New Phishing Scam Email - Claims to Offer GW2 Beta Access

Regina Buenaobra

Regina Buenaobra

ArenaNet

Join Date: Apr 2008

Me/

Hey everyone,

There's a new phishing email going around which claims to offer you Guild Wars 2 beta access if you download an attached executable file.

NOTE: ALL OFFICIAL INFORMATION ABOUT THE GUILD WARS 2 BETA IS AVAILABLE ON THE WEBSITE. CURRENTLY, INFORMATION ABOUT THE BETA IS STILL "TBA".

Here is the text of the phishing email, so you know what to look for (I bolded and underlined areas for you to pay close attention to):

Quote:
SUBJECT: Guild Wars 2 beta Selection
FROM: community @aren.net <-- PLEASE NOTE THE SPELLING ERROR
BODY OF EMAIL:
Congratulations!
Because of your time and experience on Guild Wars, you are invited to participate in the Guild Wars 2 closed beta, starting on March 1, 2010. Please note that Arenanet will never ask for any personal information including game keys, email addresses and account passwords. Attached is an installer executable for the Guild Wars 2 beta client.
Here is a list of known issues with installation with the current beta build.
• Virus Scanners, adware/spyware detectors and software firewalls all will flag this program and prevent it from installing. Please disable any one of these on your computer before installing.
• Once installed, you may re-enable these programs, but you must create an exception for scanning the Guild Wars 2 installation folder to prevent the game from being deleted.
• If, during your first execution of the game, your computer prompts you to restart, please follow the instructions and do so.
For other issues, please consult the release notes in the installation folder when installed.
Thank you for your participation. Have fun defeating the dragons on the continent of Kryta!
Arenanet Customer relations
community @arena.net
Again, I want to stress that this email is a scam. It does not originate from ArenaNet or any ArenaNet staffer. Most likely, after you download the .exe file attached to that email, it will do nasty things to your computer.

Please spread the word. We don't want anyone compromised.

Thanks for your attention, all.

gone

Guest

Join Date: Jan 2007

TY for the heads up.

ROFL @ A Keylogger/RAT/Backdoor/ With instructions...

Chocobo1

Chocobo1

Desert Nomad

Join Date: Sep 2007

New Zealand

CoA

N/

How did these people get our emails, I never ever used to get phishing emails, it only started late last year....

The-Bigz

Frost Gate Guardian

Join Date: Jan 2010

Cause you think I troll doesn't make my point less valid

We Roll Pros [POD]

A/W

Quote:
Originally Posted by Chocobo1 View Post
How did these people get our emails, I never ever used to get phishing emails, it only started late last year....

Like around that time when everyone and everything got hacked and it turned into pure madness? Hint Hint.

On Topic: If someone is stupid enough/into Guild Wars enough to /disable all defenses and restart their computer for a game to be installed, they deserve the epic fail hack. Some people aren't that good with computers as well though, so I'm happy this was posted so fast.

JimmyNeutron

Krytan Explorer

Join Date: Sep 2007

Quote:
Originally Posted by Chocobo1 View Post
How did these people get our emails, I never ever used to get phishing emails, it only started late last year....
Browser's info...websites know what site you left, your IP address, your screen resolution, etc...all from the crap left behind by your browser and cookies.

Safest way to browse is through a sandbox like Sandboxie and using Private Browsing going through multiple proxy and don't tell the browser to remember who you are.

Ex. Guru...if Guru remembers you, all websites will remember you.

X Ghoul

Frost Gate Guardian

Join Date: Dec 2009

IGN: X Ghoul

Mega M O R P H I N Power Ranger [pR]

Rt/W

I read this and got excited "ALL OFFICIAL INFORMATION ABOUT THE GUILD WARS 2 BETA IS AVAILABLE ON THE WEBSITE." then I read this right after "CURRENTLY, INFORMATION ABOUT THE BETA IS STILL "TBA"." ......FML...

Heloniar

Academy Page

Join Date: Aug 2008

A New Day Dawns [HOPE]

W/P

wow, it's so blantant.. There's so many things wrong with this.

Chthon

Grotto Attendant

Join Date: Apr 2007

Quote:
Originally Posted by Chocobo1 View Post
How did these people get our emails, I never ever used to get phishing emails, it only started late last year....
I'm not sure if that's sarcasm or not.

Assuming it's not, the answer is the holes in the NCSoft site.

ac1inferno

ac1inferno

Desert Nomad

Join Date: Aug 2007

Boston

We D Shot Your Stances [GODS]

A/W

Quote:
Here is a list of known issues with installation with the current beta build.
• Virus Scanners, adware/spyware detectors and software firewalls all will flag this program and prevent it from installing. Please disable any one of these on your computer before installing.
• Once installed, you may re-enable these programs, but you must create an exception for scanning the Guild Wars 2 installation folder to prevent the game from being deleted.
• If, during your first execution of the game, your computer prompts you to restart, please follow the instructions and do so.
That made me laugh so hard.

Zodiac Meteor

Zodiac Meteor

Imma Firin Mah Rojway!

Join Date: Aug 2008

At the Mac Store laughing at people that walk out with anything.

E/Mo

Quote:
Originally Posted by ac1inferno View Post
That made me laugh so hard.
Seriously, how stupid do you have to be?

"You need to have your virus and spyware detector disabled."
"You can enable it after download."
"Just exempt Guild Wars 2."

It's like saying,

"You need to put your hands down for me to punch your face."
"You can put your hands up at all times though."
"Just not when I'm punching your face."

Fail scam is failure.

Stop The Storm

Stop The Storm

Keeping DoA Alive

Join Date: Jan 2007

England

Were In [DoA]

A/N

yet i bet some people will have fallen for this, under 16 year olds jumping up and down screaming "guildwars 2 guildwars 2!!!!"

4thVariety

Krytan Explorer

Join Date: Jun 2005

European Union

ADL

E/

tracing Aren.net is fun. The domain is registered by some shady MDNH, Inc. which works 44.000 domains from a suite in a Las Vegas Hotel.

Aren.net itself traces back to an address in Irvine CA (omgkotickconspiracybby)

Explains why this mail is at least in decent English.

Zahr Dalsk

Grotto Attendant

Join Date: Aug 2007

Canada

Guess this will catch a lot of 30-40 year olds, young teenagers, Mac users, Dell users, and basically idiots in general.

jazilla

jazilla

Desert Nomad

Join Date: Aug 2006

Guernsey Milking Coalition[MiLk]

E/Me

Quote:
Originally Posted by Zahr Dalsk View Post
Guess this will catch a lot of 30-40 year olds, young teenagers, Mac users, Dell users, and basically idiots in general.
Most 30-40 year olds I know(including myself) are pretty savvy to the ways of the computerz. i do however appreciate your 20 year old generalizations about my age group though. GG to you Zahr.

shadowhand

Ascalonian Squire

Join Date: Jun 2006

I'm slightly disappointed. I never get any of these phishing mails. All I get is offers for questionable medicine and uh, body alteration offers...

gone

Guest

Join Date: Jan 2007

Quote:
Originally Posted by 4thVariety View Post
tracing Aren.net is fun. The domain is registered by some shady MDNH, Inc. which works 44.000 domains from a suite in a Las Vegas Hotel.

Aren.net itself traces back to an address in Irvine CA (omgkotickconspiracybby)

Explains why this mail is at least in decent English.
You sir, win 1 free lego leggo my eggo waffle.

II Lucky Charm II

II Lucky Charm II

Frost Gate Guardian

Join Date: Jun 2006

Seoul, Korea

Mo/Me

All these things can be prevented if players reformat every 2 weeks and change their passwords every 1 day. A heads up is always fine, I suppose.

gone

Guest

Join Date: Jan 2007

Quote:
Originally Posted by II Lucky Charm II View Post
All these things can be prevented if players reformat every 2 weeks and change their passwords every 1 day. A heads up is always fine, I suppose.
If I were you i'd reformat every other day. Now That I know I have a 2 week window to crack your security and have 24 hours to log your keystrokes.

Arkantos

Arkantos

The Greatest

Join Date: Feb 2006

W/

Pretty sad that people need to be warned about obvious scams like this, but thanks for the heads up, Regina.

pinkeyflower

Krytan Explorer

Join Date: Jan 2010

Which people could just be patient and wait for news through official channels, but that's fighting with human nature. At least non-power users got a heads up so that's always good.

El Perma Shadow

El Perma Shadow

Frost Gate Guardian

Join Date: Jul 2009

Conspired Illuminated Experts (CLX)

A/

fail hackers for not even knowing how to spoof the email address

Anakita Snakecharm

Anakita Snakecharm

Frost Gate Guardian

Join Date: Nov 2009

The Shining Blade Camp

Nouvel Ordre de Phoenix [MJM]

R/Mo

Yeah, this sort of e-mail should definitely send up red flags. I know, wishful thinking, but wow.

In my experience, what's described in the e-mail is nothing like a legitimate closed beta recruiting procedure anyway:

I've never heard of a legitimate beta test where the game development company approached a (not personally known, non-QA-professional, random stranger) potential tester directly and out of the blue via private e-mail, rather than posting a general announcement and inviting people to apply. Why waste effort contacting people who may not even be interested, with no way of being sure whether they've reached their quota, when they know they have a pool of people already eager?

I also think it would be unusual that you wouldn't be asked your system specs (and sometimes your previous testing experience) before being chosen, since part of the point is to see how the game runs on a variety of systems... which won't be efficiently accomplished via random mailings. This wouldn't matter later on for server stress tests when they just want to see how many people will fit, but that would be much closer to launch, not this early on.

Plus, particularly this early in the process, in a legitimate test, testers would almost certainly be required to sign a non-disclosure agreement before getting near a download, so the company has legal remedy if their trade secrets are blabbed all over the internet.

Plus being asked to disable your antivirus? Wow.

I really hope no one gets scammed by this, but it should be pretty obvious that such an offer is too good to be true. When/if GW2 is actually available for beta testing, there's no way it'll be this fly-by-night.

Thanks for the heads up!