It's Thanksgiving Day so with some much needed downtime, I decided to login to my fire mage and play a little WoW (World of Warcraft). No sooner had I done so that I was greeted with the following message:
"Blizzor: Hello, Christmas is approaching. Blizzard released Christmas gifts players can receive free of charge. Please login: wwww.Blizz-Christmas.com."
Now, Blizzard does actually give free Christmas gifts to players - but it's done in-game, with all major cities sporting a huge tree and lots of presents to open. But the Blizzor message is a scam, www.Blizz-Christmas.com is a phishing site that masquerades as a Battle.net lookalike. The intent is to steal your game login credentials. The site uses all Blizzard links in its source code - except for the actual login button. This could trick some naive gamers into believing it's legit. But it's not. Logging in via Blizz-Christmas.com won't net you free gifts - but it will give the attackers your account for free.
The domain currently resolves to 210.72.225.118, an IP hosted in China.
Phishing scams can be difficult to stop. But it seems to me that Blizzard should simply ban any toon names with "Blizzard", "Blizz" or any similar derivative to reduce the likelihood of anyone falling for the scam.

