There is a hijacker that has been sending an unknown file/link to people via Skype saying it is a screen shot or meme etc and after being clicked it automatically downloads something onto their computer that isn't shown in the recent downloads. The hijacker then takes over their Skype, email, and by-passes the authenticator into their RuneScape account and starts asking people on their friends list for Skype information so they can try and send those people the same file/link, in addition to sending it to all the contacts on the Skype account after starting a friendly short conversation.
It has already happened to 4 people, that I am aware of, in the last 3 days including my clan and 2 other clans and I've been playing crowd control to stop it from happening to the rest of my clan and guests since I keep getting pm's about the suspicious file/link being sent to them via Skype.
Please do NOT click anything unknown on Skype even from a friend or family member's account!
It seems like common sense, but how many of us actually give a second thought to something our friend/family sends us before clicking to see what it is. Don't be afraid to talk with the person and ask what it is because the hijacker doesn't even attempt to fully imitate the person they hijacked, they just initiate conversation long enough to to sound excited to send it and make you interested in clicking it.
Luckily Jagex has been great at recovering RuneScape accounts and Bank Pins have been protecting everything they are supposed to protect, minus any items on your character during forced take over rip, but we have yet to recover any of the Skype accounts that have been hijacked and they are still rouge sending the file/link to people faster than we have been able to notify everyone.
/\
As a rule for everyone, never download any suspicious files from anyone on Skype as they could be keyloggers - look at the extension at the end, if it's
.exe
it's a huge red flag, unlike for example .mp4/.mp3 (and other video/audio formats).
Jigzag
said
:
There is a hijacker that has been sending an unknown file/link to people via Skype saying it is a screen shot or meme etc
First of all, secure your skype settings if you're going to be using skype.
You can lock down your privacy settings as much as you want.
The most important thing is to disable automatically accepting incoming files.
Jigzag
said
:
and after being clicked it automatically downloads something onto their computer that isn't shown in the recent downloads.
I'd assume that by now most people realize the importance of having an Internet Security Suite. I personally use Kaspersky Total Security because its the most aggressive security software I've found including features that need to be manually enabled like the Kaspersky Web Protection Add-On.
Aside from this, my default Web Browser is Mozilla Firefox including security plugins such as NoScript, uBlock Origin, AdBlock Plus, Disconnect, Blur, Self-Destructing Cookies and BetterPrivacy that block JavaScripts.
And if somehow all of that security failed to block a link I made the mistake of misclicking, I also added Firefox to Microsoft EMET (
http://microsoft.com/emet
) and I use the Windows SmartScreen Filter.
The biggest security flaw here is user error. The safest way to click on any link is to right click it > copy the link location > paste it to see the actual address before entering it. Or better yet, don't click it.
Jigzag
said
:
The hijacker then takes over their Skype, email, and by-passes the authenticator into their RuneScape account and starts asking people on their friends list for Skype information so they can try and send those people the same file/link, in addition to sending it to all the contacts on the Skype account after starting a friendly short conversation.
Lol malware infections don't work that way. Lets say that you get some kind of malware via some website you clicked or a file you accepted through skype....
Assuming its a zero-day virus your antivirus failed to block/delete, you can pretty much assume that all passwords you've saved on your web browser have been compromised which is why I personally use a Password Manager which stores them on a encrypted vault. Assuming you're using
unique passwords
and you're not saving them on your web browser, all of your accounts should not be compromised.
And this is why Jagex doesn't return items due to account hijacking. There are so many things that would potentially need to go wrong on your part for you to get hijacked in 2016, that Jagex can't be responsible for you not securing your PC, Email and Account.
Jigzag
said
:
It has already happened to 4 people, that I am aware of, in the last 3 days including my clan and 2 other clans and I've been playing crowd control to stop it from happening to the rest of my clan and guests since I keep getting pm's about the suspicious file/link being sent to them via Skype.
Phishing
has been on the rise since January 2016. I've had over 40 RuneScape Friends hacked because they had viruses on their PCs and failed to follow basic online safety guidelines.
Tell your friends to scan their PCs with these anti-malware tools:
1) Malwarebytes Anti-Malware
https://www.malwarebytes.org/mwb-download/thankyou/
2) AdwCleaner
https://toolslib.net/downloads/viewdownload/1-adwcleaner/
3) Junkware Removal Tool
https://downloads.malwarebytes.org/file/jrt/
4) Kaspersky Security Scan
http://www.kaspersky.com/kss
After that, they will need to reset their web browsers.
Ref: http://www.howtogeek.com/171924/how-to-reset-your-web-browser-to-its-default-settings/
Then they need to secure their emails:
- GMAIL: https://support.google.com/mail/checklist/2986618?hl=en
- MICROSOFT: http://windows.microsoft.com/en-US/windows/outlook/hacked-account
- YAHOO: https://help.yahoo.com/kb/account/secure-hacked-yahoo-account-sln3516.html
- AOL: https://help.aol.com/articles/account-management-identifying-suspicious-activity
Jigzag
said
:
It seems like common sense, but how many of us actually give a second thought to something our friend/family sends us before clicking to see what it is.
The average person gets their PC malware infected within 3 hours of using it and 90% of people in the world are not following basic online safety guidelines. These are the sad but true statistics. All we can do is create online safety & security awareness.
Some resources you may want to share with friends and family are:
https://blog.kaspersky.com/cyber-savvy-quiz/
https://www.microsoft.com/en-us/safety/online-privacy/phishing-symptoms.aspx
http://www.microsoft.com/about/philanthropies/youthspark/youthsparkhub/programs/onlinesafety/resources/
Jigzag
said
:
Luckily Jagex has been great at recovering RuneScape accounts and Bank Pins have been protecting everything they are supposed to protect, minus any items on your character during forced take over rip, but we have yet to recover any of the Skype accounts that have been hijacked and they are still rouge sending the file/link to people faster than we have been able to notify everyone.
The best thing to do if you know of a RuneScape account that has been hijacked is tweet
@JagexSupport
We have multiple JMods monitoring it that can quickly check an account for suspicious activity and lock it down giving you time to secure your PC and go through the account recovery process.
As for recovering the hijacked skype accounts, you should contact Microsoft. Even if you're unable to recover the account through the conventional recovery system, you may be able to send them a ticket to regain access to the account.
https://support.skype.com/en/faq/FA10946/my-skype-account-has-been-suspended-or-hacked
Sadly we were one of the secondary clans that were involved.
One clan mates account was hacked. The hacked account then tried to get people in my clan to loan them things or asked them to add them on skype.
He/she also tried to send an exe file to some people in the clan he already had on skype. Luckily more people didn't fall for it.
Thanks for the advice Pescao. Hopefully it's okay if I copy some of it to my clan forums.
To top it off, in the past week or 2 the name impersonating scam was attempted several times in our cc.
The name impersonation scam is becoming more and more common and I see plenty of players Tweet about it when i'm over helping on the Twitter side. My best advice on those impersonators is make sure your clan knows what's going on and keep them in the loop at all times.
If you think clan members could be subjected to this, ask them to place their friends list on friends only, now I know the fact that many players like to play with their friends list on because in clans you never know someone may contact you to ask about your clans recruitment as a example or for any other reason. But if you know this type of thing is happening then locking down the clan to "Ranks only" and asking members to put their PM to "friends only" for a while is a pretty reasonable way to make sure you don't get contacted by the wrong sort of people.
Another thing I will mention is that make sure your clan members know that they should never trust trade items they are not willing to loose, to anyone. I know you hear this a lot but keep reminding your members of that, it doesn't matter who the person is, don't trust trade items you are scared to loose because there is a possibility it might get taken, even by a close friend/high clan rank, you just don't know.
With this matter it really does come down to awareness and prevention is better then dealing with the aftermath of the situation, however there is always that in game report option for item scamming which can easily apply to situations like this, so even though there isn't really a rule against "Player Impersonation" as such, as players are allowed to have any name they want, this is a potentially a way of item scamming so can be reported it as such and Jagex will review the evidence and take action where required.