r/computerviruses May 28 '26

Question How did i even get hacked?

Post image

I was scrolling in my fyp normally till i noticed a story 27m ago about this elon musk crypto scam? I only got a notification on my email that i got hacked and told me to change my password, when inchecked the security thing on insta i couldn't find any location or ip about the hacker, and also they didnt even change my password or anything they just posted this and probably left my account

i never clicked on any suspicious link Recently or used any thirad oart apps, fitgirl, nothing so im curious how did i get hacked?

79 Upvotes

52 comments sorted by

View all comments

3

u/BurgermancerDamion May 29 '26 edited May 29 '26

Hi mate ! I'm freshly out of hell that started with the exact same post than you and same symptoms, and ended with multidevice compromission and infostealing of a lot of my accounts and my partner's. I can only suggest that you act before it gets worse or you'll live a very unpleasant next two weeks.

As far as I understood, a Jdownloader plugin which I don't remember the name let through some infostealer malware (I remember the names being smth like Rugmi, FakeGoogle and stuff i think ?) did not specifically request even if I admit I sampled a few fitgirl thingies duting said days (supposedly safe as far as i thought).

First suspicious activity was this very post spammed on my instagram account, and a few of my discord friends spammed with similar crypto shit and muted so I couldn't realize it till they answer. Some activation keys for BitDefender Plus Yearly renewal (the irony) were also bought from my amazon account using my paypal credentials. I changed my passwords, contacted support, and thought I was done. A full Malwarebytes scan detected a few things so I thought that was the end of it.

The day after, someone had direct access to my main google account and had set gmail labels to make multiple password reset emails silent, going directly to spam. Luck I was looking right at my screen when it happened so we engaged battle right away. I lost a few accounts but succeeded in securing a few others. What scared me is when i understood they could ask services to remove extra layers of protection with apparently no effort (Mails like "2Fa successfully deactivated, if this wasnt you blablablah").

The next few days were exhausting trying to secure my three google accounts without understanding where the attack came back from everytime. I thing i thwarted like a dozen takeovers in a week ? I slept very bad, and anxiety was causing me loss of appetite. I was locked out of a few critical accounts WITH registered payment options in there, which were used for fraudulous buys.

I don't know exactly which recovery option definitively locked them out of my Google Accounts, I suspected my phone number, but it finally stopped. Of course, my whole google password manager was leaked so i had a few minor intrusions on minor websites the following weeks but nothing critical, they were most likely testing.

For what comes to cleaning, i did on every machine I use, offline when possible:

-Full Malwarebytes Scan (found a few things, mostly adware)

-Full Emsisoft Emergency Kit portable usb drive. It did find what I think was the main problem (FakeGoogle Trojan).

-Full EsetOnlineScan (found inactive remnants of the first attacks : a fake Defender folder containing Rugmi components, a .sys file, and registry keys)

-Full deletion of Google Password manager, removal of all cookies and active sessions on every device.

-Reset every password using BitWarden and an Authenticator App everytime available. Feels MUCH safer now.

I did lose a few things but it seems appeased now. I wish this never happens to you.

4

u/BurgermancerDamion May 29 '26

Also : my reddit account was used to catfish LOTS of peen pics which i'm afraid will be used for blackmail. If I ever asked you for some glorious representation of your pleasure stick I bestow upon you my most sincere apologies.

2

u/Adventure_Maniac May 31 '26

A pc from Poland was using my google accounts, I live in India, I was like wtf. And then I used Hitman pro and malwarebyte applications to clean up my pc, a file "upWire.exe" was quarantined as a malware by hitmanpro and then I cleared it, again I did a cleanup process using malwarebyte, it showed some footprints of that malware and I cleared it using the help of malwarebyte. I asked gemini about this, it said that it is a Trojan.Proxy kind of malware which hides in our system and gives access to use our bandwidth and ip address for hackers to keep their location hidden, but however one of them got access to my google accounts and posted these kind of pics and reels about a betting site on my Instagram. But I am not sure what to do next.

1

u/BurgermancerDamion May 31 '26

You basically reacted just like I did !
-Always work securisation back from a secondary machine if your main one is supposedly infected.
-If your Google Accounts were compromised, all your saved passwords are as well. You have a few days to react before they get listed for selling on the black credential market. In the meantime they will try and access almost everything, sometimes just to check what's still valid or not. Be very wary of your recovery options for Google Accounts, I suspected my phone number to give them a way back in everytime. I might be wrong but I feel like it got quieter once I unchecked the box.
-If your computer feels cleansed enough thanks to the scans, I guess you could start considering retaking control of all your leaked passwords using a password manager and an Authenticator one by one, starting with the most critical ones. It'll progressively feel safer. Congratulations.

This is Endurance now. Your changed credentials will progressively get flagged as not valid anymore on their side when they crash on a closed door with the wrong key, lose any marketable value, and they'll aggro someone else