Hackers target Pokémon fans with malware via fake Pokémon TCG software in latest NFT-related scam

Malware disguised as Pokémon TCG software - Source: ASEC
In the latest case of Pokémon fans being targeted by NFT related scams, security analysts at the AhnLab Security Emergency response Center (ASEC) have detailed a sophisticated campaign targeting Pokémon fans with malware via websites claiming to distribute new Pokémon Trading Card Game software that integrated the purchase and collections of Pokémon Card NFTs. ASEC analysts identified at least 2 websites distributing this malware since at least December 2022.

Any Pokémon fans duped into downloading the software would instead find themselves installing a disguised NetSupport Remote Administration Tool on their computer. While this software does have legitimate use cases in support environments, it is one of a selection of such commonly used tools that have been co-opted by scammers to gain remote access to people's computers to facilitate a variety of scams, including identify theft, as well as adding infected computers to botnets. Typically distributed by scammers through links and attachments in phishing emails, the software allows attackers complete control over a system, including basic functions such as access to files and web browsing history, clipboard contents, and capturing the user's screen, as well as the ability to execute arbitrary commands and code.

By presenting their software as a Beta, the hackers in this instance may have been trying to take advantage of the ongoing Beta for the Pokémon TCG Live, which is expected to replace the Pokémon Trading Card Game Online software some time during 2023, to present their game as legitimate to fans who may have been confused about changes happening with the new software.

Pokémon has sadly had to deal with several scams related to supposed NFT games in the recent past. In December, The Pokémon Company International sued one fraudster in the Federal Court of Australia for misrepresentation and misuse of Pokémon Trademarks in the advertising and creation of a Pokémon NFT game, which the fraudsters had claimed would be released this year on January 23rd.
Archaic Written by Archaic