Win32/Spy.Odlanor : malware-deceiver allows online poker players to see your cards! Now you know the reason for your bad luck… or not?
Speaking of malicious software, and seeing it spread everywhere, in all sectors, we could not of course exclude the gambling sector. Let alone online gambling…
Online poker malware allows online players to steal by viewing the cards of other players whose computers are infected.
The Trojan, named Win32/Spy.Odlanor, is usually downloaded by victims because it disguises itself as an installer, or a resource, such as poker databases and poker calculators, according to a post on the ESET WeLiveSecurity blog.
“In other cases, it was downloaded to the victim’s system via various poker-related programs… such as Tournament Shark, Poker Calculator Pro, Smart Buddy, Poker Office, and others,” the blog states.
Once installed, it takes screenshots of the PokerStars and Full Tilt Poker clients, allowing attackers to see the cards that victims are holding in their hands. To complete the scam, the 'scammers' would have to find out which table their victim is sitting at and sit down at the same table where the infected machine is playing.
To do this, the attackers check a screenshot to verify the victim’s user ID on the poker site, which ultimately allows the malicious cheater to find the right table, according to the blog post. “We are not sure whether the perpetrator is playing the games manually or has set up some automated method,” it states. Besides, the cheater would have to have a better hand to beat his victim anyway.
The Trojan's creators have updated it over time, adding generalized data-stealing capabilities with a version of NirSoft WebBrowserPassView, a legitimate application capable of extracting passwords from browsers.
Most victims are located in Eastern Europe, ESET reports.

