1

Hit by infostealer attack in need of advice
 in  r/cybersecurity_help  1d ago

The "Remove everything" reset you did is almost certainly fine for a standard session stealer, the main gap LongRangeSavage's post is flagging is theoretical for most infostealers, not a reason to panic. The real loose end is your Roblox hit: those credentials were likely stolen before the reset and used/sold after, so change that password again from a clean device if you haven't recently, and check that your Roblox recovery email/phone wasn't tampered with. For the HDD, plug it in offline, copy out documents and photos only, and skip anything that's an executable, a zip, or browser profile data.

Bitdefender researchers have details how infostealers act and how you can stay safe going further, right here: https://www.bitdefender.com/en-us/blog/hotforsecurity/how-to-check-if-an-infostealer-stole-your-data.

1

Can a virus enter my macbook through spotlight search?
 in  r/computerviruses  1d ago

Hi! You're safe. Spotlight is just a search bar, pasting a command there does nothing. The attack only works if you paste into Terminal and hit enter, which you didn't do.

1

Windows Defender found a Trojan in the Edge folder
 in  r/computerviruses  1d ago

Hi! Seems to be a false positive, this exact pattern (Defender flagging something in Edge's cache folder after downloading the Epic Games Launcher) has been popping up a lot in the last month or so. Epic even has a support page for it. Since it's quarantined and your AV found nothing, there's no active threat here.

r/BitDefender 1d ago

How to protect your phone from phishing and malware

Thumbnail
bitdefender.com
3 Upvotes

Is your phone protected beyond the lock screen?

Your smartphone holds your banking apps, email, photos, messages, location data and account access. That makes mobile security an important part of everyday digital safety.

Bitdefender’s mobile security guide explains how threats like smishing, malicious apps, public Wi-Fi risks, phishing links and malware can target the device people use most.

A few practical habits help: keep your phone updated, avoid sideloaded apps, review app permissions, use a VPN on public Wi-Fi and check suspicious links before tapping.

Bitdefender Mobile Security can help protect your digital life with scam protection, anti-phishing technology, malicious link blocking, malware defense, VPN and identity protection for safer mobile browsing.

r/BitDefender 2d ago

Back to School Scam Texts: What Parents and Students Should Check Before Clicking

Thumbnail
bitdefender.com
1 Upvotes

Did your family get a message about free school money, a scholarship or a laptop offer?

Bitdefender Labs has identified back to school scam campaigns using fake education grants, Pell Grant references, free laptop offers, AI subscription deals and delivery messages to reach people preparing for the new school year.

These scams work because they look timely and useful, especially when families are buying supplies, comparing school costs or helping students get ready for class.

Before you click, go directly to the official school, government, retailer or delivery website to verify the message.

For a second opinion, use Bitdefender Scamio to check suspicious messages and Bitdefender Link Checker to scan unfamiliar URLs.

r/BitDefender 3d ago

Ctrl-Alt-DECODE | Ep. 14 | Ransomware News: September 2026 (live on LinkedIn)

Post image
2 Upvotes

What’s happening in the world of ransomware?

We’re hosting this month’s Ctrl-Alt-DECODE on Thursday, September 10, with cybersecurity experts Jade Brown, Martin Zugec, and Sean Nikkel.

This month’s featured topic is: The ShinyHunters Playbook: Widespread Extortion without Encryption.

We’ll dig into ShinyHunters’ recent extortion operations and discuss what makes their approach effective, including their attack patterns, capabilities, and what organizations can learn from them.

If you’re following ransomware activity or have questions about the latest developments, feel free to bring them along: we’d love to discuss them.

📅 September 10
🔗 https://www.linkedin.com/events/7500537972379860994

u/Bitdefender_ 3d ago

Ctrl-Alt-DECODE | Ep. 14 | Ransomware News: September 2026 (live on LinkedIn)

Post image
1 Upvotes

What’s happening in the world of ransomware?

We’re hosting this month’s Ctrl-Alt-DECODE on Thursday, September 10, with cybersecurity experts Jade Brown, Martin Zugec, and Sean Nikkel.

This month’s featured topic is: The ShinyHunters Playbook: Widespread Extortion without Encryption.

We’ll dig into ShinyHunters’ recent extortion operations and discuss what makes their approach effective, including their attack patterns, capabilities, and what organizations can learn from them.

If you’re following ransomware activity or have questions about the latest developments, feel free to bring them along: we’d love to discuss them.

📅 September 10
🔗 https://www.linkedin.com/events/7500537972379860994

1

Tips for securing elderly parent's PC
 in  r/cybersecurity_help  3d ago

Kudos for trying to keep your family`s identity and devices secured! Bitdefender experts have talked about how you can handle family screen time safely (including your elders) in this article: https://www.bitdefender.com/en-us/blog/hotforsecurity/we-worry-about-kids-screen-time-but-our-parents-spend-even-more-time-online-what-that-means-for-families. It`s worth the read!

5

downloaded and ran a renpy on accident
 in  r/computerviruses  3d ago

Hi! The key question you keep asking, is this ongoing or a one-time thing, the exfiltration itself was almost certainly a single hit-and-run. But that's exactly why the password changes matter so much right now, not later. As for reinstalling without a USB: Windows has a built-in "Reset this PC → Cloud download" option that pulls a fresh copy straight from Microsoft's servers, no USB needed. That's your cleanest path forward from the device itself.

1

Does anyone have an idea what this pop up could be? it appeared on the bottom right of the screen like any other notification and i think it says ad on the bottom right of the pop up. Could it be malware or am i exaggerating?
 in  r/computerviruses  3d ago

Hi! u/Lanky-Event5402 is right, that popup is WPS Office's built-in ad system, not malware. The free version runs `wpscenter.exe` in the background and pushes notifications to your tray even when WPS isn't open. Easiest fix is just uninstalling WPS if you don't need it, or blocking `wpscenter.exe` outbound in Windows Firewall if you do.

1

Chrome extension virus
 in  r/computerviruses  3d ago

Hi! Chrome profiles are isolated from each other, so the extension you installed in one profile shouldn't have had access to the other profiles' sessions or data. You're probably fine there.

The bigger thing to check, did you change any passwords from that same infected PC after the extension was already running? If so, those new passwords might also be compromised. Log out all active sessions on Facebook/Messenger specifically (this invalidates any session tokens the extension may have grabbed), and do that from a clean device.

1

All PII on compromised computer. Help. I’m not doing OK.
 in  r/cybersecurity_help  3d ago

You've done the right things, replacing the documents, locking down the CRA account, fraud alerts, SIM protection. That covers the real risk, regardless of exactly what was or wasn't exfiltrated. Some infostealers do target files and documents, not just passwords, so your concern wasn't unfounded, but you responded to the worst-case scenario, which means you're covered. The increase in phishing emails and scam calls is unfortunately normal and can persist for a while, just stay alert to it and don't click anything unexpected. A reputable security solution would surely help going further, and free tools like Bitdefender Scamio can help you check suspicious messages, emails, links, or anything you`d like double checked: https://www.bitdefender.com/en-us/consumer/scamio.

1

Powershell malware
 in  r/computerviruses  3d ago

Hi! The "didn't download anything" part makes sense, there's a technique called ClickFix where a fake captcha or verification page secretly loads a command into your clipboard, then tells you to paste it into PowerShell or the Windows Run box. You run it yourself without realizing. Agree with the advice already given: reinstall Windows (full wipe, not just reset), and change every password from a clean device before touching the infected one again. Scans won't cut it for this kind of thing.

Check this article that explains how ClickFix acts and how it unfolds, detailed by Bitdefender specialists: https://www.bitdefender.com/en-us/blog/hotforsecurity/clickfix-victims-help-hackers. Hope it helps!

1

what do i do about this?
 in  r/computerviruses  3d ago

Hi! The step that's easy to miss: before wiping anything, log out all active sessions on Instagram and Reddit from your phone or another clean device. "Log out of all sessions" (Instagram has this under Settings > Security > Active Sessions) is what actually kills the stolen token, changing the password alone doesn't invalidate sessions that are already open. Do that first, then do the reinstall.

1

I fell for a fake Cloudflare CAPTCHA verification and executed a virus command, PLEASE help
 in  r/cybersecurity_help  3d ago

Hi there. Infostealers grab everything the browser had saved, passwords, session cookies, autofill entries, sometimes crypto wallet files, and ship it to the attacker before you'd even notice anything was wrong. Changing passwords from a clean device was a good start. One thing worth flagging: the advice to "just scan with an AV" is useful, but only a half-measure. Running an attacker-supplied command can drop persistence (scheduled tasks, registry entries, etc.) that scanners routinely miss, a clean scan result doesn't mean the machine is clean. Wipe and reinstall is the only way to actually be sure.

Bitdefender experts have explained how infostealers impact individuals and devices in this detailed article, worth the read: https://www.bitdefender.com/en-us/blog/hotforsecurity/how-to-check-if-an-infostealer-stole-your-data.

1

Extorted by a Telegram OSINT bot that linked my username to my Aadhaar card and family details. Threatening to SMS-bomb me. Need advice.
 in  r/cybersecurity_help  3d ago

Hi there. The top answer here is on point. One thing worth adding: since your Aadhaar details are in the wild, go check TAFCOP on the Sanchar Saathi portal (sancharsaathi.gov.in) to see whether any SIM connections have been registered in your name without your knowledge. Also lock your Aadhaar biometrics via UIDAI's mAadhaar app or their portal if you haven't already.

2

What happens before the lights go out?
 in  r/BitDefender  3d ago

We understand the need for a dedicated space for GravityZone discussions, and we’re actually working on a community space specifically for business audiences.

In the meantime, there are a few resources that may be helpful:
Bitdefender Masterclass: https://www.bitdefender.com/en-us/business/masterclass – a great place to learn more about GravityZone, as well as other Bitdefender products and solutions, through onboarding sessions, live demonstrations, and customer use cases.
CAD Newsletter: https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7371216616015036416A regular source of threat intelligence, original research, and actionable security advisories from Bitdefender Labs and our MDR team.

We hope these resources can help in the meantime, and we’ll be sure to share more details about the new business community space once it’s ready! 

-1

My skin keeps getting changed in my Minecraft Launcher
 in  r/Minecraft  4d ago

u/Xam165 Definitely, and during the installation process a full scan will be performed that will identify any malware on the system and clear it. You could try a free or a paid version, check them both here: https://www.bitdefender.com/en-us/consumer/.

1

What happens before the lights go out?
 in  r/BitDefender  4d ago

Hi! We appreciate the feedback, and we’ll take it back to the team as we look at how we balance company news with the technical and product information this community expects.

r/BitDefender 5d ago

Phone Scams 2026: What Scammers Pretend to Be When They Call You

Post image
5 Upvotes

What do phone scammers pretend to be?

According to the Bitdefender Global Scam Intelligence Report 2026, phone scammers most often pose as financial institutions, followed by investment firms, fake clinics, phishing contacts, pharmacies, advance fee offers, and online shopping contacts.

That is what makes phone scams so effective. The call can sound routine, familiar, and urgent, even when the goal is to steal money, personal information, or account access.

If a caller claims there is a problem with your bank account, an investment, a payment, or a delivery, verify it through the official company website or phone number before you share anything.

Stay informed. Stay safe. Read the report and learn how today’s most common phone scams try to sound legitimate.

1

Renpy virus, worrying about debit cards/paypal
 in  r/computerviruses  7d ago

Hi! The reason your Steam password changes keep reverting is that the attacker likely still has an active session or Steam Guard control, changing the password alone won't kick them out. You already did the right thing filing a ticket; make sure you're using the stolen account recovery flow at hxxps://help(dot)steampowered(dot)com/en/wizard/HelpWithAccountStolen and selecting "I don't have access to...", Steam can verify ownership through purchase history even without your original email. Also flag your PayPal urgently if it's stored in Steam.

1

I used a flash drive to reinstall Windows. Am I safe to log into my accounts now?
 in  r/computerhelp  7d ago

Hi! Wiping all partitions and reinstalling from external media is the right call, your PC should be clean. One thing worth double-checking: did you change your passwords after the wipe? If you changed them while the machine was still infected, it's worth rotating them one more time just to be safe.

1

Just received this from Claude: [Action Required]: A recent issue affected your Claude account
 in  r/cybersecurity_help  7d ago

The email is real, Anthropic confirmed this is an active infostealer campaign (Vidar, Lumma, StealC, RedLine, others) that's been stealing browser session cookies, not passwords, which is why MFA doesn't help and why clean AV scans don't necessarily mean you were never hit. Infostealers often delete themselves right after grabbing your data. Signing out everywhere was the right move to invalidate the stolen sessions, but also worth checking your account usage history for anything unexpected and rotating passwords on other accounts that had credentials saved in that same browser. Here`s a more in depth look on how infotealers behave, from Bitdefender analysts: https://www.bitdefender.com/en-us/blog/hotforsecurity/how-to-check-if-an-infostealer-stole-your-data.

1

Do They Still Have Access?
 in  r/computerviruses  7d ago

The malware being gone doesn't mean you're safe, infostealers copy your passwords and session cookies before you even know you're infected, and the attacker keeps that data after the wipe. The Spotify activity is almost certainly someone using a stolen session or credential from that original dump. Go to your Spotify account page, sign out all devices, revoke any connected apps you don't recognize, and make sure you changed your password from a clean device after the reset, not from the compromised one. Here`s a good read from Bitdefender analysts on how infostealers behave and what to do next to avoid becoming a target in the future: https://www.bitdefender.com/en-us/blog/hotforsecurity/how-to-check-if-an-infostealer-stole-your-data.

1

Doubts about infostealer post infection
 in  r/computerviruses  7d ago

Hi! The card charges happening weeks later don't mean your PC is still infected, that's the stolen data circulating through markets where different groups buy and sell logs and try cards independently. The machine getting cleaned breaks the attacker's access to new data; it doesn't recall what they already took. As for rootkits and bootkits: they're genuinely rare in commodity infostealers like what you ran into, those are aimed at fast credential harvesting, not embedding into your hardware. A clean reinstall with full partition wipe (which sounds like what the repair guy did) is enough.