An online tool billed as able to calculate the amount of money taken by poker sites is actually malware designed to steal online poker players' login details
RBCalc.exe creates a backdoor to covertly store gamblers' information
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Poker rootkit turns players into losers

Malware steals your password, then raises with 7-2 offsuit

Matt Chapman, vnunet.com 17 May 2006
ADVERTISEMENT

An online tool billed as able to calculate the amount of money taken by poker sites is actually malware designed to steal online poker players' login details.

The rakeback calculator RBCalc.exe, which was distributed on gaming site Checkraised.com, creates a backdoor into users' computers to covertly store gamblers' information. 

The program silently drops four executable files into the player's system and uses a rootkit driver to conceal the operation.

The tool's author could then steal log-in information for various online poker websites including Partypoker.com, Empirepoker, Eurobetpoker and Pokernow.
Having gained access, the hacker could then empty the compromised account by playing poker against themselves and losing on purpose.

The backdoor was uncovered by F-Secure's Blacklight rootkit detection technology.

Shortly after the discovery, Checkraised.com removed the offending file from its website and issued an official statement advising users to change their poker site passwords as well as offering instructions for manually removing the malware.

"Following the exponential rise of interest in online poker, it is inevitable that malware authors would follow suit with programs to separate players from their money," said Kimmo Kasslin, a researcher at F-Secure's data security laboratory.

"What is significant is the fact that this particular scam was hosted, albeit unwittingly, on a legitimate site and used rootkit technology to cloak itself."

F-Secure warned players that standard security software from the bigger vendors would not have protected against this rootkit exploit.

See also:

Gambling website 888.com has claimed that the online poker bubble will burst and that the rate of user sign-ups cannot be sustainedUsers bored with low quality gameplay, claims startup  12 May 2006
Research suggests that the future for online gambling is bright, as its main audience is youngGot to know when to hold 'em  23 Feb 2006
The US is attempting to clamp down on overseas web gambling sitesPoliticians attempt to block overseas betting websites  20 Feb 2006
Online gamblingEyes down for a full house  16 Jan 2006
BVS Video PokerAn enjoyable game that simulates video poker  03 Oct 2005
Gambling spamInboxes deluged with junk mail relating to betting  01 Sep 2005

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities