How I Got Pwned: A Story of Steem-Stealing Malware

in #steem4 years ago

SO. I bought The Surge 2 a couple months ago. Great game. Action packed. Souls-like. In a word, awesome.

I waited on the edge of my seat for the Steam download to finish. I was so stoked to play this release. But because there is no God and life is more brutal than any of us could have possibly imagined, an error came up when I clicked that lovely blue “Play” button. Something about Vulcan something or other. I searched online for a solution and found basically nothing useful, just a couple of half-baked Reddit threads with no answers. There were, however, a couple of alleged fixes on YouTube.

Long story short, I followed the instructions in one of the videos, and promptly got the most gnarly malware I’ve gotten in years (probably since before I watched my adult videos on anything besides PornHub). My computer locked up, relentlessly opening and closing programs and web browsers, sending me on a game of computer virus Whack-a-Mole that lasted a few hours. Turns out I just needed to update my video card driver, and the whole thing was entirely avoidable. yay.

Almost a week after this debacle, I logged into Steem to see how things were going around here. I wasn’t really active here at the time, just logging in once a week or so to buy or sell SteemMonsters, read a couple of pos- wait, WTF?

I didn’t transfer that 552 STEEM to @blocktrades. I made a short, frustrated post and ragequit. The transfer occurred on the day that I tried to fix my game and got pwned. I still hadn’t put together the pieces of this puzzle - that the malware had stolen my STEEM via my browser, which evidently had my password saved.

pvt8ydgjlr.jpg

After taking that hit, I really just needed to walk away from this platform for awhile. 552 Steem isn’t all that much in the grand scheme of things, but it was enough to me feel like I had wasted a lot of time and energy.

That being said, I think it’s time for me to start posting here again. It’s good for me to be writing and presenting my creative outlets, and I’ve got some new projects in the works (new band, working in GameMaker Studio) to write about.

Don’t trust fixes for games on YouTube! Is the lesson of this post! See ya’ll soon 🔥

Photo sources:

https://wccftech.com/the-surge-2-inteview-e3-2018

https://www.aarp.org/money/scams-fraud/info-2017/how-to-protect-against-computer-viruses.html

Sort:  

It's bad and I feel for you - but I'm astonished that someone knew enough about Steem to realize that there might be something to steal.

Right?!? That was my first thought too. Who targets Steemians??

If this malware still has access to your computer would changing your keys do anything? I am guessing and hoping you already had your computer cleaned up with some good malware program.

Yeah, I cleaned her up, haven’t had problems since. I did change my keys, but you’re right that wouldn’t do any good if it just got to my acc thru my browser. Thanks for stopping by!

Thanks for using eSteem!
Your post has been voted as a part of eSteem encouragement program. Keep up the good work!
Dear reader, Install Android, iOS Mobile app or Windows, Mac, Linux Surfer app, if you haven't already!
Learn more: https://esteem.app
Join our discord: https://discord.me/esteem

Congratulations @k0wsk1! You have completed the following achievement on the Steem blockchain and have been rewarded with new badge(s) :

You published more than 350 posts. Your next target is to reach 400 posts.

You can view your badges on your Steem Board and compare to others on the Steem Ranking
If you no longer want to receive notifications, reply to this comment with the word STOP

To support your work, I also upvoted your post!

You can upvote this notification to help all Steem users. Learn how here!

Thanks a lot for the information. I've resteemed so that it reaches more people.

By the way, were you storing the Steem Keys directly in the Browser or were you using the KeyChain Extension developed by @yabapmatt?

Thanks so much!! Apparently I had my Steem keys in the browser, I do know about KeyChain though. I’ll be switching to KeyChain from now on, seems more secure

Sorry to hear - 552 STEEM is a lot to lose. Glad to see you found the motivation to come back.

Posted using Partiko iOS

Thanks, excited to be back!

So sorry to hear of this. Glad you have put much of the anger aside.

Good to see you’re still here, @practicalthought ❤️

Appreciate the warning, thanks.

No problem!

😔 😔 😔 @w0wsk1 I feel so sorry for you... Maybe one really should check frequently if a power down has started. steemworld.org always tells you - and steempeak.com shows a (unwanted) power down in the wallet and in that case - changing the keys on another device...
But I know - it doesn't help you now... @peekbit

Yeah, now I guess I know for the future! Thanks for stopping by!

Hey there! Your post was manually curated by the @ocd and @ocdb team!

We invite you to be part of our community, we believe this post will interest you.

tysm ❤️❤️❤️

Hi, @k0wsk1!

You just got a 11.05% upvote from SteemPlus!
To get higher upvotes, earn more SteemPlus Points (SPP). On your Steemit wallet, check your SPP balance and click on "How to earn SPP?" to find out all the ways to earn.
If you're not using SteemPlus yet, please check our last posts in here to see the many ways in which SteemPlus can improve your Steem experience on Steemit and Busy.

Hi @k0wsk1!

Your post was upvoted by @steem-ua, new Steem dApp, using UserAuthority for algorithmic post curation!
Your UA account score is currently 3.907 which ranks you at #4486 across all Steem accounts.
Your rank has not changed in the last three days.

In our last Algorithmic Curation Round, consisting of 110 contributions, your post is ranked at #21.

Evaluation of your UA score:
  • You're on the right track, try to gather more followers.
  • The readers appreciate your great work!
  • Good user engagement!

Feel free to join our @steem-ua Discord server

Ahhhh that’s awful man... did you change your passwords and confirm the computer and account is safe?

That’s the first time I’ve heard of hackers taking steem from YouTube, I guess the crypto hackers know what they are doing