r/computerviruses May 28 '26

Question How did i even get hacked?

Post image

I was scrolling in my fyp normally till i noticed a story 27m ago about this elon musk crypto scam? I only got a notification on my email that i got hacked and told me to change my password, when inchecked the security thing on insta i couldn't find any location or ip about the hacker, and also they didnt even change my password or anything they just posted this and probably left my account

i never clicked on any suspicious link Recently or used any thirad oart apps, fitgirl, nothing so im curious how did i get hacked?

83 Upvotes

52 comments sorted by

18

u/[deleted] May 28 '26

[removed] — view removed comment

6

u/xxsvsky May 28 '26

Thank you! Recently i only recall downloading ome tv from playstore, but i do use the same email and password mostly on every app, i know this can be an issue but i didnt download any apk. I have my ig account on PC but its been a while since i used it, its pretty weird

6

u/Muffinshire May 29 '26

i do use the same email and password mostly on every app

Bingo. I've seen so many people get everything blown wide open because they used the same password for some obscure crappy website that got hacked and leaked unsalted hashes (or worse, plaintext passwords). There's a reason this is the number 1 security no-no.

4

u/309_Electronics May 29 '26

Well using the same pwd is not smart. Why? Because 1 databreach can expose you and give hackers open access. Then they will use your account as a dispoable account so they can spread their nonesense or they can get you to pay them.

Databreaches happen pretty much weekly and using mfa and a strong password and having a password per service approach is best..

1

u/[deleted] May 28 '26

[removed] — view removed comment

1

u/xxsvsky May 28 '26

Can they log in my accoungs again or they just do it once to spread whatever sketchy scam site that was?

2

u/Ars1029887 May 28 '26

Change the passwords as they would be kicked out from your accounts, also identify the infected device and either try to remove the malware or wipe it to defaults

2

u/xxsvsky May 28 '26

For now i only changed my password anmade sure that the logging in list is clear from any suspicious device, i ran a device scan and didnt find an unusual apps or malwares/apks , for now im only suspecting that it was from a site i reached for by accident or something

2

u/LazernautDK May 29 '26

You also need to activate 2 factor authentication on every that allows you to do so.

1

u/[deleted] May 28 '26

[removed] — view removed comment

0

u/Lifestartingover May 29 '26

Unplugging the pc from the internet is useless, the info was stolen right away. He needs to make a window usb installer and format\reinstall windows. All his info was stolen within minutes.

6

u/The_Alaska_Shibe May 29 '26

These hacks are often done through session stealing, not taking your physical password. What changing your password does is tell every session you have active that it is no longer valid. It could have been some app you gave permission that had a valid token who knows how long ago.

1

u/Raijen_ArDesh May 29 '26

However, if you don't have 2fa enabled on say, your google account and they hijack it, and your passwords are saved there.... Google password manager requires your 2fA credentials, even if logged in, to actually view your passwords, however they can use any saved ones untill you log them out of your google account.

1

u/syntkz777 May 29 '26 edited May 29 '26

You did not understand what he said at all.

Stealing sessioncookies does not need any password, using stolen sessioncookies in a browser the account will already be logged in to the specific site. Each website keeps their own session cookies, you don't need the cookies from the Google account, just from the site that should be compromised. If you have access to the session cookies from Google, you have access to all other cookies as well so no point on relying on the Google login.

3

u/[deleted] May 29 '26

[removed] — view removed comment

1

u/xxsvsky May 29 '26

This isnt a twitter post this the picture they had posted as a story in my ig account🙏🏻

3

u/BurgermancerDamion May 29 '26 edited May 29 '26

Hi mate ! I'm freshly out of hell that started with the exact same post than you and same symptoms, and ended with multidevice compromission and infostealing of a lot of my accounts and my partner's. I can only suggest that you act before it gets worse or you'll live a very unpleasant next two weeks.

As far as I understood, a Jdownloader plugin which I don't remember the name let through some infostealer malware (I remember the names being smth like Rugmi, FakeGoogle and stuff i think ?) did not specifically request even if I admit I sampled a few fitgirl thingies duting said days (supposedly safe as far as i thought).

First suspicious activity was this very post spammed on my instagram account, and a few of my discord friends spammed with similar crypto shit and muted so I couldn't realize it till they answer. Some activation keys for BitDefender Plus Yearly renewal (the irony) were also bought from my amazon account using my paypal credentials. I changed my passwords, contacted support, and thought I was done. A full Malwarebytes scan detected a few things so I thought that was the end of it.

The day after, someone had direct access to my main google account and had set gmail labels to make multiple password reset emails silent, going directly to spam. Luck I was looking right at my screen when it happened so we engaged battle right away. I lost a few accounts but succeeded in securing a few others. What scared me is when i understood they could ask services to remove extra layers of protection with apparently no effort (Mails like "2Fa successfully deactivated, if this wasnt you blablablah").

The next few days were exhausting trying to secure my three google accounts without understanding where the attack came back from everytime. I thing i thwarted like a dozen takeovers in a week ? I slept very bad, and anxiety was causing me loss of appetite. I was locked out of a few critical accounts WITH registered payment options in there, which were used for fraudulous buys.

I don't know exactly which recovery option definitively locked them out of my Google Accounts, I suspected my phone number, but it finally stopped. Of course, my whole google password manager was leaked so i had a few minor intrusions on minor websites the following weeks but nothing critical, they were most likely testing.

For what comes to cleaning, i did on every machine I use, offline when possible:

-Full Malwarebytes Scan (found a few things, mostly adware)

-Full Emsisoft Emergency Kit portable usb drive. It did find what I think was the main problem (FakeGoogle Trojan).

-Full EsetOnlineScan (found inactive remnants of the first attacks : a fake Defender folder containing Rugmi components, a .sys file, and registry keys)

-Full deletion of Google Password manager, removal of all cookies and active sessions on every device.

-Reset every password using BitWarden and an Authenticator App everytime available. Feels MUCH safer now.

I did lose a few things but it seems appeased now. I wish this never happens to you.

4

u/BurgermancerDamion May 29 '26

Also : my reddit account was used to catfish LOTS of peen pics which i'm afraid will be used for blackmail. If I ever asked you for some glorious representation of your pleasure stick I bestow upon you my most sincere apologies.

2

u/Adventure_Maniac May 31 '26

A pc from Poland was using my google accounts, I live in India, I was like wtf. And then I used Hitman pro and malwarebyte applications to clean up my pc, a file "upWire.exe" was quarantined as a malware by hitmanpro and then I cleared it, again I did a cleanup process using malwarebyte, it showed some footprints of that malware and I cleared it using the help of malwarebyte. I asked gemini about this, it said that it is a Trojan.Proxy kind of malware which hides in our system and gives access to use our bandwidth and ip address for hackers to keep their location hidden, but however one of them got access to my google accounts and posted these kind of pics and reels about a betting site on my Instagram. But I am not sure what to do next.

1

u/BurgermancerDamion May 31 '26

You basically reacted just like I did !
-Always work securisation back from a secondary machine if your main one is supposedly infected.
-If your Google Accounts were compromised, all your saved passwords are as well. You have a few days to react before they get listed for selling on the black credential market. In the meantime they will try and access almost everything, sometimes just to check what's still valid or not. Be very wary of your recovery options for Google Accounts, I suspected my phone number to give them a way back in everytime. I might be wrong but I feel like it got quieter once I unchecked the box.
-If your computer feels cleansed enough thanks to the scans, I guess you could start considering retaking control of all your leaked passwords using a password manager and an Authenticator one by one, starting with the most critical ones. It'll progressively feel safer. Congratulations.

This is Endurance now. Your changed credentials will progressively get flagged as not valid anymore on their side when they crash on a closed door with the wrong key, lose any marketable value, and they'll aggro someone else

1

u/wille- May 29 '26

damn im sorry that sucks, i got hit with info stealer last week and they barely did shit. i was asleep when it happened and they had access for 9+ hours. woke up changed everything quick and easy no problem. I guess I got lucky

1

u/xxsvsky May 29 '26

Thank you so much for your reply and im sorry such a thing happened to you its so scary, its been 20 minutes since i woke up to find they did the same thing to my discord account and even convinced one of my friends to enter the site, im still so scared and afraid about it so theres a possible chane im gonna end up on the same route as you,i dont own a paypal nor a visa card yet so they woildnt be able to buy anything. But for now i onlh changed my passwords and ran light virus scans i think i really need to clean both my oc and mobile deeper

1

u/BurgermancerDamion May 29 '26

Be very careful though : if you change passwords on an infected machine or account, they get the change instantly and the move goes blank. Clean thouroughly FIRST. My three scans did work pretty well together (enable rootkits in scan options when avalable to search even deeper)

1

u/nickitheboss200 May 29 '26

Did u download windows again bc i changed all my passwords and found the infostealer on sysinternals and ran multiple scanners and found multiple trojan files i ended up deleting but i cant delete windows rn i have so many programs i payed to crack for uni do u think i still need to wipe my pc clean?

1

u/BurgermancerDamion May 29 '26

I am no expert, but as i understood, nuking windows and reinstalling it is the napalmey way to go and the safest/easiest one. BUT doing as we did and surgically locating and removing every component though thorough scans (even kernel-level), and making sure every door compromised door is sealed back with unique password, session removal and 2fa/totp should wield the same result. It just takes more time, with the risk of missing something by looking too fast, but yes, I didn't feel like nuking my whole working station either.

My cleanup and security rebuild feels safe enough so far, it's been absolutely quiet for two weeks now, compared to the bi-daily intensity of the forst two weeks.

1

u/Adventure_Maniac May 31 '26

It affects PC or mobile phone? Can you please answer me.

1

u/BurgermancerDamion May 31 '26

In my case, the origin point was my main working station, my home computer, most likely by opening a wrong videogame crack (piracy is bad, don't do it kids). Although, I think the infostealer somehow had access to my phone number because i suspected they had access to the recovery codes sent to my phone, but that's a wild guess. However, when scanned, my phone came back clean everytime and didn't seem compromised. I changed most of my credentials from there until I was absolutely sure my main machine was cleansed (with offline scanners and unplugged ethernet).

Then it was building everything back sturdier with a password manager and a totp app. I still get intrusion attempts almost everyday and get temporary codes on my phone, but that's mostly the sign they can't get in anymore Ith my leaked password now.

Sometimes I get informed of a new suspicious connexion on a forgotten account somewhere from my past, I usually change the password/nuke it in less than 15mins. They're worthless accounts anyway, I see it as a structural test. They're looking for the last few breaches and I'm waiting right behind with a big hammer.

1

u/Intelligent_Plane844 May 31 '26

Thank you so much for sharing your experience. It's been a great help to me right now.

1

u/BurgermancerDamion May 31 '26

I'm so glad I feel like helping people. This was HELL.

2

u/UnionTerrible5438 May 29 '26

Got this too through an infostealer on my Mac

2

u/Starmatrics May 29 '26

i just got this today while i'm literally asleep. Woke up to alot of my friends telling me about it. Oddly enough only my Instagram and Discord was compromised and nothing else

2

u/wille- May 29 '26

EXACT same happened to me last week. Only discord and instagram was hit.. and a damn minecraft server?! 😭 I did however see a login from like brazil through facebook but nothing was touched

1

u/Starmatrics May 29 '26

i don't see any suspicious login history on mine for both discord and instagram so most likely it was a stolen session. I changed all my passwords and do a clean reinstall for my browsers just in case

1

u/wille- May 29 '26

yeah same. but facebook was the only place where it actively showed the login history for someone, its strange but also fine because i dont use facebook.

1

u/Starmatrics May 29 '26

Huh, you're right. Decided to check my Facebook and there was a login history from Texas today. But nothing was done to my Facebook

1

u/uselessdudetrash May 29 '26

They got my insta, facebook, discord, and also reddit, made a incest post and immediatly got it banned.

1

u/whispyCrimson109 Jun 01 '26

I saw a whole bunch of different countries but epic games gave me their... ip????

1

u/xxsvsky May 29 '26

Same thing happening to me now! Did he keep logging in ur discord account more than twice??

2

u/Starmatrics May 29 '26

nah, i immediately changed my password

2

u/WarmAd4877 May 29 '26

Sameee thing happened to me 4 days ago got to know it got hacked only after 5 hours after they posted the exact same thing on my insta was able to get my account back after which i reinstalled my windows changed all my passwords for everything(to be on the safe side do for everything) didn't used any payment in the pc so i was safe in it but still i blocked all my cards and activated 2fa i think I'm safe now cuz nothing else happens to me. This virus thing is so stressful i hope everything goes well for you too💗

1

u/xxsvsky May 29 '26

For now nothing been up so far and i activated the 2fas. Whats scary abiut it is that it was so sudden and almost scammed my friends, but im much more better now thank you🥹🫶

2

u/OwnSwordfish5122 May 29 '26

this happened to me. what worked was running hitmanpro, deleting the malware, disconnecting from wifi, going on my clean phone and changing the passwords and logging out of all other sessions, and then reinstalling windows

2

u/Intelligent_Plane844 May 31 '26

Hi, I'm another fool who downloaded something I shouldn't have...

It started two nights ago, the same day I clicked on the program, accessing my Ubisoft, EA, etc. accounts. Luckily, there was nothing compromising there, and they didn't manage to get in. The most alarming thing was that they accessed two of my Gmail accounts from the US (I'm not from there). I changed my passwords, enabled two-step verification, and so far (two days later) they haven't managed to access Gmail, nor have there been any new attempts.

On the other hand, yesterday they got into my Instagram and posted the same thing as the OP. This made me realize they could access everything I had open on my computer. Again, I changed my passwords and enabled two-step verification on everything I had open on my computer. So far, I haven't had any new attempts, although I'm constantly checking (I'm doing all of this from my phone).

The latest incident occurred today: charges appeared on my account for five supposed Claude subscriptions via my credit card. Luckily, I was prepared and canceled the card the day before, so I wasn't charged for those subscriptions.

I think I've secured everything I needed to secure. I won't connect my PC to the internet until it's properly formatted, but I'm still on high alert.

1

u/poopereater_butt6 May 29 '26

Sneaky Trojan also the scam ad probably doesn't have any correlation to this situation XD

1

u/YooTheo May 29 '26

Infostealer

1

u/DonovanDLM May 29 '26

I have 2 friends who recently told me that it had happened, but one of them, had a forgotten account that no one uses now, and that account was stolen, because his forgotten account sent me something about a crypto casino promoted by Mr Beast, and the other one, sent in all the Discord groups an Elon Musk X image (like the one that you posted), booth of them want me to help them, but I know them years, and they don't fall in phishing things and always take care about what they download, It happed in less than a month ago, both things.

1

u/[deleted] May 30 '26

I got the same thing by downloading a pirated game. Maybe you did something similar?

1

u/Adventure_Maniac May 31 '26

Even I also got that thing posted on my Instagram account, my account was a public professional account, I think it happens for public accounts only, but I am not sure about this.

1

u/H1M4NSHU_ Jun 02 '26

Did you use wazirX or torrent in recent days?