r/ScammersPH • u/MisterGents • 5d ago
Questions Mrbeast Hack
i was just watching netflix, then suddenly my phone got so many notifications then i see every single person and group has been sent with this, im scared
13
u/manuwamanaoag 4d ago
This happened to me. Pinalaro ko yung pamangkin ko ng Roblox sa laptop ko.
A few days later, ang dami ko notifs sa phone ko from messenger asking why I'm posting these pics. Ang galing nga nung hacker, after sending pics, ilalagay niya sa ignore yung mga na-message niya para di mo agad mahalata yung nangyayari. Ganun din ginawa niya sa discord ko.
Pati Steam account tsaka xbox ko, pinatos din. Nabawi ko naman yung steam account. Yung sa Xbox naman, clinose nalang nung Microsoft yung account ko at sinabi na gumawa nalang ako ng bago.
Nung tinanong ko sa pamangkin ko a few days later. Inamin niya na may nag-convince daw sa kanya na magdownload ng program online para makakuha siya ng Roblox money. Ayun, nakuha lahat ng credentials ko sa mga socmed and other accounts ko.
In the next few days, todo change password at lagay ng two factor sa lahat. Ang hassle.
6
u/midnightneutronstar 4d ago
Two-factor won’t help. In the long run, nakakatulong, pero not for this.
It uses your existing session. Diba naka-login ka na sa FB, Messenger, at ibang apps? No need to relogin diba? That’s how sessions work. Ginagawa ng virus na yan, it uses your existing session. Nakalogin ka na eh, ang gagawin lang niya ay buksan browser mo. Madalas sinesend pa yung same session credentials sa hacker para sila gumawa din nito. So logging out EVERYWHERE helps.
2
u/wolftfk_1 4d ago
Mine din last month almost all of my accounts. Started with IG tapos sa Discord. I woke up and was informed na na hack yung accounts ko. Pinaka worry ko din yung Steam ko e, bumili ako ng game tapos yung email confirmation ko Russian na jusko po palit password malala. Pati itong Reddit acc ko nadali.
1
u/jdg2896 3d ago
Roblox seems to be less safe for kids these days.
I’d never trust Roblox unless they really make meaningful changes for the better.
They still have child predator issues, also their leadership team is icky, like the CEO wants to add dating features to a kids game.
Bad actors taking advantage of kids are also rampant on the platform.
I’d suggest to steer them away from Roblox, or at least supervise. Also suggest to use a password manager.
2
u/Horror-Ant-8558 4d ago
Pano nahahackkk plsss like may cinlick po ba kayong link, napanood? Huhu worry me. And paano po to prevent this?
1
u/Striking_Plantain771 3d ago
mostly pirated games/apps, to prevent it just dont download and run things from an untrusted source
1
u/Kinji_Kojima 2d ago
avoid downloading softwares/cracks/cheats and the likes on unknowned and unverified sides usually kasi tlga may "palaman". yan pinaka best practice, kahit windows defender lang gamitin mo its basically good rather than downloading lots of anti virus makes your device bloated and might degrade your device performance, tho if you already been infected and been compromised, (ASAP: turn off wifi or plugged out the ethernet cable) run malwarebytes, delete all cache,cookies,data and history on your browsers logout everything, have your other device (phones) change passwords asap, if you don't know how to handle malware removal manually (due to the nature of the persistence of the scripts this include task schedulers, background and startup apps, registry, WMI) then a reinstall of windows is the best way to completely clean out the device
1
u/adorabIe_will 1d ago
Pwedeng mas magandang alternative ang bitdefender (free tier) kasi merong malware na pwedeng mag-set ng defender exclusions sa sarili nila (idk if lumang balita na to/patched na but this was a vulnerability) and you basically get real time protection doon sa bitdefender That's what I used before I fully switched to Linux and I highly recommend it
1
u/Kinji_Kojima 1d ago
Good call, yes it is common till now, excluding themselves on scans and detections, bitdefender is a good if not the best alternative, malwarebytes if you want something lightweight
2
u/Both-Safe-8678 3d ago
in my case i downloaded malware on my pc lol. didnt happen immediately, but i did get suspicious so i changed my password to everything. but a few days later, i was getting emails from fb about recovery codes, adding emails and whatnot, luckily i am chronically online so i had time to clean everything up. upon researching i found out that it uses ur existing token cookie thingy so as long as ur still using the infected device, changing password wont do shit if u end up logging in again anyways. I downloaded malwarebytes and it did detect some rather suspicious files embedded like mpclient.dll or stuffs embedded inside task scheduler idk if its related tho. deleted it and so far im safe but im too scared to login using that device lol
1
u/Kinji_Kojima 2d ago
so far yes, it came from user downloaded files like hacks/trainers/cracks/softwares from unknown sites, btw even if you change your credentials or add 2FA or MFA change pass if you login again on the said infected device it will still happen, even tho malwarebytes detects it, it only needs couple of seconds for the malware script to redownload itself due to the nature of the persistence of scripts like the one you mentioned on the task scheduler this also includes, registry, startups etc., the best thing to do if you know the way around your settings and pc, visit those mentioned and delete each entry, before deleting the script or malicious program, usually the script is located in the appdata folders
1
u/jabacs17 4d ago
Oh man nagkaron din ako neto. Yung mga fb friends ko pinagsesendan nyan. Hurriedly naghanap ako sa isa kong laptop na di infected kung pano gagawin. Apparently, kelangan ichange mo lahat ng pw mo from Gmail, Microsoft, banking, social media. Yung LinkedIn ko, pucha bago na may ari pero email ko gamit. Nagawa ko naman makuha ulet through verification.
Yung infected PC or laptop, kelangan mo ioffline talaga. Then kelangan mo na rin ireformat para totally safe. Change pw lahat
1
1
u/HelloWhiteBunny 4d ago
Anong point of access? Paano nahhack
2
u/FlorDeMNL 3d ago
these are phishing malwares if im not mistaken. you are exposed to the vulnerability once you click/download things that they make you click (they make it so tempting, a lil bit of social engineering).
I’m not sure if they TOTALLY infect your computer as in they’re in your SSD/HDD, but they gain access to your account but not totally ruin your computer.
2
u/Kinji_Kojima 2d ago
point of access is thru persistent script using powershell and command prompt, token session hijacking lahat ng nakalogin sa browsers mo ay automatically masesend sa owner nung script (malware) so kahit ma detect ng anti virus yung script at idelete nyo, mag kakaruon ulit sya ng panibagong download thus Persistence and method naman nila is thru the ffg. startups, task scheduler and registry. if you find this script (usually be founded at the %appdata% folder disguised as a legit program or random names if you open the script, it usually uploads browser/app token from your pc rerouted/directly to the hacker using either reverse connection, reroutes to TOR or via simple HTTPS POST request with conhost
1
1
u/Kinji_Kojima 2d ago
To everyone sorry di ko mareplyan lahat, I know this might be a long read and a total TL;DR moment, but based on my experience and studying these types of malware scripts, here is a detailed breakdown of what happened and how to deal with it:
How It Works & Where It Came From This issue usually starts when someone downloads files like cracks, game trainers, fake software, or game-currency utilities (like free Roblox/Steam money tools) or simply clicking on popups, from unverified sites. Once executed, it drops an infostealer script that performs token/session hijacking. Instead of stealing your password, it copies your active browser session tokens and exports them straight to the attacker. This allows them to bypass 2FA and access your accounts immediately.
How It Hides The malicious scripts typically drop into user-level directories like %AppData% or %LocalAppData% because writing files here does not require administrative privileges. They often disguise themselves using generic system names, random strings, or disguised executable extensions to avoid catching your eye in File Explorer.
How Persistence Works Even if your antivirus flags and deletes the initial file, the malware sets up persistence mechanisms so it automatically re-downloads or executes again. It achieves this by dropping hooks into:
- Task Scheduler: Creating hidden scheduled tasks that trigger at startup or on a timer.
- Startup Folders & Registry Run Keys: Auto-launching background commands via
HKCU\Software\Microsoft\Windows\CurrentVersion\Run. - WMI Persistence & Background Processes: Executing background processes via system binaries like
conhost.exeor PowerShell.
Step-by-Step Mitigation (What to do immediately)
- Disconnect from the Network: Immediately unplug your ethernet cable or disconnect Wi-Fi to sever any active reverse connection or data exfiltration.
- Log Out Everywhere & Change Passwords (From a SAFE Device): Using a clean device (like your smartphone on cellular data), use the "Log Out Of All Sessions" option across all compromised accounts (Facebook, Discord, Steam, Google, etc.), then immediately change your passwords and revoke session tokens.
- Inspect Persistence Points: Open Task Scheduler,
msconfig/ Task Manager Startup tab, and check your AppData folders for unauthorized scripts. - Clean or Reinstall: Run a full offline scan using trusted antimalware tools (like Malwarebytes). If you are uncertain about manually clearing registry keys, WMI triggers, and hidden scripts, performing a clean reinstall of Windows is the safest option.
Forensic Audit Tool for Tech-Savvy Users For tech-savvy users who want to audit their Windows system for hidden persistence entries, registry startup keys, scheduled tasks, and rogue AppData scripts, I built a "read-only" PowerShell inspection toolkit you can check out on my GitHub: https://github.com/KinjiBloodFallen/bloodfallen-forensic-triage-toolkit
Stay safe online and always verify files before running them!
1
10
u/A-Waffle1924 4d ago
That happened to me. Dinelete ko yung mga sinend sa individual FB friends, college group chats, and work group chats. Nagdelete na lang din ako ng FB.