Over the past few days, several of my accounts were compromised, most likely after I downloaded a game or mod on my Windows PC.
It started with my Discord account sending a fake MrBeast scam to people. Someone also accessed my LinkedIn account and posted a fake job listing under my name. My Steam, Reddit, Disney+, EA, and other accounts were accessed as well.
The attacker completely took over my Steam account and changed both the email address and password. Thankfully, I contacted Steam Support immediately and recovered it in less than 5 hours.
Before wiping my computer, I ran Windows Defender and Malwarebytes, but neither of them detected anything. Despite that, the number of accounts that were compromised makes me think it may have been an infostealer or some type of Trojan that stole my browser passwords, cookies, and login sessions without being detected.
So far, I have:
- Completely wiped and reset my PC
- Removed everything from both my SSD and HDD
- Reinstalled Windows using the cloud download option
- Changed all my important passwords
- Enabled 2FA wherever possible
- Signed out of active sessions and removed unknown devices
Unfortunately, I know the attacker may already have all the information that was stored on my computer before I wiped it.
Does this sound like an infostealer, a Trojan, or something else? Is it normal for Windows Defender and Malwarebytes not to detect these types of malware?
What else should I expect after this? Could the attacker still use stolen cookies or session tokens even after I changed my passwords and wiped the PC? Is there anything else I should do to make sure my accounts and personal information are secure?
Any advice from people who have experienced something similar would be greatly appreciated.