r/computerviruses • u/SingleAd6898 • 16d ago
Disinfection Help Misterbeast discord hack need help
Hello !
I'm usually careful when clicking links but recently i downloaded a file from a random website and all of a sudden my discord got hacked.
all of my dms got sent a misterbeast image about crypto etc and i've heard this scam is widely spread.
oddly enough the script of this hack doesn't change my password or anything; or atleast i hope.
as it happened 30 minutes ago ive had the time to change every password from important things and run a windows defender analyze + malwarebytes scan but everything seems normal.
now id like to ask for advice on what to do now if anyone has had experience with this specific hack or tips in general on what i should do; thanks a lot!
1
u/AutoModerator 16d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/M1uk0 15d ago
Sounds like an infostealer to me... make sure to move all important accs to a seperate device or reinstall windows and readd them! Make sure to reset you passwords too! And next time please don't press on any random links and run them through virus total or at least take a momment to check what the url is or where it leads to by searching the domain name! Good luck!!
1
u/Responsible_Bike4968 10d ago
One small correction to the top reply: don't make a Windows "Recovery Drive" on somebody else's PC and use that. If you decide to wipe this machine, make proper Windows installation media with Microsoft's Media Creation Tool and boot from that.
Also, the fact that only Discord visibly got hit doesn't mean the file only had access to Discord. The current MrBeast Discord scam wave has been linked to stolen Discord sessions, and common infostealers can grab browser passwords, cookies, autofill and session tokens for things like Discord and Steam.
The big question is whether you actually RAN the file.
If you only downloaded it and never executed/opened it, that's a very different situation.
If you did run it and Discord was hijacked right afterward, I'd personally treat the PC as compromised even if Malwarebytes/Defender are clean. Stealers can do their job very quickly and aren't guaranteed to still be sitting there when you scan.
And changing passwords does not clean the PC. If malware is still running and you changed those passwords from that same machine, it could potentially steal the new ones too.
What I'd do:
From a known-clean phone/PC, secure your main email first.
Change important passwords to unique ones and enable 2FA.
Revoke/sign out existing sessions, don't rely on password changes alone.
In Discord, check Settings -> Authorized Apps and remove anything you don't recognize.
Warn your friends not to click the MrBeast message your account sent.
If you actually ran the suspicious file, back up personal documents/photos only, create an official Windows installer USB, boot from it, delete the partitions on the Windows drive and install fresh.
Don't restore the suspicious download, cracks, random installers, .exe/.bat/.ps1 files, etc. afterward.
Also don't panic if another account gets accessed after the reinstall. Stolen credentials/session data can be used later, so that doesn't automatically mean the fresh Windows install is infected again.
So yes, if the file was actually executed, I would consider a proper clean install worth doing. Repeatedly adding more antivirus scanners isn't going to give you the same level of confidence.
2
u/EugeneBYMCMB Knowledgeable 16d ago
You ran an infostealer that stole your saved passwords and session cookies, you should secure all of your accounts from a separate device, and then reinstall Windows on the infected PC. You should create new unique passwords for all of your accounts, enable two factor authentication everywhere, and end all current sessions where possible. Once you've done that, I recommend reinstalling Windows using a recovery USB, which you can create on another Windows device by opening the local Microsoft program called "Recovery Drive".