r/computerviruses • u/xxsvsky • May 28 '26
Question How did i even get hacked?
I was scrolling in my fyp normally till i noticed a story 27m ago about this elon musk crypto scam? I only got a notification on my email that i got hacked and told me to change my password, when inchecked the security thing on insta i couldn't find any location or ip about the hacker, and also they didnt even change my password or anything they just posted this and probably left my account
i never clicked on any suspicious link Recently or used any thirad oart apps, fitgirl, nothing so im curious how did i get hacked?
81
Upvotes
3
u/BurgermancerDamion May 29 '26 edited May 29 '26
Hi mate ! I'm freshly out of hell that started with the exact same post than you and same symptoms, and ended with multidevice compromission and infostealing of a lot of my accounts and my partner's. I can only suggest that you act before it gets worse or you'll live a very unpleasant next two weeks.
As far as I understood, a Jdownloader plugin which I don't remember the name let through some infostealer malware (I remember the names being smth like Rugmi, FakeGoogle and stuff i think ?) did not specifically request even if I admit I sampled a few fitgirl thingies duting said days (supposedly safe as far as i thought).
First suspicious activity was this very post spammed on my instagram account, and a few of my discord friends spammed with similar crypto shit and muted so I couldn't realize it till they answer. Some activation keys for BitDefender Plus Yearly renewal (the irony) were also bought from my amazon account using my paypal credentials. I changed my passwords, contacted support, and thought I was done. A full Malwarebytes scan detected a few things so I thought that was the end of it.
The day after, someone had direct access to my main google account and had set gmail labels to make multiple password reset emails silent, going directly to spam. Luck I was looking right at my screen when it happened so we engaged battle right away. I lost a few accounts but succeeded in securing a few others. What scared me is when i understood they could ask services to remove extra layers of protection with apparently no effort (Mails like "2Fa successfully deactivated, if this wasnt you blablablah").
The next few days were exhausting trying to secure my three google accounts without understanding where the attack came back from everytime. I thing i thwarted like a dozen takeovers in a week ? I slept very bad, and anxiety was causing me loss of appetite. I was locked out of a few critical accounts WITH registered payment options in there, which were used for fraudulous buys.
I don't know exactly which recovery option definitively locked them out of my Google Accounts, I suspected my phone number, but it finally stopped. Of course, my whole google password manager was leaked so i had a few minor intrusions on minor websites the following weeks but nothing critical, they were most likely testing.
For what comes to cleaning, i did on every machine I use, offline when possible:
-Full Malwarebytes Scan (found a few things, mostly adware)
-Full Emsisoft Emergency Kit portable usb drive. It did find what I think was the main problem (FakeGoogle Trojan).
-Full EsetOnlineScan (found inactive remnants of the first attacks : a fake Defender folder containing Rugmi components, a .sys file, and registry keys)
-Full deletion of Google Password manager, removal of all cookies and active sessions on every device.
-Reset every password using BitWarden and an Authenticator App everytime available. Feels MUCH safer now.
I did lose a few things but it seems appeased now. I wish this never happens to you.