Since yesterday new wave of phishing attack spreads through Steam chat.

Works similar to previous attacks:

  • friend sends you message with link and information about free game
  • link leads to fake Steam log in page
  • logging in compromises your account, so that you're unable to log into it again
  • now-zombie account sends the same message you get to all your Steam friends, fishing for more unwary users

Do not click on any links, that are sent with this message:

1 free game for new users!
take the game you want!
....://spindatgamex(dot)com / rolldatgamexx(dot)com / spindatgamexx(dot)com / takedatgamex(dot)com / christmasskin(dot)fun / dagamesrollx(dot)com / takedagame(dot)com

Or this:

Hi, can you spin this roulette <LINKREMOVED-JUSTINCASE> ? If GTA V, PUBG or CSGO falls out, I can buy the key from you. Try it, it will take no more than 30 seconds. You go -> press the ROLL button, a free game falls out -> you take the key and write to me) Well, or you activate the game on your account)

Or this:

Hey, m8!Get a free random game (GTA V, PUBG, CSGO and more) on ...://t(dot)co/xNAKzWQ5ew Only for new users, full legit and no deposit
//
🎁 Go to 👉 ...://t(dot)co/qucKFViqZv 👈 аnd tаkе yоur 50$ Skin Gift !
PRОМ0C0DE: LUCК4Y0U 🎁

1. Can SteamGifts support staff can help me to recover my Steam account?

First of all we're unable to help you, as we're not connected with Steam Support.

All we can do is suspend your SteamGifts account on your request, so it won't be possible to do any harm here - see keys from ended giveaways, change e-mail, spam discussions, make fake giveaways etc.
You can request to be suspended under 1st post of this PSA. We will suspend you for number of days listed in your request, or give permanent suspension, if you prefer. You can write unsuspend request when you recover ownership of your account, to use SG again before suspension runs out.

If you don't want to suspend your account and have active / not claimed giveaways:
It is not possible to see keys from active giveaways. But when giveaway ends keys are available on /created page. That's why you should click on Modify link next to the key, copy it to secure place (such as txt file) and exchange it with gibberish, or already used key. That way no one, except for you, will be able to see them.

2. What to do when I was phished?

  1. Write to Steam Support, explaining situation
  2. Attach proof of purchase(s) that are connected to your account:
    • keys activated on account from bundles
    • keys activated on account from retail shops
    • receipt of buying game on Steam with credit card
    • steam wallet codes
    • photograph of boxed game code activated on Steam
    • more information here
  3. Wait for reply, it should take 2 - 3 days to recover account, if you manage to provide all necessary information

3. How to avoid being phished in the future?

When link redirects you to "Log in with Steam" page (same is true for log in with Facebook, Twitter etc) never write your credentials there.

  1. Open log in site on your own, by writing known address or using google. In case of preventing Steam phishing:
    • steamcommunity.com
    • store.steampowered.com
  2. Log in using your credentials
  3. Go back to site which required you to log in and refresh
    • if you're logged in your Steam account, and see green button "Log in" you're free to access website.
    • if refreshing did not remove request to provide your credentials - it's phishing attempt.

4. Anything I can do to help my phished friend?

To avoid further spam of phishing messages you can block communication with friend. And unlock it, when friends regain access to account. That way you don't need to remove user from friends to stop seeing messages, and don't cut ties with them.

As pointed here it is possible to report compromised Steam accounts.

You can also report sites, which are used in phishing attempt here:
https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en
https://app.webinspector.com/
https://submit.symantec.com/antifraud/phish.cgi
https://phishing.eset.com/report

Thanks for notice, Nask


1. Do not create new threads about this issue

We don't need to spread information and updates about this attack in multiple threads. It makes it hard to follow current state of situation.

That's why I will close all other threads about this matter. You can inform other users that you were attacked in this thread. No reason to create separate thread for every case.

Also please, don't create new threads in case of future attacks. Stick to posting all relevant information in thread created already by other user.

2. Do not accuse others of being "scammers", as they sent you link to phishing site.

They are victims of this situation, not attackers.
Do not write user reports on them

3. Do not create spam / mocking threads about this issue.


You can post any relevant information here, such as changes in phishing message, change of phishing site address, tips how to recover account, and discuss it in general. I will update this post in my free time. I do not like to cut ongoing discussions in other topics, but it is necessary to keep all information in one place.

Previous PSA posts about this attack:
https://www.steamgifts.com/discussion/HWhcX/psa-accounts-being-hackedphished-in-steam
https://www.steamgifts.com/discussion/TioOP/danger-careful-with-1-free-game-for-new-userstake-the-game-you-want-https-spindatgamexc-no
https://www.steamgifts.com/discussion/GCxxD/a-wave-of-steam-scams-beware-to-not-lose-your-account
https://www.steamgifts.com/discussion/xc8jE/i-fell-into-the-hack
https://www.steamgifts.com/discussion/cnNgf/definitely-not-clickbait-easy-steps-to-avoid-the-next-phishing-attempt-on-your-pc#oRnNU7W

5 years ago*

Comment has been collapsed.

and here's a new one , just got this from a friend , the message wud be like this :
"Hi, can you spin this roulette <LINKREMOVED-JUSTINCASE> ? If GTA V, PUBG or CSGO falls out, I can buy the key from you. Try it, it will take no more than 30 seconds. You go -> press the ROLL button, a free game falls out -> you take the key and write to me) Well, or you activate the game on your account) "
and seems it has been around for a while too :
https://steamcommunity.com/discussions/forum/1/2789318172125126720/
so it's definitely a malware, and don't even think of click on the link on the message!

5 years ago*
Permalink

Comment has been collapsed.

Thanks, added to OP

5 years ago
Permalink

Comment has been collapsed.

you're welcome.

5 years ago
Permalink

Comment has been collapsed.

GTA V, PUBG or CSGO

Further proof that you can't ever trust anyone who doesn't know how to properly utilize the oxford comma.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

There is easy protection from this: don't open links from unknown people. And if message was sent by Your friend... yeah, basically You know what Your friend WOULDN'T write, right? If I got messages like this, even from my friends, I would know it's fake.

Also triple check the address. Always.

5 years ago
Permalink

Comment has been collapsed.

Ive heard it's also coming from gamebundlex, but I have not tried (and will NOT try) it.

5 years ago
Permalink

Comment has been collapsed.

I have not tried (and will NOT try) it.

I remember someone saying something similar to Sam-I-Am, and yet, in the end, they still ate those green eggs and ham.
Just saying.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

Well I'm back in action

5 years ago
Permalink

Comment has been collapsed.

and I'm lucky I got out of that with only 1 blacklist

5 years ago
Permalink

Comment has been collapsed.

Congrats on being back! And sorry about the blacklist... hugs

5 years ago
Permalink

Comment has been collapsed.

I sent a friendly note to HB about one of these scam sites using their HB logo and claiming that they are being sponsored by HB. According to the response I got, HB is putting their (legal?) team on it -- hopefully they can help stop the scam at the source. Would be great to prevent others from falling into the trap! Stay safe, everyone!

5 years ago
Permalink

Comment has been collapsed.

Boop for more awareness.

5 years ago
Permalink

Comment has been collapsed.

5 years ago
Permalink

Comment has been collapsed.

That blog post if from 1.11.2017

And the tweet doesn't exist (anymore?)

5 years ago
Permalink

Comment has been collapsed.

This is fanatical twitter screenshot.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

Sounds like facebook.

5 years ago
Permalink

Comment has been collapsed.

I have seen images of users replying to the phishing bot in chat. Why even when the other party is not able to/will not comment? Dont put yourself at risk of any kind even by replying. You might accidentally click on the link when exiting the chat and then accidentally fall into a trap which could be why it had been so widespread. Cheers, Cruse~

5 years ago
Permalink

Comment has been collapsed.

Clicking the link won't get you "hacked".

5 years ago
Permalink

Comment has been collapsed.

I know but it leads you to the trap. Is what I am advising against. :)

5 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

5 years ago
Permalink

Comment has been collapsed.

Bump

5 years ago
Permalink

Comment has been collapsed.

Still going on... I just got sent the link to one of those roulette sites from a friend with a 100+ level account. Hopefully he can get it back quickly.

Fortunately I'm always suspicious when something seems too good to be true and did a quick search to see if the site was legit. Turned up this discussion near the top of the page.

5 years ago
Permalink

Comment has been collapsed.

And the hits keep coming...

A friend of mine on Steam just got hacked as his account is sending me links to these now. His account has been sending me links ever half hour since since 6:39 PM EST.

5 years ago
Permalink

Comment has been collapsed.

Another wave has started.

christmasskin . fun

5 years ago
Permalink

Comment has been collapsed.

Thanks, added to OP.

5 years ago
Permalink

Comment has been collapsed.

New wave:

"Hey, m8!Get a free random game (GTA V, PUBG, CSGO and more) on https :// t.co /xNAKzWQ5ewOnly for new users, full legit and no deposit"

Link leads to https : // keysroll . site/

5 years ago*
Permalink

Comment has been collapsed.

please remove the link.

5 years ago
Permalink

Comment has been collapsed.

Better?

5 years ago
Permalink

Comment has been collapsed.

Yep.

And thanks for heads up! Added to OP.

5 years ago
Permalink

Comment has been collapsed.

I think they started on steam forums promising free CSGO skins. From there they don't just hijack your account and trade your skins away, they use those stolen accounts to keep posting in that thread to make it look more legit.

To a new user, it will look really tempting to try and get new skins.

https://steamcommunity.com/app/730/discussions/0/3247565033768757041/

5 years ago
Permalink

Comment has been collapsed.

I opened one discussion, and it's full of copy-pasted comments with scam links. Has 3k replies and is not closed by Steam moderators. Wow.

5 years ago
Permalink

Comment has been collapsed.

That's the one.

They aren't doing anything about it. The longer that thread stays alive, more accounts will get phished.

5 years ago
Permalink

Comment has been collapsed.

Wow! That thread is getting longer and longer! I click on "last page", scroll down, and then there are one (or more) new pages already! Insane that Valve is doing NOTHING about it!!

5 years ago
Permalink

Comment has been collapsed.

Greed and stupidity go hand in hand and they're never out of fashion. People never learn that trust should be hard earned in the online, not given away freely.

5 years ago
Permalink

Comment has been collapsed.

Who's talking about trust? EVERYONE likes freebies!

5 years ago
Permalink

Comment has been collapsed.

my friend account hacked this new site dagamesrollx(dot)com and takedagame(dot)com its same site rolldatgame(dot)com https://gyazo.com/2624f9635725dce8cae207e950142cd3

5 years ago
Permalink

Comment has been collapsed.

Thanks for info, added to OP.

But looks like they simply change address constantly. Wonder why Valve won't block all links with "game" in them, or simply add info that there is scam going...

5 years ago
Permalink

Comment has been collapsed.

is this still going?

View attached image.
5 years ago
Permalink

Comment has been collapsed.

yes if you search the site in scamadviser.com its domain age 2 days

5 years ago
Permalink

Comment has been collapsed.

Yea another person from my friends list got hacked the other day. Didn't realize this was still ongoing until then.

5 years ago
Permalink

Comment has been collapsed.

It has never stopped from going on, they just change the address, whatever useless crap they promise you will get and where it gets spammed. It wont stop until people stop falling for them, just like some people still believe in spam emails about foreign riches no matter how much the media tries to warn about it.

5 years ago
Permalink

Comment has been collapsed.

Wait...you mean to say that the British barrister e-mailing me doesn't have $1,000,000 in the bank from that relative I never heard of...

Inconceivable!

5 years ago
Permalink

Comment has been collapsed.

No he's legit, I checked with my good friend the Nigerian Trade Emperor.

Closest I've come to a believable one was when I was quite high and they offered me a free box of new flavor of potato chips every month for product testing if I just enter my card info. Shame it was all in Swedish and I don't make deals with djävuls.

5 years ago
Permalink

Comment has been collapsed.

Check out the CSGO forums. Shit just hit the fan. So many accounts got jacked.

5 years ago
Permalink

Comment has been collapsed.

Not a phishing but a attempt to scam user to download and run Steam password stealer. Problem, they have chosen wrong person.

View attached image.
5 years ago
Permalink

Comment has been collapsed.

This has been going on since 2012. In fact, in CSGO lounge in the old days, everytime you bump your thread some scums will add you and tell you to click a screenshot or his friend wants to trade with you.

5 years ago
Permalink

Comment has been collapsed.

Hey, m8!Get a free random game (GTA V, PUBG, CSGO and more) on https://t.co/<link-shortner used> for new users, full legit and no deposit

OOOOf... I guess this still going on...
I'm sure it's not going to be an avalanche-like a few months back, but still - Beware

5 years ago
Permalink

Comment has been collapsed.

Yep. Got that message from 1 friend (so far?). Suspicious that their account has closed comments on the page. Probably to prevent people from warning others that the account has been compromised.

5 years ago
Permalink

Comment has been collapsed.

I got that one, followed by this one from the same user:

Brother, tell me what game you won?
If GTA V, PUBG or CSGO falls out, I can buy the key from you
https://t.co/<redacted>

5 years ago
Permalink

Comment has been collapsed.

I guess we are talking about the same user (¬、¬)

5 years ago
Permalink

Comment has been collapsed.

Probably.

5 years ago
Permalink

Comment has been collapsed.

TL;DR : As usual, don't be dumb.

5 years ago
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.