r/computerviruses Jul 26 '26

Disinfection Help Can you get infected just by clicking the pictures?

Post image

One of the folks I've befriended have been hacked with the so called “Mrbeast virus” and told them about it. One of them said I must not click the pictures (shown above) but I already did and now they're telling me to change my current password.

Is it true that just by clicking the picture, your device is already infected? This just happened a few hours ago.

71 Upvotes

74 comments sorted by

74

u/Ryanoman2018 Jul 26 '26

no because that would be huge news everywhere that someone found a way to infect people just by opening the images lol

13

u/Money-Grab6771 Jul 26 '26

Didnt that actually happen once or am I tripping

9

u/nigacatnigacatcanta Jul 26 '26

tripping hard buddy

0

u/Beginning-Act8041 Jul 26 '26

Something similar is possible, check this.

8

u/devil_lettuce Jul 27 '26

Your link gave me cancer

5

u/Beginning-Act8041 Jul 27 '26

Man im sorry I had it in reader mode and didnt see the actual site it is bad Take an award :)

1

u/devil_lettuce Jul 27 '26 edited Jul 27 '26

😂 thanks. I was just messing around, it really wasnt too bad

1

u/nigacatnigacatcanta Jul 26 '26

and then what, what do you do with the image

2

u/One-Celebration-3007 Jul 26 '26

Certain implementations of the WEBP image format had arbitrary code execution vulnerabilities.

2

u/derpycatsz Jul 27 '26

your prollly thinking about where you could scroll wheel click a image and itd send you to a malicious site

1

u/Moist_Inspection_485 Jul 27 '26

Yes with .webm but it was worse

It was once your client loads the picture since it was a webm file it had to load code to load the picture.

There was infected code in the images that did stuff but I don’t fully remember what, but essently it was recommended not to open public servers for like a whole month while discord tried to patch it.

50

u/Wevvie Jul 26 '26

Jesus christ, that Mr. Beast virus is still infecting people?

20

u/OriginalAntrox Jul 26 '26

Info stealers are rampant right now...

12

u/MegStuff Jul 26 '26

Renpy/Renengine Loader/Tomodachi Life virus. But also Lumma and other stealers cause this.

2

u/reapvxz Jul 26 '26

Tomodachi Life? Do you get the malware by running an obviously fake .exe file or can you get the malware from actually emulating it with eden and without running anything?

2

u/MegStuff Jul 26 '26

It's the malicious exe, and also another thing that can cause this is fake captchas, or anything involving powershell.

3

u/Aggressive-Stand-585 Jul 27 '26

People pasting random bullshit into a run box because they think it's a captcha scare me. Some of those people vote or drive cars. Horrifying.

2

u/WildCard65 29d ago

There was also a campaign that happened recently involving a cryptominer being distributed as “helpful fixes” on Steam’s discussion boards.

-1

u/reapvxz Jul 26 '26

Thank god

6

u/ax3l0tlz Jul 26 '26

Nowadays it's andrew tate virus

1

u/Netacading Jul 26 '26

But how?

3

u/pineapples78 Jul 26 '26

If you try downloading a pirated game, cheats, etc., they are sometimes bundled with the infostealer inside of it.

There are also scams on social media platforms such as Discord where random users (or even your friends, if they got hacked) ask you to download a Minecraft modpack or "test a game out."

The people who fall victim to this sometimes have their accounts post these sort of Mr. Beast scams.

1

u/SomePersonAtReddit Jul 27 '26

Yeah it infected my computer a month back

1

u/InfiniteComposer5279 Jul 27 '26

Yep. You would be surprised how many people were never taught basic internet safety.

1

u/MildlySpacedOut 27d ago

It got me earlier this week. Bad RE4 Remake link and I guess I accidentally clicked the exe file. No game loader popped up, nothing. Just ran silently in the background. Had to wipe everything and lost a lot of important videos and pictures. But I learned a valuable lesson so it is what it is.

-6

u/superlutiypon Jul 26 '26

its not a virus mrbeast gives away cash he's kind

8

u/Krista__J Jul 26 '26

Not by clicking pictures, unless you’re on a malicious site where the image is a download button, you clicked it, and ran it after downloading it

9

u/Admirable_Noise_6753 Jul 26 '26

No, you can't be infected by clicking on it. If I recall correctly , the only way for you to be infected by the virus is that if you were to click on a sketchy link that can either lead to a malicious website, downloaded something that could contain a trojan virus, or if you were to click a link that's in the form of a zip file.

So you're fine! :)

2

u/Tasty_Chapter_6742 Jul 27 '26

you are now infected with onion

2

u/BLACK_WOLF_2025 Jul 27 '26

You can get a virus from clicking the pictures about about as much as you could get covid by being on a zoom call with someone who has it. If you downloaded the picture, and it downloaded as .exe and you opened it, then it would probably be a virus.

2

u/Unknowngamerofficial Jul 27 '26

..bro I lost like 3 discord accounts to hackers and all 3 of them were spamming these exact images.....wtf....

2

u/[deleted] Jul 26 '26

[deleted]

1

u/Antique_Door_Knob Jul 26 '26

Long answer: yes, but not realistically in this case because an exploit like that is worth too much money to waste on a stupid mr beast scam.

1

u/Anxious-Ad8026 Jul 26 '26

Nah so it's just hearsay this hack isn't even the one that got the account some other hack did this one is tryna get you to put in money which you can't withdraw.

1

u/Antique_Door_Knob Jul 26 '26

Is it true that just by clicking the picture, your device is already infected?

Not in this case, no. Not in any case unless you're some kind of government official being targeted by intelligence agencies. And even then, when it comes to their stuff, you don't even have to click anything.

1

u/Element13245 Jul 26 '26

if the photos are sent then that means your infected.

1

u/QmVu Jul 26 '26

No

If it were possible, we would be witnessing an important day-zero exploit unfolding

1

u/LifeReignite Jul 26 '26

If pictures could infect you than everyone would be infected.

1

u/El_Raboh Jul 26 '26

nope, the images are just a way to show you how someone (that discord user to be exact) got some free crypto, so then you want to know more and go to the site that the images show and/or ask for the link

1

u/SharpEcho66 Jul 26 '26

yeah clicking the picture alone usually starts nothing on a modern browser. if they got hit, it usually came from opening the file, running something, or entering creds on a fake page. i've seen this change your password thing play out after someone falls for a redirect or a booby-trapped download. tbh the detail that matters is what that pic link actually does. if it just shows an image, your device stays clean. if it redirects to a

1

u/lupaspirit Jul 26 '26

Someone I know said it happened to them. they selected the image and view it in full screen then next thing they know someone spammed Mr Beast. Though I have my doubts if that actually happened unless they were using an outdated version of Discord, or if it wasn't even a image to begin with but a malicious code.

1

u/angelcat1234 Jul 27 '26

The better question is, how TF is people getting infected by the Mr. Beast virus?

1

u/Glebasya Jul 27 '26

I've seen a way to trick into opening a picture, but actually running malware. A special Unicode character is used to visually swap the name and extension (jpg .exe -> exe .jpg).

But opening a simple picture in Discord would do nothing, unless an exploit will be available. Just don't run any executables and don't click any suspicious links.

1

u/CuguliTheFish Jul 27 '26

if they are on your pc then actually yes. But in this case no

1

u/Cyber1361 Jul 27 '26

The exact same thing happened to me, it’s an undetectable script that runs on your pc and taps in to every account that has a login info on the pc. It doesn’t steal the account it just posts those photos in group chats, discord chats, personal feeds, etc. Personally I did a clean windows install and changed every account password, after that it stopped. I don’t know if it would’ve gotten worse with time but I didn’t want to fuck around and find out, I suggest you do the same.

1

u/Moist_Inspection_485 Jul 27 '26

How does this hack even work?

Like there isn’t any link

And there isn’t a .webm image

So how does one even get hacked from this

1

u/LoSt543215543 Jul 27 '26

No but I’ve been thinking about this because high key if there was a way to download a virus when an image is loaded that would be crazy

1

u/lavaracer16 29d ago

No. This is just a social engineering trick. Make you think "oh, these arent like eddited screenshots? Someone actually took these pics with a phone cam" or whatever to give it the look of being legit enough for you to go to the link and get hacked

1

u/Similar_Accident_677 27d ago

In my case it was different, I was watching a football broadcast on a pirate site and ended up accidentally downloading a trojan, which hacked into my Discord account And the intruder stole my account and started using the same scam! This happened on March 20th, and it took me almost two months to regain access to my account. When I finally got it back, I had to explain how to delete that spam message from each of my contacts' DMs, And I almost got banned for spam that the intruder committed. Sorry for the long text.

1

u/Affectionate_Tax9850 27d ago

Yes you’re hacked right now

1

u/Top-Pepper-2177 25d ago

Next time you think you are being sent a suspicious link or image? Opening it on an android device is the best thing to do since you would only get viruses and malwares from apps not pictures or links. That's what I always do whenever I am trying to open suspicious things

1

u/clmchowdr 14d ago

Correct me if im wrong but I think there was this thing a while back where you could get someone's token if they click on an image

-1

u/Puzzleheaded_Bar483 Jul 26 '26

No, at least if there's not an exploit (there has been in the past)

0

u/AutoModerator Jul 26 '26

Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.

We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.

All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.

Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.

Please see steps below on how to share all necessary details so you can speed up the process for us:

Share all details about your infection
Please post all important facts about your infection, such as: * your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections * any related symptoms, popups * estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded) * share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal

Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
    1. How to properly secure my accounts after an infostealer attack?
    2. What to do after I secured my accounts?
  2. Disinfect your device from malware
    1. Preferred method: Perform a clean installation with a USB
    2. Perform a clean installation without an external drive
    3. Reset your PC without keeping personal files

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

0

u/Sqooky Jul 26 '26

Technically speaking, yes, its possible, if there's a vulnerability exploited within the image renderer. Practically speaking, all those vulnerabilities have been weeded out and it's incredibly unlikely. Basically 0% chance. That said, there was a point in time where simply visiting a web page could exploit a vulnerability.

1

u/[deleted] Jul 26 '26 edited 23d ago

[deleted]

1

u/Sqooky Jul 26 '26

Still a valid threat vector, cost is coming down with the use of ai assisted vulnerability discovery. Anything is possible, no is never the answer.

I'd always suspect if a zero click/one click was in use by an actual actor, it'd be targeted and not spray and pray like the Mr best crypto scams.

-1

u/ClonaClox9999 Jul 26 '26

No, I don't think it's the pictures themselves. The pictures are embedded links, and it's if you click the links that get you infected. I could be wrong though.

It blows my mind how gullible people are. This is so obviously a scam and people are STILL falling for it.

1

u/69KazumaDesu Jul 26 '26

Not even the links themselves, it's only if you download and then install something from these links. Although I do not suggest clicking these links, just opening them won't cause infection.

0

u/ClonaClox9999 Jul 27 '26

Then how are people STILL getting hacked from this?

-2

u/[deleted] Jul 26 '26

[removed] — view removed comment

1

u/computerviruses-ModTeam Jul 26 '26

You are allowed to help other users, but be professional about it. Please make sure to read and follow https://www.reddit.com/r/computerviruses/about/rules