Poker players are being spied on by money-making malware

Poker chips

Two of the world's largest poker sites have been affected by a new piece of malware that allows cheats to prosper.

First reported by the Eset Security Blog, the Win32/Spt.Odlanor allows attackers to view cards in the victim's hand and then join the game on PokerStars or Full Tilt Poker in order to fleece the victim of their chips.

Victims are infected with the trojan when downloading software from elsewhere and it has been known to masquerade as Daemon Tools or mTorrent. It has also reached systems through various poker-specific programs such as player databases and poker calculators.

When the malware has been successfully executed it takes a screenshot of either the PokerStars or Full Tilt Poker client and this are relayed back to the attacker. From here on in screenshots can be obtained that reveal the hand and player ID thus making it very simple to find the exact table the person is playing at because each client allows you to search for tables by player ID.

Serial targets

Most of the victims are in Eastern Europe, particularly Russia and the Ukraine, and as of September 16 several hundred users have fallen victim to the malware.

Poker players are often targeted by cyber criminals and you can go as far back as 2008 to find warnings from one researcher about the threat posed, and PokerStars security product manager Trent Wyatt admitted in last year that poker players are definitely open to cyber crimes.

Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser