Fake "Gift 50$" steam link links to real steamcommunity.com
Hi all,

A friend got a message from another friend about "Gift 50$" with next to it, the *real* steamcommunity.com link, then a bunch of numbers. I know - we know - and I hope everyone knows it's a scam. But this one has me perplexed. What's the point of this one if it leads to the real steam, and since it's a "bad" url, redirects to the frontpage of Steam?

I've been trying to find anything, hoping to see a "smart" IDN homograph attack or something, but nothing. Trying to google it up got me no answer aswell.

Thanks for your time :)

edit: just for clarification, when I talk about the link, it's literally just "steamcommunity.com/" and then a bunch of numbers. no "/gift/" or "/profile/" or anything like that. Why bother hacking into a Discord account just to post a real steamcommunity link?
Ultima modifica da root@Nero:~#; 26 mag 2024, ore 15:19
< >
Visualizzazione di 1-15 commenti su 92
it doesn't lead to the real steam, they use a link with the word "community" mispelled
Messaggio originale di potato:
it doesn't lead to the real steam, they use a link with the word "community" mispelled

Okay, here's the thing, it does

The "steamcommunity.com" I posted, I copy-pasted it from his message. I'm confident, 100% sure this is the right url.
Messaggio originale di ragefifty50:
report

then block

This isn't the point of me posting this message. Please read my original post.

I want to figure stuff out, it's what I do, it's what I like to do. I want to figure out why would someone get into someone's discord account to post a real steam url, because I'm sure of it it's real, it's not misspelled, nothing.
It's a phishing link.

Old scam.

https://steamcommunity.com/discussions/forum/1/2592234299571197182/

Going waaaaaaay back...

https://steamcommunity.com/discussions/forum/7/558754899933789316/

https://steamcommunity.com/discussions/forum/1/523898291503812045/

At one point, the Global Volunteer mods helped adding all the variations of the Steam link to the filter (many of us regulars helped send the links to them) but some time in the past couple years, Vavle removed them from the filter for some dumb reason.

It's been making the rounds really hard again the past few months.

:winterbunny2023:
Okay, figured it out. It's a highlight in Discord. It *shows* a real steamcommunity.com url, but when you do a right click (and not highlight then copy/paste like my friend did sending it to me), it's a weird ass URL.
Messaggio originale di cSg|mc-Hotsauce:
It's a phishing link.

Old scam.

https://steamcommunity.com/discussions/forum/1/2592234299571197182/

Going waaaaaaay back...

https://steamcommunity.com/discussions/forum/7/558754899933789316/

https://steamcommunity.com/discussions/forum/1/523898291503812045/

At one point, the Global Volunteer mods helped adding all the variations of the Steam link to the filter (many of us regulars helped send the links to them) but some time in the past couple years, Vavle removed them from the filter for some dumb reason.

It's been making the rounds really hard again the past few months.

:winterbunny2023:

No. This wasn't the correct thing. I saw your copy-pasted message a while ago, and no. It wasn't that. I was just unaware you could have embeds in Discord.
Messaggio originale di lycanroc in a dog costume:
Okay, figured it out. It's a highlight in Discord. It *shows* a real.
Never log into any given link or button.
Messaggio originale di lycanroc in a dog costume:
Messaggio originale di cSg|mc-Hotsauce:
It's a phishing link.

Old scam.

https://steamcommunity.com/discussions/forum/1/2592234299571197182/

Going waaaaaaay back...

https://steamcommunity.com/discussions/forum/7/558754899933789316/

https://steamcommunity.com/discussions/forum/1/523898291503812045/

At one point, the Global Volunteer mods helped adding all the variations of the Steam link to the filter (many of us regulars helped send the links to them) but some time in the past couple years, Vavle removed them from the filter for some dumb reason.

It's been making the rounds really hard again the past few months.

:winterbunny2023:

No. This wasn't the correct thing. I saw your copy-pasted message a while ago, and no. It wasn't that. I was just unaware you could have embeds in Discord.
Here you have a breakdown of 6 common Discord scams.
https://youtu.be/Jz-3goOPj9o?si=yMJo70J8fTAQ2hjt
Fake Steam links are one of them.
Messaggio originale di cSg|mc-Hotsauce:
At one point, the Global Volunteer mods helped adding all the variations of the Steam link to the filter (many of us regulars helped send the links to them) but some time in the past couple years, Vavle removed them from the filter for some dumb reason.
They moved all the variations to its specific section out of the filters, they're still being blocked. But as in everything else is an arms race.

Messaggio originale di lycanroc in a dog costume:
Okay, figured it out. It's a highlight in Discord. It *shows* a real steamcommunity.com url, but when you do a right click (and not highlight then copy/paste like my friend did sending it to me), it's a weird ass URL.
Putting a different URL as the link text is one of the oldest trick in the book
Steam changed how they show URLs to combat that IE:
https://www.wikipedia.org/

[url=https://www.wikipedia.org/]https://steamcommunity.com/discussions/[/url]
Not sure how it works on Discord
Ultima modifica da Tito Shivan; 27 mag 2024, ore 3:56
Messaggio originale di Tito Shivan:
Messaggio originale di cSg|mc-Hotsauce:
At one point, the Global Volunteer mods helped adding all the variations of the Steam link to the filter (many of us regulars helped send the links to them) but some time in the past couple years, Vavle removed them from the filter for some dumb reason.
They moved all the variations to its specific section out of the filters, they're still being blocked. But as in everything else is an arms race.

Messaggio originale di lycanroc in a dog costume:
Okay, figured it out. It's a highlight in Discord. It *shows* a real steamcommunity.com url, but when you do a right click (and not highlight then copy/paste like my friend did sending it to me), it's a weird ass URL.
Putting a different URL as the link text is one of the oldest trick in the book
Steam changed how they show URLs to combat that IE:
https://www.wikipedia.org/

[url=https://www.wikipedia.org/]https://steamcommunity.com/discussions/[/url]
Not sure how it works on Discord
Discord uses Markdown, so the formatting would be

[https://steamcommunity.com/discussions/](https://www.wikipedia.org/)

Except that intentionally doesn't work in messages from humans, and I'm pretty sure bot messages aren't officially allowed in account-to-account chats, only in servers.

So Discord would probably be interested in what that scammer account is doing, since it's a violation of their TOS even if it wasn't also a scam.
Ultima modifica da Ben Lubar; 27 mag 2024, ore 5:26
Here some facts.
- You can't do gifting via url. People can gift via Steam, but you only get notification via site & client, email, and pop up when you login to steam client. If anyone giving you a link for a gift it's automatic red flag scam.

PLEASE NOTE Discord has a problem where it allow uses to change the path of their hyperlink
using a command so they can say whatever they want, but the link goes somewhere else.


- Steam support will never do support outside of Steam, they don't do DMs, voice call, email, phone call, or sms, they only reply to tickets you make via Steam help page only on site no where else.

Anyone claim to be Steam admin/support automatically red flag scam. Scammers use claims having pending bans, or whatever.

- Scammers use tricks like vote for my team or you won a prize and try to trick you to login to their scam site, they even use FAKE tab pop up within your browser to trick you thinking it real thing but it just a fake phishing page to get you to login.


These are not new scams, or recent at all been around for years, the issue is people either ignore these signs, PSA, never take notice, be ignorant thinking it can't happen to them, or just want to play stupid games win stupid prizes learning hard way.
url spoofing , redirecting to website forgery for hijacking accounts - tell all your friends to join some popular Steam Groups / Game Hubs and Enter some chat rooms for more great examples of the online criminal activity taking place on this platform.

education I guess is the best medicine, since Valve won't remove malicious urls or find a way to at least slow down the number of accounts posting scam urls.

url scan io or phish report - as soon people can get fakes reported to security sites and host, to get the hosts to shut down the sites the criminals already have new spoofed urls to switch to and spread. Then it takes days, weeks months to get them reported and shut down again. sounds just like VAC and cheats huh?
Ultima modifica da CANCELCULTURE; 27 mag 2024, ore 8:07
Messaggio originale di CANCELCULTURE:
url spoofing , redirecting to website forgery for hijacking accounts - tell all your friends to join some popular Steam Groups / Game Hubs and Enter some chat rooms for more great examples of the online criminal activity taking place on this platform.

education I guess is the best medicine, since Valve won't remove malicious urls or find a way to at least slow down the number of accounts posting scam urls.

url scan io or phish report - as soon people can get fakes reported to security sites and host, to get the hosts to shut down the sites the criminals already have new spoofed urls to switch to and spread. Then it takes days, weeks months to get them reported and shut down again. sounds just like VAC and cheats huh?
Can't remove things if don't know them, and scammer easily change their url all the time, all can do report them, they add to block list if click on link via steam to tell you it scam site, but doesn't work at all if you're visitng the link from other places like discord, twitter, youtube, and so on.
@Dr.Shadows did you ever notice that there is no pop up window warning users when urls are clicked from within Steam's own official game hub chats or Steam User Group chat rooms? Maybe not. They don't even seem to keep up with updating the block list of suspicious url red warnings in chat rooms. I'm not about to believe that those urls, accounts and groups are not being reported.
< >
Visualizzazione di 1-15 commenti su 92
Per pagina: 1530 50

Data di pubblicazione: 26 mag 2024, ore 15:17
Messaggi: 92