This week I got a message from someone I know. I’m sharing it anonymously, because the story is one of the most common ones I see — and it’s probably relevant to more than a few people.
The short version: he downloaded something he shouldn’t have. One day someone broke into his Instagram and Discord, posted all kinds of things, and the platforms didn’t even flag a login from an unfamiliar place. He reinstalled Windows — everything looked fine. A couple of days later, comments started appearing on TikTok under his name, “like from some bot.” He changed his passwords. He turned on two-factor authentication. And yet the feeling that “something is still hanging over me” never went away. No alerts. No “new device signed in.” As if it was all simply happening through him.
And here’s the key point I want people to understand:
This is not a simple password leak. This is an infostealer.
This kind of malware doesn’t just steal passwords. It also steals your login “keys” — session tokens and cookies — straight from the browser. And with those, the attacker doesn’t need your password at all. They simply reuse your already-open, already-authenticated session.
That’s exactly why the victim feels stuck:
- The platform sees the activity as “you,” so it shows no foreign login.
- There are no warning notifications.
- 2FA isn’t requested — the session was authenticated earlier.
- And changing the password often does NOT kill the already-open sessions, if it’s done the wrong way.
The person does everything the internet tells them to do — change the password, add 2FA — and can’t understand why it doesn’t help. It doesn’t help because they’re solving the wrong problem.
What you actually need to do (and in this exact order):
- Do everything from a CLEAN device. Not the one that was infected.
- If you reinstalled Windows — good. But don’t import old saved passwords and don’t restore your browser profile “from the cloud.” That’s how you bring the infection back.
- Start with your primary email — it’s the “master key” account. Change the password, enable 2FA, and check that no one added mail-forwarding rules or changed your recovery phone/email.
- For each account separately (Instagram, Discord, TikTok, Google, etc.):
- change the password,
- click “Log out of all devices / all sessions” — this is the single most important step, it revokes the stolen keys,
- enable 2FA via an authenticator app, not SMS,
- review “Connected apps” and remove anything unfamiliar.
- Treat every password saved in the browser as stolen. Wherever it was reused — change it everywhere.
Two questions I always get:
“So which antivirus should I buy?” — You don’t need to buy anything expensive. For a clean, updated Windows, the built-in Microsoft Defender is enough, and for a one-time scan, the free version of Malwarebytes works fine. Money spent on a “premium” antivirus won’t solve this particular problem — revoking the sessions will.
“Why isn’t SMS 2FA good enough?” — SMS can be intercepted, and your number can be stolen via a SIM swap (the attacker moves your number onto their own SIM). An authenticator app generates the code on the device itself, offline — so there’s nothing left to intercept.
The bottom line: if it feels like “something is hanging over you” and changing your password doesn’t help — the problem probably isn’t the password. It’s the open sessions. You have to close them.
Stay safe. And if you know someone this is happening to right now — pass it on. It can save them a lot of grief.
#cybersecurity #infosec #infostealer #accountsecurity #digitalforensics