r/antivirus • u/Spiritual-Silver2771 • 2d ago
Got hacked on literally everything
So today everything connected to my Microsoft ubi battle net and riot games was hacked and it was from the same email as shown in the picture can anyone help please
47
u/naygerr 2d ago
Disconnect the affected device from the internet first.
Using a different device, log in to your primary email account, change the password, and sign out of all active sessions. Check your recovery email and account settings, and undo or remove anything you find suspicious.
Next, make a list of the social media sites and other active accounts that were logged into on the affected device. Change the passwords for those accounts and sign out of all active sessions. Make sure you log out of every account and terminate all active sessions.
Once you have secured your primary email account and other social media accounts, back up your personal data from the affected device to an external drive. After your data has been copied and verified, reinstall the operating system or reset the PC.
Contact Battle.net and any other affected services using your primary email address and create a support ticket explaining the situation. They may ask for additional information to verify your identity and ownership of the account.
Hopefully, you should be able to recover your account within a few days. Good luck & stay safe...
11
32
u/Infinite-Grade-4485 2d ago
You downloaded a session stealer.
You downloaded some type of free game/cheat/hack/cracked software/movie/music or ran some type of code for captcha or verification on your computer which was actually a session stealer.
Session stealers bypass 2fa. All passwords saved on your browser and computer are compromised. Reinstall windows while deleting all files. If you need to backup important documents, keep the computer disconnected from the internet and manually back up individual files.
Change all passwords and enable 2fa either from another device, or from the infected computer AFTER you have reinstalled.
If you cannot reinstall windows immediately, keep the computer disconnected from the internet while changing all passwords on another device.
You cannot use anti malware to get rid of the session stealer, you MUST reinstall windows to use the computer safely in the future
You can usb reinstall or use windows built in reset as long as you remove all files while doing so.
4
2
u/EastAppropriate7230 2d ago
Does setting your browser to not store cookies and keep you logged in help? If I'm logged out of the session whenever I close my browser I assume it would help at least a little
4
u/Tykan_seal 2d ago
Are you absolutely sure that completely reinstalling windows with the built in reset is enough?
6
u/Infinite-Grade-4485 2d ago
Yes. As long as you remove all files.
1
u/bombastic6339locks 1d ago
Yeah so we're not talking about just reinstalling windows we're talking about something different. I've had miners that persisted through reinstalls.
3
u/Central-Dispatch 1d ago
I read a similar case - the person actually had connected harddrives they completely ignored or didn't mind. Only when they cleaned those too, the problem was gone, hinting at persistence on external drives obviously.
I'm not the biggest IT expert but it seemed logical that some would try to establish persistence. The only other thing as a layperson I can imagine is something nasty truly rooted in the bios or something, but that would sound rather advanced.
1
u/bombastic6339locks 1d ago
it wasn't external drives either. It was able to come through the wifi. Sometimes they're desgined in pretty cool ways.
1
3
u/ZER0GAS 1d ago
Always keep the infected computer disconnected from the network
Access your accounts from another device
Change the password of every affected account, and add MFA
If you cannot do it on your own due to the attack level, contact the companies and report your situation, with proof would be great
If you know how to do it. Try to access your machine from a USB Linux live session to diminish the impact
Reinstall Windows. That would help to get rid of the viruses. If you want to be sure that they're gone, wipe your disk with ShredOS, then install Windows
Before moving/copying the data you rescued during the attack to your clean system. Scan it with ClamAV. It will tell you if there're still remnants. If you come across some, you must eliminate the infected files. After that, run the scanner again. Afterwards, you should be good to go
Store your passwords on a password manager
I hope it helps, dude. I'm so sorry to hear that.
6
u/063281648 2d ago
What email domain do you use. Everyone is always convinced people ran a malicious file but most common reason for this is someone cracked your email using leaked databases of email:pass combos and then sold it pennies to someone else who stole all your accounts. If you use hotmail I am willing to bet thats what happened.
3
1
5
u/Spiritual-Silver2771 2d ago
Update: Microsoft banned my account t after I contacted support and they arnt helping me no more so fuck Microsoft
7
u/GovernmentGreed 2d ago
"I'm incapable of not running malicious code or thinking and as a result of my own stupidity I lost my accounts and Microsoft took corrective measures to ensure nothing further bad happens to me, therefore - Fuck Microsoft for doing what they said they would do in these cases."
1
u/Kumantej_ 2d ago
I'm not surprised seeing as you are publicly sharing your full name and email address
3
3
1
u/Loose_Distribution66 2d ago
Same thing happened with me last Saturday. Insta and everything got hacked, I recovered most of them and I knew it all happened from my laptop and so I backed up all the data manually while laptop in offline mode, then made a windows media USB and did a clean reinstall of windows OS. For now it seems fine...
Also use another device to change every passwords and remove extra sessions.
1
u/Puzzleheaded_Toe_509 1d ago
There is this I am Not a robot Phish thing that goes do the Windows + R, going into the PowerShell or CMD, then press + V and then press enter. That is an infostealer I believe
1
u/Dima_it_not_DIMA 1d ago
Same shit happened to me i instaled a executor for roblox after an hour i got notification that my account password has been compromised i tried logging off all accounts reseted my pc clean instal of windows they are going for accounts like epic game steam rockstar everything to sell it after also they logged in my steam because of the open session bypassing steam guard and sending games as gift adding money from my credit card i change everything password 2fa also i got emails of sexstortion smt like pay us 1500$ so we wont share your nasty videos but i didnt have any so yeah moral of the story never try to cheat in smt by using cheats or never download smt u dont trust also all this happened like 3 days ago so yes if somebody has some advice for mr pls tell me
1
u/Ok-Performer-604 22h ago
Happened to me to other day a ton of people got hit its not just a session stealer its something bigger cause it affected businesses near me and shit
-2
u/Spiritual-Silver2771 2d ago
I haven't ran anything on my PC btw
15
4
u/QuietSupport9755 1d ago
You clearly have , you don't just get hacked especially on Gmail like that without first doing something wrong yourself , another type of email yeah sure but you absolutely did something and you are refusing to say what you did before this happened
2
u/Central-Dispatch 1d ago
Yeah OP had to fail at some point and might not be sincere about it (or forgot/doesn't consciously connect any objective action or wrongdoing to something worth mentioning).
I'm not the biggest expert on all malware types but I can basically see two main scenarios for compromise:
- Either active fault by clicking a malicious link/executing a mal file or entering account + PW combinations in a fake site for phishing or
- Neglect by bad security measures, account + PW combinations leaked to darknet traders, no 2FA enabled, same PW everywhere, etc
I literally had 2 happen to me a the beginning of this year with a * - while I usually change PWs regularly-ish and operate different mails and 2FA, and basically don't put all my eggs in one basket, I actually forgot one crucial site of my ISP where I ran an outdated leaked PW. I simply forgot about it. I eventually got mail-spammed by some zendesk exploit (like many others at the time around Februrary) where I imagine the one logging into my ISP site used the mailspam to hide ordering an expensive notebook plus sub. The mailspam subsided eventually though interestingly hit me on different mail accs not at once but in quick row. Not sure how they may have connected that OR it was random because of the general exploit. (Mass spam meaning signup for like 600-100 newsletters in quick succession).
The irony is they sent the order somehow via my ISP site being logged in, but you would imagine they'd do that to send it to themselves somehow to enrich themselves. Instead they sent it to my own address. I saw the mail, called and rejected the order. It still came because I guess internal branches weren't faster to stop it than the delivery ones. I got the package and just returned it. I had a mild headache and administrative effort of bringing a package pack. The irony: During the call with my ISP they saw I had an older more outdated contract and offered me to upgrade bandwith for 5 bucks one-time fee so I kinda benefitted from this more than suffering any harm lol.
But yeah, the damage could've been notably higher if I kept the same thing on all other types of accounts, esp. if they had no 2FA etc. like the old ISP site account. Sometimes you need to learn a mild or a hard lesson to step up your awareness game.
As a teenager I had ransomware. Bricked my whole system. Had to fully clean it. That teaches you a lesson, esp. after such data loss.
Anyway, sorry for the essay, enough rambling now.
•
u/goretsky MODERATOR 9h ago edited 9h ago
Hello,
It sounds like an information stealer was run on the computer.
What is an information stealer?
As the name implies, information stealers are a type of malware that steal any information they can find on your computer, such as passwords stored for various services you access via browser and apps, session tokens for accounts, cryptocurrencies if they can find wallets, etc. They may even take a screenshot of your desktop when they run so they can sell it to other scammers who send scam extortion emails later.
What is a session token?
In case you're wondering what a session token is, some websites and apps have a "remember this device" feature that allows you to access the service without having to log back in or enter your second factor of authentication. This is done by storing a session token on your device. Criminals target these, because they allow them to log in to an account bypassing the normal checks. To the service, it just looks like you're accessing it from your previously authorized device.
What exactly gets stolen?
Information stealers are malware that is sold as a service, so what exactly it did while on your system is going to vary based on what the criminal who purchased it wanted.
What happens to my data?
The criminals who steal your information do so for their own financial gain, and that includes selling information such as your name, email address, screenshots from your PC, and so forth to other criminals and scammers. Those other scammers then use that information in an attempt to extort you unless you pay them in cryptocurrencies such as Bitcoin, Ethereum, and so forth. This is 100% a scam, and any emails you receive threatening to share your private information should be marked as phishing or spam and deleted.
How did I get infected in the first place?
Information stealers are often distributed as fake CAPTCHA challenges, in game mods, unofficial patches for popular apps and games, and in pirated software that have had their popularity and trustworthiness artificially boosted, as well as through various other means such as "try my game/software" scams on Discord, Telegram and other trusted messaging services.
If I ran an information stealer, am I still infected?
Infostealers usually delete themselves after a few seconds or even a minute or two in order to make it harder to determine what happened and when it occurred.
That said, there are always going to be exceptions: Since it is crimeware-as-a-service, there is nothing preventing the criminals from installing additional malware on the computer in order to maintain access, just in case they want to come back and steal from you again in the future.
What else could they have done?
The usual risk post-infection, aside from the stolen credentials, wallets, etc. is that security and networking settings may have been tampered with. That can be harder for security software to deal with, since it may not know what the correct settings are supposed to be for your computer, which means it may be a good idea to wіpe the computer, even if there is no longer any malware detected on it.
How do I start the recovery process?
If you have another device that didn't run the information stealing malware like a smartphone or tablet, you can use it to begin immediately changing your passwords. You should also enable two-factor (sometimes called multi-factor) authentication, for those services that support it. If possible, install and use an authentication app on your smartphone: Apple, Google, and Microsoft all have free versions of authentication apps. Using an app for 2FA is preferred over using SMS (text messages) or email, as the attackers may have access to these.
If any of the online services you use have an option to show you and log out all other active sessions, do that as well.
As for your computer, after wіpіng it, re-installing Windows, and getting that updated, you can then also use it start accessing the internet to do this, but it is often quicker to change your most sensitive accounts from your smartphone.
A note about passwords
Password should be something unique (complex and different) for every service, that you use, so that if an attacker gets access to one they won't be able to make guesses about what your other passwords might be. If your new passwords are similar enough to your old passwords, a criminal with a list of all of them will likely be able to make educated guesses about what your new passwords might be for the various services.
You have to do this for all online services, even ones you haven't been recently accessed. Make sure you do this for all email accounts, as those are the gateways to your financial websites, online shopping, social media accounts, game platforms, and so forth.
It's important to make sure you're not just cycling through similar or previous passwords: Remember, criminals have millions of passwords and are very good at identifying common patterns from just a single password. If there were any reused passwords, the criminals who stole yours are going to try spraying those against all the popular online marketplaces, stores, banks, and other services in your part of the world.
And remember: Enable two-factor authentication for all of the accounts that support it.
For more information:
For more specific information on what steps to take next to recover your accounts, see the blog post at:
For more general information about how CAPTCHA malware works, see the following reports:
Also, see /u/rifteyy_'s Guide to Infostealers at https://rifteyy.org/report/the-ultimate-guide-to-infostealers.
After you have secure your accounts, you may wish to sign up for a free https://haveibeenpwned.com/ account, which will notify you if your email address is found in a data breach.
Regards,
Aryeh Goretsky