/a>. You can also\u00a0<a href=\"http:\/\/www.twitter.com\/danchodanchev\"><strong>follow him on \u00a0Twitter<\/strong><\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For years, cybercriminals have been trying to capitalize on the multi-billion dollar PC gaming market. From active development of game cracks and patches aiming to bypass the distribution protection embedded within the games, to today&#8217;s active data mining of a botnet&#8217;s infected population looking for gaming credentials in an attempt to resell access to this [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[12023,12011,12003,12029,12017,10773,12035,12037,12027,12019,12009,12025,12013,5551,12015,12007,12033,12021,12005,12031],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/8238"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=8238"}],"version-history":[{"count":2,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/8238\/revisions"}],"predecessor-version":[{"id":24573,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/8238\/revisions\/24573"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=8238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=8238"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=8238"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=8238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}