DIY Steam information harvesting tool sends out mass malicious invites

Webroot’s Dancho Danchev has unearthed a DIY Steam information harvester / mass group inviter tool being offer for sale on a number of cybercrime-friendly underground forums, proving once again that there really is an automated tool for every malicious cyber enterprise you want to engage in (click on the screenshot to enlarge it):

To use this tool successfully, all you need to enter is a working Steam Group URL, and it will proceed to fill in everything from associated user names, Steam IDs, service registration date, to installed games, average play time, last login time, and more.

With this information in hand, the cyber crook is ready to approach the users with personalized spoofed mass invites to new games, patches, mods and other inviting offers, and serve them malicious links.

The tool can be currently bought for a little less than $20, but it can also be rented. “For 80 rubles ($2.61), the author will send 1,000 Steam Group invites on your behalf, and for 130 rubles ($4.24), he’ll only send those invites to Steam users who are online, in an attempt to increase the probability of a successful participant, by leveraging the momentum of the real-time invitation,” shares Danchev.

Don't miss