Explorer

'Ice Breaker': Israel-Based Security Experts Uncover Cyberattack Targeting Gaming Industry Ahead Of ICE London

The whereabouts of the attackers are currently unknown.

ICE London, the leading gaming and gambling convention, is set to be held on February 7-9. Ahead of that, an Israel-based security platform has uncovered a cyberattack, which is using a human-operated customer service attack vector to target the event. As per Security Joes, a managed detection and response (MDR) and incident response (IR) service provider, claims that the operation, dubbed "Ice Breaker" has been active for at least four months prior.

In its report, Security Joes claims that the bad actors have been using social engineering tactics to lure customer service agents, who often turn out to be third-party business process outsourcing (BPO) firms. After striking up a conversation, attackers share a link to a fake online screenshot storage, which in reality is a complex complied JavaScript file, which is able to discover running processes, steal passwords and cookies, open a proxy tunnel controlled by attackers, exfiltrate files and data, as well as run scripts imported from attackers' server. 

"This operation is highly sophisticated and well-planned," Security Joes COO Alon Blatt said. "The attackers have been able to map potential victim networks and strike at the most opportune time, but we were able to detect and prevent the deployment of their second-stage malware before it could cause any harm. We urge gaming and gambling companies to arm their security perimeters with 24x7 experts complemented by advanced security systems."

The whereabouts of the attackers are currently unknown. As per Security Joes, they have been observed to use "broken English during their social engineering tactics, specifically targeting non-English customer service agents."

"This is a highly effective attack vector for the gaming and gambling industry," said Security Joes Senior Threat Researcher Felipe Duarte. "The never-seen-before compiled JavaScript 2nd stage malware is highly complex to dissect, showing that we are dealing with a skilled threat actor with the potential of being sponsored by an interest owner."

View More
Advertisement
Advertisement
25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Advertisement

Top Headlines

BCCI Secretary Jay Shah Announces Whopping Prize Money After India's T20 World Cup 2024 Win
BCCI Secretary Jay Shah Announces Whopping Prize Money After India's T20 World Cup 2024 Win
3 New Criminal Laws To Take Effect Today Replacing Colonial-Era IPC, CrPC, Evidence Act. Know Key Reforms
3 New Criminal Laws To Take Effect Today Replacing Colonial-Era IPC, CrPC, Evidence Act. Know Key Reforms
Ravindra Jadeja Announces Retirement From T20Is Following T20 World Cup 2024 Triumph
Ravindra Jadeja Announces Retirement From T20Is Following T20 World Cup 2024 Triumph
With NEET-UG Row, Agnipath & Inflation In Focus, Parliament Set For Heated Debates In Second Week Of Session
With NEET-UG Row, Agnipath & Inflation In Focus, Parliament Set For Heated Debates On July 1
Advertisement
ABP Premium

Videos

Women empowerment in J&K’s Nowshera under the UMEED scheme | ABP NewsWatch: Cars swept away in raging Ganga as Haridwar faces weather's wrathDevotees depart for holy Amarnath Shrine amid tight security from Pantha Chowk base campWhole of India is filled with enthusiasm: President of Punjab Cricket Association on India’s T20 WC victory

Photo Gallery

Embed widget