Jump to content

Account Hijacked. First time


Recommended Posts

Posted (edited)

EDIT

I can confirm, I downloaded a bad version of Runelite.

 

Nothing worse then logging into your osrs account and getting that error that its already logged in. Changed the password and logged in and my account was cleaned out.....

How does this happen? Password was not used on other accounts, My pc is clean... Took a dive into google about leaked databases from runescape?

 

Anyone have idea? Or has it happened to others?

Edited by SnapOn
Posted
3 minutes ago, AnimalMother said:

Which clients you have used in the past incl. steam? you have 2 factor auth for the osrs account?

Recently have been using runelite for the quest helper plugin. (Downloaded the client from the right source.)

I did not have the two factor auth enabled. (thats my bad i guess)

I made sure all accounts were un linked as of now also..

Just sucks...

Posted
18 minutes ago, SnapOn said:

Recently have been using runelite for the quest helper plugin. (Downloaded the client from the right source.)

I did not have the two factor auth enabled. (thats my bad i guess)

I made sure all accounts were un linked as of now also..

Just sucks...

RL is completely safe with all it's plugins, IF you downloaded it from the correct source which you said you did.
Two-factor auth + bank pin is a must imo, now you learned it the hard way...

Maybe you used any other services in the past? Tried other bot clients? Downloaded anything remotely shady in connection to osrs/RS?

Would still maybe make sure ur computer is clean...

  • Like 1
Posted
12 hours ago, SnapOn said:

Nothing worse then logging into your osrs account and getting that error that its already logged in. Changed the password and logged in and my account was cleaned out.....

How does this happen? Password was not used on other accounts, My pc is clean... Took a dive into google about leaked databases from runescape?

 

Anyone have idea? Or has it happened to others?

99% of the time it's leaked databases nowadays..
That's why you can't go without 2FA these days :/

  • Like 1
Posted (edited)

tbh.. i have good knowledge in this field.

feel free to pm me anytime.

to do :

1# change all your passwords from a clean device/pc. 

its obvious why...its highly likely to have a keylogger, pwd grabber installed into ur pc by now. and you dont want to get hijacked again.

2# disbale all 2nd auth, and re-enable it again.

since they have access to ur pc, they can copy ur current cash files, and use them again to bypass 2nd auth, on any other pc.

3# if you cant locate the malware, i suggest you do full re-installation of ur windows. (not a re-pair mode)

since the malware can be hidden in many many places, even in file-less form, it will recover itself if the coder is smart enough.

common places to check in (startup/task scheduler/drivers...basically its a mess) :/

 

ps, id be glad if you give me a sample :D

 

 

edit:

it doesn't have to be a bad version, it could just be a bad plug-in. which could trigger the malware code by time or event...etc.

Edited by iz0n

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...