Discord Infostealers: How hackers steal your password

Поделиться
HTML-код
  • Опубликовано: 1 окт 2024
  • Discord Infostealers can hack your accounts by stealing your passwords and tokens if you fall for a malicious link in discord, beware of messages about free games etc. Check out Intezer Analyze (sponsor) : analyze.inteze...
    Buy the best antivirus: thepcsecurityc...
    Join the discussion on Discord: discord.tpsc.tech/
    Get your business endpoints tested by us: tpsc.tech/
    Contact us for business: thepcsecurityc...

Комментарии • 390

  • @CoolJosh3k
    @CoolJosh3k 2 года назад +390

    A video all about how attackers can get around 2FA, and what can be done to lower the risk, would be really good.

    • @dripful.
      @dripful. 2 года назад +5

      the truth about 2fa is that it mostly get you ( legit user ) problems with login ( example your phone is discharged and you are trying to login to discord ) when a hecker can bypass it easily with a token ( doesn't matter if it's encrypted or not.)

    • @CoolJosh3k
      @CoolJosh3k 2 года назад +8

      @@dripful. It has flaws, but still a big improvement in security. There are worse ways to lose access than just not having your phone charged.

    • @farawaygaming_
      @farawaygaming_ 2 года назад +2

      @@dripful. this is a problem I have, my phone is no longer connected to service, so I cannot get the 2fa text message

    • @dripful.
      @dripful. 2 года назад

      @@CoolJosh3k ur phone is broken for example and what you gonna do?

    • @____-fv4bm
      @____-fv4bm 2 года назад +1

      @@dripful. Bitwarden premium. 2fa anywhere.

  • @abitterberry2149
    @abitterberry2149 2 года назад +80

    I've seen an interview about Minerva, its supposedly an "antivirus" that uses those virtualization detection and other stuff against the attacker. I think its amazing to approach cybersecurity from this angle! I don't know if its only an entreprise product but I wonder if you'd be willing to make a video, it would be so interesting!

  • @mnageh-bo1mm
    @mnageh-bo1mm 2 года назад +56

    Hey ! Clicking the link only doesn't do anything
    You have to download the file and then open it by yourself
    it's not magic like you saying !

    • @wannabedal-adx458
      @wannabedal-adx458 2 года назад +12

      But I would start with the first line of cyber defense: "Don't click on suspicious links or links from people you don't know!"

    • @mnageh-bo1mm
      @mnageh-bo1mm 2 года назад +5

      @bhavya prashanth lol no way you get hacked by a link that's considered 1 click vuln which is very expensive .... do your research fam

    • @mnageh-bo1mm
      @mnageh-bo1mm 2 года назад +6

      @@wannabedal-adx458 yeah sure
      clicking links wouldn't be a problem tho if people weren't so keen on entering their passwords into them the second they load

    • @declan_youtube
      @declan_youtube 2 года назад +5

      @@mnageh-bo1mm They can attack by using embeds to download malware, but it is very rare and kinda impracticle

    • @mnageh-bo1mm
      @mnageh-bo1mm 2 года назад +2

      @@declan_youtube what do you mean? Drive by download?

  • @ExtrymGamingLTU
    @ExtrymGamingLTU 2 года назад +91

    I'm still confused how they get into your system. Do you only need to click on their "Free Discord Nitro" link and that's it, your discord account is compromised, or do you need to put in your login credentials in those websites or download something?
    Asking cause everyone says that all you need is a click on the link and I want to know if that's actually true or does it take a bit more interaction

    • @Appoxo
      @Appoxo 2 года назад +51

      To me the title says that you only have to click the link, while the video talks like you need to download the file and execute it.

    • @DOSeater
      @DOSeater 2 года назад +19

      You need to download an execute a file

    • @hd9g
      @hd9g 2 года назад +25

      I watched the entire video and still confused who the malware was activated.

    • @kritikusi-666
      @kritikusi-666 2 года назад +24

      Yeah it is misleading. You definitely need to execute the program. I download many things to try and infect my virtual machine for testing and research. I have yet to come across something that that is new and sophisticated behavior like that haha. I can see it happening via pdf files or something micro related, but this was a bit puzzling. =)

    • @Iuffycs
      @Iuffycs 2 года назад +8

      You either have to download an executable file, or enter your credentials into a "login page".

  • @Neraam_S
    @Neraam_S 2 года назад +79

    how to avoid this: simply don't click on the links

    • @Raecrisos
      @Raecrisos 2 года назад +6

      Does clicking just the link instead of executing the files affect your machine? I'm new to IT security stuff just curious.

    • @xMicrostar
      @xMicrostar 2 года назад

      @@Raecrisos you can be injected with malware (through javascript) and you wont even notice.

    • @yottawatts9470
      @yottawatts9470 2 года назад +5

      It can yes. People can use security exploits in the browser to get access to your hard drive.

    • @grieveinsilence
      @grieveinsilence 2 года назад +4

      ​@@Raecrisos I think its easy for them to make links whose the browser download and execute it without your intervention(clicking),so... both?

    • @DogeMaster
      @DogeMaster 2 года назад +7

      @@Raecrisos generally no, however as the other replies say, its entirely possible for browser exploits to be used to do stuff without user intervention. make sure your browser/system are up to date to help with stuff like this, but of course not clicking shady links will give maximum protection

  • @finsflexin
    @finsflexin 2 года назад +15

    Don’t worry I won’t be hacked. I message Discord Bots my passwords to keep track of them, I trust them.

    • @Unidentified_Entity6
      @Unidentified_Entity6 2 года назад

      your token can easily be stolen and they can easily see the messages

    • @finsflexin
      @finsflexin 2 года назад +4

      @@Unidentified_Entity6 😭

  • @Qwepyt
    @Qwepyt 2 года назад +14

    They don't steal it! *You give It to them!*

  • @GummieI
    @GummieI 2 года назад +86

    O_o Must admit I assumed passwords stored in the browser would be encrypted

    • @DOSeater
      @DOSeater 2 года назад +20

      They are, but the encryption key is easily accessible

    • @ricogoins
      @ricogoins 2 года назад +10

      @@DOSeater That's so dumb they should store it server sided

    • @alessioantinoro5713
      @alessioantinoro5713 2 года назад +26

      @@ricogoins That's worse

    • @CrackThrough
      @CrackThrough 2 года назад +3

      @@alessioantinoro5713 yeah, practically & the cost is too high because you'd have to transfer the whole file for each account
      + we cant really use something that works like RSA (because you'd still have to toss the private key to clients if you use your account on multiple devices)

    • @CrackThrough
      @CrackThrough 2 года назад +1

      also csv convertion being very accessible

  • @BreadMan434
    @BreadMan434 2 года назад +12

    This is why I don't have any cookies saved by default, with Firefox set to strict by default for cookie protection just in case.

  • @iburry
    @iburry 2 года назад +15

    I know that Firefox keeps logins in a simple text file, but they are, supposedly, encrypted. Are they really just that easy to read?

    • @LXST-IN-TRVNSLVTIXN
      @LXST-IN-TRVNSLVTIXN 2 года назад +2

      you have to set a master password, if you dont its easy to read

    • @Mr.Unacceptable
      @Mr.Unacceptable 2 года назад +1

      Yes. You can also read them through commands from the windows install disk of a passworded windows install. As well as change the password of that install. Just using the CMD and admin privileges on the install disk. You can find step by step instructions how to change the password of a pc using the disk. Everyone should do it to their own systems as a learning tool.Anything you can do with admin privileges on a passworded and encrypted system with the password key you can do with the windows install disk using the CMD command window and a USB CD-rom or windows install on a USB stick. The only stop I found for this is to password your BIOS after you set it to only start up from your hard drive.

  • @ye_nope
    @ye_nope 2 года назад +6

    how does the malware get executed if you just download a zip file though

  • @double421
    @double421 2 года назад +5

    Can you recommend a proper Password Manager? (For Windows)

  • @thrices4372
    @thrices4372 2 года назад +16

    I wish intezer were able to have affordable prices for small business that are starting on the security area.

  • @arnav_mehta
    @arnav_mehta 2 года назад +15

    keep up the good content ☺️

  • @crowruin2
    @crowruin2 2 года назад +12

    Yeah this one has been making the rounds a lot lately
    To anyone who reads this if you haven't done it already I would turn off DMs from server members
    This makes it so the person has to add you to message you
    Right Click a server > Privacy Settings > Untick Allow DMs from server members
    If you want to have it set to not allow DMs by default on joining a server
    User Settings > Privacy and Safety > Server Privacy Defaults
    Untick Allow DMs from server members
    Of course though watch out for friend's who's accounts are compromised

    • @Appoxo
      @Appoxo 2 года назад

      Can you whitelist users that want to msg me? I am a member in some discord tech servers that helped me troubleshoot big projects via dms (would have exploded the chat)

    • @crowruin2
      @crowruin2 2 года назад

      @@Appoxo unfortunately no you would have to add those users so they could message you
      You can pick and choose what server that setting applies to of course so I would do that

  • @PandaMilitary
    @PandaMilitary 2 года назад +7

    Hi sir can you pls test windows defender vs malware in 2022 because I love Microsoft's antivirus and I want to see if its good.

  • @ardeof
    @ardeof 2 года назад +11

    There's also a token stealer called "2d_pong.exe". Once launched, they're within your account in seconds and already have the password changed and whatnot.

    • @ep1k_4
      @ep1k_4 2 года назад +1

      umbrella jump: hold my scam

  • @venekus7983
    @venekus7983 2 года назад +3

    Can Kapersky and other anti-viruses detect this malware or no?

    • @xohnji
      @xohnji 2 года назад

      It can detect

  • @marcuspvxea
    @marcuspvxea 2 года назад +15

    TDLR:
    Don't run something you dont know about.

  • @antysiq
    @antysiq 2 года назад +11

    thats what i needed right now, thanks! 🤝🏼

  • @gregritferdjr
    @gregritferdjr 2 года назад +1

    This just happened only 3 hours ago and I thought I was unhackable. You’re not. Nobody is.

  • @SikedGuy
    @SikedGuy 2 года назад +2

    Can Malwarebytes detect stuff like this?

  • @TheBauwssss
    @TheBauwssss 2 года назад +11

    Yeah, this is all very nice, but to be honest I was really hoping you were going to answer the elephant sized question that is currently burning in everyone's mind? With that question being:
    How and since when, in the name of all that is holy, does the simple act of clicking on a link in a discord chat result in your system becoming the victim of a drive-by download attack? How is it possible for a simple, *single* click on a link to result in malware being autonomously downloaded, executed and installed onto your system? (And somehow the malware installer even managed to gain administrator privileges *without* triggering any UAC prompt whatsoever!?!? (At the very least I am pretty sure the malware somehow gained administrator privileges, because it stands to reason, and I very much hope so that it is indeed the case, that the folder C:/WINDOWS is completely read-only for anything and everything, _except_ for an elevated processes, right?

    • @raylopez99
      @raylopez99 2 года назад

      I don't know, but it seems Discord is not the place to be if such nasty stuff happens. Discord is like Skype? But with executable files from games and stuff?...not good seems to me.

    • @TheBauwssss
      @TheBauwssss 2 года назад +1

      @@raylopez99 yeah, you're quite right indeed, this is quite the mess! is Skype somehow vulnerable too? If indeed the case then that would suck so bad because I was still using that daily! :(

    • @raylopez99
      @raylopez99 2 года назад

      @@TheBauwssss Maybe. I recall getting a lot of unknown pings and traffic from all over the world...I thought I was being hacked, until it turns out the culprit was Skype...that's the way it works, you can get anybody from anywhere in the world pinging you, and maybe sending you files (or requests to be your friend, and so forth). So what I do now is only restrict incoming calls from people on my Skype "contacts list" and further I only use Skype when I want to make a call, so I don't start it automatically at startup. Problem solved.

    • @declan_youtube
      @declan_youtube 2 года назад

      There are a few ways. Depending on the browser, when you visit a website it can automatically install malware without telling you it's installing anything. Bypassing the UAC is possible with vunerabilites with apps you install, and if it asks you to give admin privileges to it some people would allow access. Another way of bypassing UAC is admin permissions aren't required to send keystrokes, so in the UAC if it doesn't ask for a password and it's just yes or no they can press the arrow keys to Yes. As far as I'm aware, C:/WINDOWS is read only even for Administrators, and you require SYSTEM level permission to edit it (not saying Malware can't get that, but it's more than just Admin)

    • @wrockd
      @wrockd 2 года назад

      @@declan_youtube Yea you can "Download" malware but not "Install" it automatically. Both are different terms.
      And while bypassing UAC isn't that hard in itself, but the methods that you stated are useless. Emulating Keystrokes doesn't work for UAC on Win 10. The UAC Prompt is displayed on a Winlogon Desktop, which is a SYSTEM Privileged Desktop(Kindof a User Account) separate from your common Local one and could only be accessed by users with Local System privileges. Pretty much the reason why you can't screenshot UAC Prompt nor access it with RDP Software. And if a software is already running with Local System Privileges it doesn't need to elevate anyway. And there are two basic/fundamental ways to Bypass UAC/Privilege Escalation one is Using an existing escalated process that is suspended and then injecting the malicious payload into that process and waking it, second is the good ol' DLL hijacking, manually changing registry values also worked before but it's been patched for good.
      But anyway, any of this doesn't matter unless you don't manually run the downloaded executable yourself, browser doesn't execute any downloaded binary itself.

  • @heyclip
    @heyclip 2 года назад +8

    I've been recieving a ton of messages like this, I've had some fun decompiling the whole thing, most times it's either a node application or a modified betterdiscord installer, I've also noticed that it seems to be sending the token to a telegram bot, great video as always!

  • @citizenkimi
    @citizenkimi 2 года назад +7

    I've seen Intezer has added an URL analyzing tool too, but it was moved into the Enterprise plan after some days and I basically couldn't manage to use it more than a few times. What gives?

    • @CelesteOnYoutube
      @CelesteOnYoutube 2 года назад

      Well they are not a charity...

    • @citizenkimi
      @citizenkimi 2 года назад

      @@CelesteOnRUclips If they told the users what they were going to do it'd be useful

  • @Alex13312
    @Alex13312 Год назад +1

    In discord I go to settings and go to devices and see that the operating system is linux even though I use windows 10 but when I reset the password in a few hours the same linux user and the same location is back.

  • @Re0Search
    @Re0Search 2 года назад +5

    Yo tpsc, I want to be like you someday. How do I start and what do I need to learn in college and etc? I'm in Highschool about to be in college right now and I like to learn cybersecurity.

    • @Re0Search
      @Re0Search 2 года назад

      @@r3tr0n17 I don't even know what you just said, sorry if i'm asking too many questions but what are those?

    • @TheArthas17
      @TheArthas17 2 года назад

      Also learn just basic coding on yoir free time, like Javascript, etc

  • @ULTRACOMFY_eu
    @ULTRACOMFY_eu 2 года назад +3

    I accidentally got infected by this when I tried analyzing it with pestudio on my main PC - single click got registered as double click and boom, file was running. The only thing that saved me was my virtual firewall (TinyWall) that didn't let it exfiltrate any data. Then ran every virus scanner under the sun on my PC and installed a VM so this doesn't happen again.

    • @DvirMuja
      @DvirMuja 2 года назад

      You single clicked it, basically highlighting the file and it still launched? How?

    • @ULTRACOMFY_eu
      @ULTRACOMFY_eu 2 года назад +1

      @@DvirMuja Well I don't know. I assume it was human factor, but it really didn't feel like a double click. Happens.

  • @swiftsilver
    @swiftsilver 2 года назад +4

    redline stealer is so common. Many people on russian forums have their own paste of redline stealer from its source. It's just good!

  • @Yomush
    @Yomush 2 года назад +9

    And that's why, ladies and gentleman you should turn off DMs from server members. So you don't get attacked by bots with shady links and get your info stolen

    • @BrambleTakato
      @BrambleTakato 2 года назад +4

      I personally think the main takeaway is the number one rule of the internet;
      Do NOT click said shady links… At all.

    • @portman8909
      @portman8909 2 года назад

      Measure twice and cut once.

  • @thearousedeunuch
    @thearousedeunuch 2 года назад +9

    Aren't password managers a safety risk in and of themselves?

    • @DuhNoU
      @DuhNoU 2 года назад +5

      depends on the quality of it

    • @lukeyxo
      @lukeyxo 2 года назад +5

      pretty sure stuff like icloud has it encrypted on their side too so if icloud gets hacked the hackers will just get a bunch of really encrypted files and stuff, could be wrong as i read about this once long ago when i was bored

    • @_BangDroid_
      @_BangDroid_ 2 года назад

      @@DuhNoU How do you quantify the quality of various PW managers?

  • @User-iw4oo
    @User-iw4oo 2 года назад +9

    ways to avoid this:
    1) don't click the link
    2) Use a vm (virtual machine) without any saved data and paste the download link there. (Make sure file sharing is disabled between Host (Your pc) and guest (The vm). If something happens on your vm, even more noticeable since there's only the default processes, it's a virus.
    3) disable messages from non-friends

    • @ok-hk2rc
      @ok-hk2rc 2 года назад

      If I copy the link, so I can scan it with a link scanner will I get in danger or I only will get in danger if I click the link?

    • @User-iw4oo
      @User-iw4oo 2 года назад

      @@ok-hk2rc the danger is not always clicking the link. Most of the time it is downloading the file with the link. Still, don't click on links from random people

    • @ok-hk2rc
      @ok-hk2rc 2 года назад +1

      @@User-iw4oo oh alright

    • @User-iw4oo
      @User-iw4oo 2 года назад

      @Sonic Hedgehog while this is true it cannot be applied in all situations

    • @swilleh_
      @swilleh_ 2 года назад

      your friends can be hacked too and then the hacker will sent the "put something in here" to hack you

  • @focat
    @focat 2 года назад +5

    ah yes, a replit website, thats how you know the developer didnt put enough effort to buy a domain

    • @vouchmeclips8537
      @vouchmeclips8537 2 года назад +2

      You don't need to buy a domain though? You can host the web page off your PC. Replit is a far more easier and navigable option. And even if you buy the domain, you still need a web server or client-server to host it.

  • @kvetinky
    @kvetinky 2 года назад +1

    How to clean off discord’s browser cookies, so i can get rid of this.

  • @codedaily365
    @codedaily365 2 года назад +2

    Some use BEEF malware within the browser to hack.

  • @ep1k_4
    @ep1k_4 2 года назад +2

    did anyone ever hear of $9394, MixerSquad or Umbrella Jump? in my case of being hacked it was late at midnight and someone wanted me to try out his game (and wasn't calm at all i fell for it just because of the time pressure)

  • @marekmaxpabianice
    @marekmaxpabianice 2 года назад +2

    WHat about firefox and protected with a master password?

  • @rpe
    @rpe 2 года назад +5

    Great tutorial! It really helped me!

  • @SWC44
    @SWC44 2 года назад +3

    IF ONLY IF THEY GOT " REAL JOBS " !!!!!!!!

  • @yoruichishihoin8335
    @yoruichishihoin8335 2 года назад +4

    How do you get this virus again, simply visiting the site or downloading the self-proclaimed "free" game and running it?

    • @Mario583a
      @Mario583a 2 года назад

      People can embed malicious files on Discord and try to trick you into executing it.
      Meanwhile Discord's Trust and Safety literally has no visible way to report the hosted CDN files.
      Well, they do have a [Report Spam] function if you get it via DM, but still....

  • @roninstormYT
    @roninstormYT Год назад +1

    if it is our password that saved how do we keep the passwords for each account we canot just remember then use it for all accounts thats how they get in i have a new pass for all my accounts youtube twitch xbox playstation nintendo amazon other online servces . where do we right them then on a offline pc that we never go online with ?

  • @ProximoNovio
    @ProximoNovio 2 года назад +1

    So how do you scan large files with this website?

  • @Computer-Catt
    @Computer-Catt 2 года назад +3

    you fail to mention a lot of things
    they cant get your passwords if you dont save them in chromium browsers
    and if you have discord installed they can only get your session token
    you may reset your session token by or changing your password to the same one if you are lazy
    or enabling 2fa

    • @opfromthestart3645
      @opfromthestart3645 2 года назад

      He mentioned that firefox is also vulnerable, and it is not chromium based.

    • @Computer-Catt
      @Computer-Catt 2 года назад

      @@opfromthestart3645 firefox is chromium based

    • @opfromthestart3645
      @opfromthestart3645 2 года назад

      @@Computer-Catt it isnt though, mozilla has their own engine

    • @Computer-Catt
      @Computer-Catt 2 года назад

      @@opfromthestart3645 googled it seems that you are correct
      my source came from experience when i launched a chromium password stealer on my pc to see what would show up
      amongst those was firefox
      thats why i thought
      farewell

  • @nickmullen9510
    @nickmullen9510 6 месяцев назад +1

    I dont understand what is the point of showing some random info stealing malware what is actually important is being aware of the attack vector, when it comes to the malware itself, there are infinite variants that do the same or slightly different things, the wow now it can steal more is not really that informative

  • @RedSaltedEGG
    @RedSaltedEGG 2 года назад +23

    Lets say you do get affected by this, how would a regular user detect and remove it? Would antiviruses detect this on scan (assuming theyre not obfuscated, etc)?

    • @unstyled3509
      @unstyled3509 2 года назад +1

      antiviruses can find it, sometimes if it's on an autolaunch you can uninstall it or end it with task manager (i think anyway)

    • @SamiV2
      @SamiV2 2 года назад +2

      @@unstyled3509 you can turn of the auto launch from settings

    • @unstyled3509
      @unstyled3509 2 года назад

      @@SamiV2 oh yeah, or that, to be honest I completely forgot about autolaunch settings and stuff lol

    • @vouchmeclips8537
      @vouchmeclips8537 2 года назад +1

      Antiviruses usually have a system where they get a list of all new malware and viruses and then build a defence against it and make it easier to detect. It's both automated and a manual process but that's why antivirus software are so expensive.

  • @cris2k344
    @cris2k344 2 года назад +1

    which pasword manager would you recommend, both free and paid

  • @jukebox581
    @jukebox581 2 года назад +2

    aside from login in on browser apps, just ignore peeps sending links that you dont know and even if they're real people and genuine, just don't.

    • @kirstan
      @kirstan 2 года назад

      The Internet is a scary place

  • @ghxst9207
    @ghxst9207 2 года назад +1

    I clicked the free discord nitro link and it hacked my account.

  • @Baburun-Sama
    @Baburun-Sama Год назад +1

    This is Known as "Phishing"

  • @the_silent_one_
    @the_silent_one_ Месяц назад +1

    Thanks for the tutorial :D

  • @xXLaciWarriorXx
    @xXLaciWarriorXx 2 года назад +1

    that f-cking intro man! I literally jumped up to that gunshot noise in the middle of the night.

  • @Doge36064
    @Doge36064 2 года назад +2

    OMG that happend to me sometime he said hi, i got a free game i made wanna try it i was smart enough to not click it!

  • @arnav_mehta
    @arnav_mehta 2 года назад +3

    Which Antivirus do you use personally?

    • @hircine92h
      @hircine92h 2 года назад

      He did a video a while ago on this. I think he uses Comodo with some combinations.

    • @shellohd8421
      @shellohd8421 2 года назад

      @@RUclips.Pigeon its garbage

  • @jamesphillipshort
    @jamesphillipshort 2 года назад +1

    I had a weird experience one time on Discord that ultimately got me booted from the Samsung Care Ambassador Program.

  • @onlyVetements
    @onlyVetements 2 года назад +1

    i assume this doesn't affect safari, macos users?

  • @ixlys
    @ixlys 2 года назад +1

    just use ur own voice..

  • @ankitminz5872
    @ankitminz5872 2 года назад +2

    That's frightening

  • @gusty2333
    @gusty2333 2 года назад

    How does one manufacturer a virus? cause it sounds like copy and pasting code that you want in the virus

  • @alexthedarkskin
    @alexthedarkskin 2 года назад +1

    attack the attacker!

  • @SDKLarrabee
    @SDKLarrabee 2 года назад +1

    fuck this im saving my passwords on browser dont know what to do now :(

  • @theyreheretokillus
    @theyreheretokillus 2 года назад +1

    so u want a new os

  • @sh_gosha6867
    @sh_gosha6867 2 года назад +2

    Nice

  • @cllncl
    @cllncl 2 года назад

    2:46
    Russia just HAS to fuck everything up, doesn't it

  • @notoneaura
    @notoneaura 2 года назад +1

    2FA makes you no 👎 hacking.

    • @netLG
      @netLG 2 года назад

      no not really if they get your token

  • @TheBoostedDoge
    @TheBoostedDoge 2 года назад +1

    This is why 2fa is important

    • @Josuegrs
      @Josuegrs 2 года назад

      @anonymous anonymous He probably means other sites credentials that are stolen with this malware. Even if they have your username and password retrieved through a browser's saved passwords, they won't be able to access your accounts unless they have the TOTP. This is why we must use password managers in combination with a 2FA and strong master password to manage all our passwords.

  • @Weston_Guidero
    @Weston_Guidero 5 месяцев назад

    If i've been infected by this on my computer what should/can i do about it? Should I wipe my C:/ drive completely is that the only way of removing the virus? It could be a trojan or this, but it was basically this scenario in discord except they asked to type in a password to access an .exe in a .rar file then once i typed it in and it ran the .exe. he hacked my discord and could still add himself on my new discord, because i believe he had access to my session tokens or keylogger on my ip potentially? I'm not sure which. But question remains: Do I wipe my C drive and I'm good? I have multiple other drives, I disconnected it from the internet and removed, uninstalled and deleted all files that I know of with the file name of the exe/virus. However I know there could still possibly be other software or infected system files. I had that exact microsoft framework file as well giving me pop for that file specifically that i need user privileges or something to remove it (I will get back to you on the specific message).

  • @StirsMYCookiez
    @StirsMYCookiez 2 года назад +2

    Hey Leo, little reminder about the video description, "buy the best antivirus" links to an old url, should be "best-antivirus" after the domain, instead of "best"

    • @zombies1238
      @zombies1238 2 года назад

      Thanks, I will send this to Leo

  • @Drake-sl8jd
    @Drake-sl8jd 2 года назад +1

    Just got hacked and then video comes out... nice

  • @brillie_bean4178
    @brillie_bean4178 Год назад

    Hey I need help....I know some people who are talking to minors and getting them to send explicit images I need help getting contact with more victims and I thought one of their discord was a good idea ....I have no idea how now that I've been blocked-

  • @ItsLone_Plays
    @ItsLone_Plays 2 года назад

    My Discord account has gotten hacked, I need help getting it back. Is there a way you could help me?

  • @DahoodRex
    @DahoodRex 2 года назад

    you could tell his mouth that he talking in like bengail or something thats why he use this audio

  • @Lewboskii
    @Lewboskii 2 года назад

    any recommended antivirus?

  • @mini_toaster
    @mini_toaster 10 месяцев назад

    Is Kaspersky a good anti-virus and can it detect a virus like that?

  • @Wojtas01
    @Wojtas01 2 года назад

    i got hacked on steam because of a discord hackwe hacked a polish guy and i lost my steam account

  • @MrNifts
    @MrNifts 2 года назад +2

    This is why you use MFA where ever possible

    • @zombies1238
      @zombies1238 2 года назад +3

      This specific strain of malware also has an async function that checks for tokens. If they find those, a simple CRXF attack can bypass MFA

    • @MrNifts
      @MrNifts 2 года назад

      @@zombies1238 arh , ok. Thanks

    • @markx7139
      @markx7139 2 года назад

      @@zombies1238 do you mean crsf?

  • @Roki_100
    @Roki_100 2 года назад

    thats why people should stop using discord :)
    it has more bugs, issues than features
    2fa is just a visual thing as tokens bypass it, voice channels are only an forgotten and abandoned poorly made addition, yet people still use it on daily basis, what is wrong with people

  • @Shinedown2012
    @Shinedown2012 2 года назад

    Now I don't feel as bad about Russia future.

  • @WXcq-ph8fn
    @WXcq-ph8fn Год назад

    Thanks now I can get the mfs who nuked my server

  • @tensterss
    @tensterss 2 года назад

    please add some delay to the microphone because it doesnt match up with the video

  • @Quandle69
    @Quandle69 2 года назад

    If i Start an grabber in an virtualbox can he get any information from me?

  • @Quandle69
    @Quandle69 2 года назад

    If i Start an grabber in an virtualbox can he get any information from me?

  • @buzer2011
    @buzer2011 2 года назад

    So you have to actually open the downloaded zip file and run the .exe, or what? The video isn't clear on how the malware is activated.

  • @itamarsharlin
    @itamarsharlin Год назад

    If someone get my token he can get hack into my computer?

  • @Uushiine
    @Uushiine 2 года назад

    im doing this to have my friedns account

  • @sammay4493
    @sammay4493 2 года назад

    Definetely not trying to use this on my friend....

  • @HelloGlamorous
    @HelloGlamorous 2 года назад

    lmaooo one of my buddies keeps having this happen to him because he tries to download mod menus for fortnite

  • @arronyk1250
    @arronyk1250 2 года назад

    well ive been hit by one but it wasnt an ordinary grabber it was a website it stole all of my broswer passwords

  • @HolyLightofAngel
    @HolyLightofAngel Год назад

    I want to do this to someone without sending them a link, is it possible?

  • @MMT-24-7
    @MMT-24-7 2 года назад +1

    Great video! 👍🏻I was wondering if it is possible to bypass virtual machine detection. Personally I think it would make for a great video, but I'm saying that with the little knowledge I have concerning the topic. Anyhow, keep up making great videos and know that you just earned another sub!

  • @SabishiiVT
    @SabishiiVT 2 года назад

    i wish this video came out last year, i got hack last year with the "wanna try a free game" i had 2FA On and they went threw it, all of my two account's where hack so i can not get it back

  • @buttersxp
    @buttersxp 2 года назад

    its rat they can login ur acc with tokens

  • @killunova
    @killunova 2 года назад

    have you guys gotten the "I accidently reported you click this link to talk to your employee one LOL.

  • @nlb234
    @nlb234 2 года назад

    1:56 POV you use mac :skull:

  • @vegaaltair8478
    @vegaaltair8478 2 года назад +1

    All the reason why I use password manager and I never ever saved my pass on browser ever since. Might not be 100% bulletproof ,but better than nothing

    • @vouchmeclips8537
      @vouchmeclips8537 2 года назад

      Google has better encryption than other web browsers. Huge variety of google is programmed from good and experienced programmers hence why it's a popular browser.

  • @Jackpkmn
    @Jackpkmn Год назад

    I like how you suggest not using browser password saving instead to use a paid service (haha get f'ed poors) to save it instead. Instead of say suggesting not downloading and running random unsolicited executables from the web.

  • @micmeister25ify
    @micmeister25ify 2 года назад +5

    Thank you every single knowledge you’ve shared to us!

  • @Amitseruta
    @Amitseruta 2 года назад

    As someone who has coded a undetectable malware which i have add over 10k from max from 1 person being $600. Now i just got my victim to use 1 file and boom, mine. Im not giving it away, its mine. I made it. So no one is getting it

  • @supercow99
    @supercow99 2 года назад

    yes i got the free game :D:D:D:D

  • @word20
    @word20 2 года назад

    There is one app that has one analyse on virus total recognized as malicious,
    that is GamesAppIntergrationService in windows 10.
    Is this a false positive? All other vendors recognize it as safe.
    It connects to Microsoft and to verizon business in US

  • @DogeisCut
    @DogeisCut 2 года назад

    I have over 300 passwords stored in my browser? How can I easily transfer them all to a password manager?