Introduction
Many people I know have gotten their ROBLOX accounts hacked and I thought maybe I should release a guide on the different methods of account hacking including: Phishing Links, Malware and Cookie Logging.
So I made this guide with non tech savvy people in mind as many users who get their accounts hacked are not tech savvy and don’t know about things like Cookie Logging, Process Injection etc
Cookie Logging
@VoidedBlades has a great resource on cookie logging and how to avoid it here:
Cookie logging explained - Resources / Community Resources - DevForum | Roblox
But ill provide a brief description. Roblox stores your account login in a browser cookie which is a small file stored within your browser and cookie logging is where a website or program tries to take that cookie which if used in another browser, the attacker could have access to your account.
HAR Files
HAR files, or “ H ttp AR chive files”, contain an archive of site cookies, including your account’s .ROBLOSECURITY
id. Hackers can use that gain control of your account without a username & password pair. To avoid this, remember to refresh your session (logging out & in) every once in a while.
Phishing Links
Most of us know that free robux generators are scams but there are some people who dont and they are more commonly being advertised on trusted platforms like Youtube.
Example here
A general rule of thumb for things like this is: If it is too good to be true, then it probably isn’t and never give away your password to any of your accounts no matter what the website or app says
Malware
A lot of accounts get hacked because of malware, files specifically made to do malicious things to your computer including cookie logging, keylogging and even stealing passwords from your browsers saved password database.
Many of these programs are disguised as other types of programs like on a Discord server of mine someone posted a file claiming to be a Roblox FPS Booster but was a file that stole the saved password to Roblox.
To avoid these I recommend using an Anti Virus(Windows defender works just make sure you have it set up properly) and avoid software like McAfee and Norton as they are more bloatware than anti viruses. I recommend using something like Malwarebytes to scan ANY FILE you download from sources like Discord, Twitter, Instagram reddit etc. If you don’t know how to scan a file just right click the downloaded file and click scan. Even better don’t download ANY files from these sources.
SIM Swapping
SIM Swapping is when someone gets information about you from phishing emails or by using social engineering. They then contact the victims phone company asking them to change the victims phone number over to their phone using the data they have on the victim to make it seem authentic. Once this is done the victim loses the connection to the cellular network and the fraudster now has the victims phone number.
No you may be thinking what does this have to do with roblox? Well if a user has 2FA on their account linked to their phone, the fraudster now can get access to that account.
So I hope that this resource helps you stay safe in the future and please share this with people you know who might be high at risk of getting their account hacked(ie small children). I know this wasn’t very in-depth but it wasn’t meant to be, it was meant for the average joe someone who doesn’t know much about cybersecurity or computers at all.