Reliable Technology ServicesReliable Technology ServicesReliable Technology ServicesReliable Technology Services
Menu
  • Home
  • About Us
  • Services
    • Managed IT Services
      • Remote Monitoring & Maintenance
      • Onsite and Remote Support
      • Managed Security Services
    • Cloud Services
      • Cloud Email Solutions
      • Managed Backup Services
      • Cloud Data Storage Solutions
    • IT Consulting
      • Disaster Recovery & Business Continuity
      • IT Vendor Management Services
      • Network Infrastructure Planning, Design & Implementation
    • Cybersecurity
      • Employee Cybersecurity Training
      • Penetration Testing & Vulnerability Scanning
      • Cybersecurity Risk Assessments, Software and Services
  • FAQ’s
  • Blog
  • Contact

Gamer or Gambler? Watch Out for this New Social Engineering Threat

  • Home
  • Blog
  • Gamer Or Gambler? Watch Out For This...

Gamer or Gambler? Watch Out for this New Social Engineering Threat

CategoriesInformation Security

Rick Ornato

April 24, 2023

0 0

Share this post

Ice Breaker.

No, not the kind that you play during team building exercises. This is the name of a recent social engineering threat that has emerged in the past few months. They play on emotions to get their target to react without thinking, in a way that allows the threat actor to gain access to your accounts or systems.

The problem is, it’s not you that they’re targeting this time.

How Ice Breaker Strikes

Security experts in Israel first noticed the multi-step threat in September 2022, and the attacks have only grown more prevalent since. Gaming and gambling events are beginning soon, such as the ICE London 2023 game convention in February (which is actually where the threat got its name) or any given night in Las Vegas. Whichever one is your hobby, watch out for any suspicious activity on your accounts while we’re still learning more about how this threat works!

Let’s walk through it.

The cybercriminal starts by pretending to be a customer with an online platform of some kind, like a digital casino or tournament site. They contact the support team there, sounding like a non-native English speaker and requesting to talk to someone else who is too. This is to decrease the chances of getting flagged as a scam. To worsen the odds further, many online platforms in the gaming and gambling industries tend to outsource their customer support, so they can’t necessarily impose their own security awareness training and warn about these kinds of tricks.

Once the threat actor is on with support, they’ll send a screenshot of a supposed problem that they’re having and ask for help resolving it. The “picture” is often sent through external platforms like Dropbox, or a fake screenshot hosting website.

Only when the team member clicks on the link, it doesn’t open a JPG — instead malware instantly begins to download and start running.

What Does Ice Breaker Do?

After the malware has been downloaded onto the customer support agent’s system, it creates a backdoor through JavaScript. This allows the hacker to run processes, steal data, move or take files, and really wreak whatever havoc they like.

So far, whomever is deploying Ice Breaker seems to run one of two final payloads on the target company. Either a loader spawns a Houdini RAT to give them remote access to your system, or an automatic installer package given the moniker Ice Breaker backdoor (clever, right?). Then they can view behind the scenes goings-on in the company, steal user or employee passwords, run more processes and continue gathering information to launch worse attacks.

Be careful of phishing scams coming from these sites in particular. Even legitimate company email addresses may have been compromised by this attack. If something seems suspicious, listen to your gut and do some more digging.

Conclusion

Gaming and gambling are common targets for cybercriminals, since there’s always money in a tournament or casino. You should always be careful when entering payment info online, but especially if the purpose of the platform is to hold large amounts of money. It’s a natural target for thieves, that puts your accounts, funds and privacy at risk.

Take time to research where you’re storing you funds. Do they have a good security system? Are they encrypting data and verifying users before they send links to customer support? What steps will they take to recover your lost data or funds in the event of a breach? These are the kinds of questions you should ask yourself before trusting your bank details to any website.

If you do get notified that your information has been compromised in a breach, affecting the gaming and gambling industries or anywhere else, you should immediately report it to the authorities, including your IT provider. Change your passwords and keep a close eye on your finances and other accounts for any suspicious activity!

In the modern threat landscape, knowledge is still the greatest power.

References

  • https://thehackernews.com/2023/02/experts-warn-of-ice-breaker.html
  • https://www.cybersecurityconnect.com.au/strategy/8660-new-ice-breaker-threat-actor-targets-gambling-industry-support-lines

Related Post

JULY 31, 2023

3 Smart Ways to Hide Your...

Our modern world is extremely digitized; because of that, we constantly use...

00

JULY 24, 2023

Consumer Financial Protection...

Consumer Financial Protection Bureau, commonly known as CFPB, is a government agency...

00

JULY 17, 2023

How Well Do You Know Your...

The faster you can identify suspicious activity on your network, the faster you can...

00

JULY 10, 2023

Beginning of the End? Behind...

Since bursting onto the scene in November 2022, ChatGPT has changed the game for...

00

JULY 3, 2023

A Real Pain: CACTUS...

Virtual private networks, more commonly known as VPNs, have long been touted as a more...

00

JUNE 29, 2023

Crash Course in Keylogging:...

What if threat actors could see everything that you did online? Everything you searched,...

00

Managed IT Services

  • Managed IT Services
    • Onsite and Remote Support
    • Remote Monitoring & Maintenance
    • Managed Security Services
Get a free IT Consultation
Contact Us

© 2018 Reliable Technology Services, All Rights Reserved.