Forums

WARNING about hijacker!

Quick find code: 86-87-183-65821620

Jigzag
Jul Member 2013

Jigzag

Posts: 659 Steel Posts by user Forum Profile RuneMetrics Profile
I wanted to pass on a WARNING to all clans!

There is a hijacker that has been sending an unknown file/link to people via Skype saying it is a screen shot or meme etc and after being clicked it automatically downloads something onto their computer that isn't shown in the recent downloads. The hijacker then takes over their Skype, email, and by-passes the authenticator into their RuneScape account and starts asking people on their friends list for Skype information so they can try and send those people the same file/link, in addition to sending it to all the contacts on the Skype account after starting a friendly short conversation.

It has already happened to 4 people, that I am aware of, in the last 3 days including my clan and 2 other clans and I've been playing crowd control to stop it from happening to the rest of my clan and guests since I keep getting pm's about the suspicious file/link being sent to them via Skype.

Please do NOT click anything unknown on Skype even from a friend or family member's account!


It seems like common sense, but how many of us actually give a second thought to something our friend/family sends us before clicking to see what it is. Don't be afraid to talk with the person and ask what it is because the hijacker doesn't even attempt to fully imitate the person they hijacked, they just initiate conversation long enough to to sound excited to send it and make you interested in clicking it.

Luckily Jagex has been great at recovering RuneScape accounts and Bank Pins have been protecting everything they are supposed to protect, minus any items on your character during forced take over rip, but we have yet to recover any of the Skype accounts that have been hijacked and they are still rouge sending the file/link to people faster than we have been able to notify everyone.
/\
\/
/\
\
`. I Know Right `.
\
\/
/\
\/ ~ * . clan .

10-Aug-2016 11:13:50

Scret
Mar Member 2018

Scret

Posts: 25,434 Sapphire Posts by user Forum Profile RuneMetrics Profile
It doesnt seem like common sense, it is common sense.

Pretty brutal scam though
`*•.¸(*•.¸(`*•.¸+¸.•*´)¸.•*)¸.•*´
+«´¨`•°
SKILL SCHOOL
•´¨`»+
. .•*(¸.•*´(¸.•*´+`*•.¸)`*•.¸)*•.

10-Aug-2016 13:19:29 - Last edited on 10-Aug-2016 13:21:40 by Scret

Pescao6
Aug Member 2007

Pescao6

Posts: 9,075 Rune Posts by user Forum Profile RuneMetrics Profile
Jigzag said :
There is a hijacker that has been sending an unknown file/link to people via Skype saying it is a screen shot or meme etc

First of all, secure your skype settings if you're going to be using skype.

You can lock down your privacy settings as much as you want.


The most important thing is to disable automatically accepting incoming files.


Jigzag said :
and after being clicked it automatically downloads something onto their computer that isn't shown in the recent downloads.

I'd assume that by now most people realize the importance of having an Internet Security Suite. I personally use Kaspersky Total Security because its the most aggressive security software I've found including features that need to be manually enabled like the Kaspersky Web Protection Add-On.

Aside from this, my default Web Browser is Mozilla Firefox including security plugins such as NoScript, uBlock Origin, AdBlock Plus, Disconnect, Blur, Self-Destructing Cookies and BetterPrivacy that block JavaScripts.

And if somehow all of that security failed to block a link I made the mistake of misclicking, I also added Firefox to Microsoft EMET (
http://microsoft.com/emet
) and I use the Windows SmartScreen Filter.


The biggest security flaw here is user error. The safest way to click on any link is to right click it > copy the link location > paste it to see the actual address before entering it. Or better yet, don't click it. :D
*
Pescao6
of
El Imperio Latino

Hola Noob! Klk? What's up?
~
Discord: Pescao6#0001

10-Aug-2016 13:26:39 - Last edited on 10-Aug-2016 13:29:53 by Pescao6

Pescao6
Aug Member 2007

Pescao6

Posts: 9,075 Rune Posts by user Forum Profile RuneMetrics Profile
Jigzag said :
The hijacker then takes over their Skype, email, and by-passes the authenticator into their RuneScape account and starts asking people on their friends list for Skype information so they can try and send those people the same file/link, in addition to sending it to all the contacts on the Skype account after starting a friendly short conversation.

Lol malware infections don't work that way. Lets say that you get some kind of malware via some website you clicked or a file you accepted through skype....

Assuming its a zero-day virus your antivirus failed to block/delete, you can pretty much assume that all passwords you've saved on your web browser have been compromised which is why I personally use a Password Manager which stores them on a encrypted vault. Assuming you're using unique passwords and you're not saving them on your web browser, all of your accounts should not be compromised.

Now even if they obtained your RuneScape password which you should be changing every 3 months, they can't bypass the RuneScape Authenticator to get into your account. The only thing they can do is disable the authenticator through your email. So what you need to do is secure your email with 2-step verification .

And this is why Jagex doesn't return items due to account hijacking. There are so many things that would potentially need to go wrong on your part for you to get hijacked in 2016, that Jagex can't be responsible for you not securing your PC, Email and Account. :P
*
Pescao6
of
El Imperio Latino

Hola Noob! Klk? What's up?
~
Discord: Pescao6#0001

10-Aug-2016 13:26:52

Pescao6
Aug Member 2007

Pescao6

Posts: 9,075 Rune Posts by user Forum Profile RuneMetrics Profile
Jigzag said :
It has already happened to 4 people, that I am aware of, in the last 3 days including my clan and 2 other clans and I've been playing crowd control to stop it from happening to the rest of my clan and guests since I keep getting pm's about the suspicious file/link being sent to them via Skype.

Phishing has been on the rise since January 2016. I've had over 40 RuneScape Friends hacked because they had viruses on their PCs and failed to follow basic online safety guidelines.

Tell your friends to scan their PCs with these anti-malware tools:
1) Malwarebytes Anti-Malware
https://www.malwarebytes.org/mwb-download/thankyou/
2) AdwCleaner
https://toolslib.net/downloads/viewdownload/1-adwcleaner/
3) Junkware Removal Tool
https://downloads.malwarebytes.org/file/jrt/
4) Kaspersky Security Scan
http://www.kaspersky.com/kss

After that, they will need to reset their web browsers.
Ref: http://www.howtogeek.com/171924/how-to-reset-your-web-browser-to-its-default-settings/

Then they need to secure their emails:
- GMAIL: https://support.google.com/mail/checklist/2986618?hl=en
- MICROSOFT: http://windows.microsoft.com/en-US/windows/outlook/hacked-account
- YAHOO: https://help.yahoo.com/kb/account/secure-hacked-yahoo-account-sln3516.html
- AOL: https://help.aol.com/articles/account-management-identifying-suspicious-activity

If your registered email is known to a RuneScape hijacker, I would strongly recommend changing your account recovery email .

And follow the advice on Securing your computer and account .
*
Pescao6
of
El Imperio Latino

Hola Noob! Klk? What's up?
~
Discord: Pescao6#0001

10-Aug-2016 13:27:02 - Last edited on 10-Aug-2016 13:31:16 by Pescao6

Pescao6
Aug Member 2007

Pescao6

Posts: 9,075 Rune Posts by user Forum Profile RuneMetrics Profile
Jigzag said :
It seems like common sense, but how many of us actually give a second thought to something our friend/family sends us before clicking to see what it is.

The average person gets their PC malware infected within 3 hours of using it and 90% of people in the world are not following basic online safety guidelines. These are the sad but true statistics. All we can do is create online safety & security awareness.

Some resources you may want to share with friends and family are:
https://blog.kaspersky.com/cyber-savvy-quiz/
https://www.microsoft.com/en-us/safety/online-privacy/phishing-symptoms.aspx
http://www.microsoft.com/about/philanthropies/youthspark/youthsparkhub/programs/onlinesafety/resources/

Jigzag said :
Luckily Jagex has been great at recovering RuneScape accounts and Bank Pins have been protecting everything they are supposed to protect, minus any items on your character during forced take over rip, but we have yet to recover any of the Skype accounts that have been hijacked and they are still rouge sending the file/link to people faster than we have been able to notify everyone.

The best thing to do if you know of a RuneScape account that has been hijacked is tweet
@JagexSupport
We have multiple JMods monitoring it that can quickly check an account for suspicious activity and lock it down giving you time to secure your PC and go through the account recovery process.

As for recovering the hijacked skype accounts, you should contact Microsoft. Even if you're unable to recover the account through the conventional recovery system, you may be able to send them a ticket to regain access to the account.
https://support.skype.com/en/faq/FA10946/my-skype-account-has-been-suspended-or-hacked
*
Pescao6
of
El Imperio Latino

Hola Noob! Klk? What's up?
~
Discord: Pescao6#0001

10-Aug-2016 13:27:13

KitKat
Feb Member 2008

KitKat

Posts: 7,030 Rune Posts by user Forum Profile RuneMetrics Profile
Sadly we were one of the secondary clans that were involved.
One clan mates account was hacked. The hacked account then tried to get people in my clan to loan them things or asked them to add them on skype.
He/she also tried to send an exe file to some people in the clan he already had on skype. Luckily more people didn't fall for it.

Thanks for the advice Pescao. Hopefully it's okay if I copy some of it to my clan forums.

To top it off, in the past week or 2 the name impersonating scam was attempted several times in our cc.
Founder of Chill Mates
.........
¸ • * ˆ ˆ * • ¸
....
Scatter Kindness
....
¸ • * ˆ ˆ * • ¸

10-Aug-2016 17:17:48

L0NE DRUID
Jan Member 2011

L0NE DRUID

Posts: 8,683 Rune Posts by user Forum Profile RuneMetrics Profile
The name impersonation scam is becoming more and more common and I see plenty of players Tweet about it when i'm over helping on the Twitter side. My best advice on those impersonators is make sure your clan knows what's going on and keep them in the loop at all times.

If you think clan members could be subjected to this, ask them to place their friends list on friends only, now I know the fact that many players like to play with their friends list on because in clans you never know someone may contact you to ask about your clans recruitment as a example or for any other reason. But if you know this type of thing is happening then locking down the clan to "Ranks only" and asking members to put their PM to "friends only" for a while is a pretty reasonable way to make sure you don't get contacted by the wrong sort of people.

Another thing I will mention is that make sure your clan members know that they should never trust trade items they are not willing to loose, to anyone. I know you hear this a lot but keep reminding your members of that, it doesn't matter who the person is, don't trust trade items you are scared to loose because there is a possibility it might get taken, even by a close friend/high clan rank, you just don't know.

With this matter it really does come down to awareness and prevention is better then dealing with the aftermath of the situation, however there is always that in game report option for item scamming which can easily apply to situations like this, so even though there isn't really a rule against "Player Impersonation" as such, as players are allowed to have any name they want, this is a potentially a way of item scamming so can be reported it as such and Jagex will review the evidence and take action where required.

I hope this information helps :) .
A Jagex Verfied Community Helper
Leader of Zealmania
|
A Runescape player since 2005
|
@JagexHelpL0ne

Tech Issues? Click Me!

10-Aug-2016 19:33:04 - Last edited on 10-Aug-2016 19:35:03 by L0NE DRUID

Ledr Knuckls

Ledr Knuckls

Posts: 1,257 Mithril Posts by user Forum Profile RuneMetrics Profile
ty for the info and i have passed the info onto my clan and will keep doing so as everyone is on at different times throughout the week

but tysm for the info and have fun but stay safe and secure
Every Day Is A New Beginning , Take A Deep Breath , Smile , And Start Again


< ~=~=~> OffSite Website <~=~=~=~>

11-Aug-2016 05:20:28

Quick find code: 86-87-183-65821620 Back to Top