A PSA for the Tumblr Pokémon community
(And anyone else who happens to see this.)
Hello there. You know me as firewcll, Taiyo-mun, Sam, or just by my screen name of Astrion. My Discord got hacked a few nights ago, the threat actor having tricked me after they hijacked a Discord account of someone I trusted in cybersecurity. Ironic as this is, this is an important takeaway. Even someone trained in cybersecurity can be hacked if the hacker presents the right narrative. I spectacularly ignored all the red flags and paid the price. I don’t want the same to happen to anyone else.
Based on what I’ve deduced from this individual’s actions, they’re an amateur hacker tricking people into downloading their game (for me, it was called ‘Cyberkia’). This ‘game’ is actually malware, in the form of a keylogger that will boot you out of Discord and force you to relog manually, all while reading your keystrokes. They hijacked my account, and began using it to troll people, spread their virus, destroy servers I was in or in charge of, and generally sow chaos. I’m not sure if they’re after credit card information too, but don’t take any chances.
If you have, in the past, added Astrion#4262 or #6773, that account is now known as ‘FadeD’. As edgy as their name is, they are sadly a rather dangerous threat actor who will gladly phish and snatch your account from you. People that have interacted with me will likely know that it isn’t me, though this is an extra layer of precaution.
If you see this account, report it hacked to Discord (so they can hopefully get back to me about it sooner), and Do Not Respond. If they did get you and you’re just now seeing this, Do NOT Log Back In To Discord. Do not type anything sensitive on your keyboard. Disconnect your WiFi or ethernet cable, backup your files, and perform a hard, clean reinstall of Windows. I was hasty and did not back up my files before I did this, out of fear they were infected, and lost quite a bit of data. Once you’re done with this, to be sure, change all of your passwords from a secure device (I did so with my phone). I recommend using https://passwordsgenerator.net/ to make them.
Fun fact: Even with the best tools, it’ll take a black hat hacker mathematically the lifespan of the universe to crack a 16 character password consisting of numbers, letters of both capital and not flavors, and special characters. Do this for everything important, especially if they shared a password with your Discord (something you shan’t do in the future).
I’m going to be hyper-paranoid about how I go about Discord now. If you would like, I can provide my Discord again in private, but know that I will no longer accept any file from someone I have not known for a while (and even then, I’ll still probably open your file in a virtual machine).
Please remain safe. And if it’s all the same, if this FadeD person has not blocked you yet, you’re more than welcome to troll them however you see fit. Just don’t break the law or anything, I don’t want you getting in trouble too.
Happy roleplaying. I don’t use Tumblr for roleplay anymore, but I may return someday if enough people want me to.














