Share via

Hacked - bot installed Remote access Trogan

Cody Jordison 0 Reputation points
2026-02-26T03:32:11.1966667+00:00

Outlook account only accessed though my Samsung phone. No computer. No iPad.

Used a bot to guess my password.

Has deleted allll my emails.

I have changed my password , enabled 2 factor and recovered my account - HOWEVER - the R.A.T. is still active. Any incoming email immediately has the subject and body of email removed and replaced with a ransom note demanding I pay money. I have installed 2 anti virus detectors on my phone with no luck. The RAT is still hiding. Until its gone I'm afraid my account is gone.

Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sumit Shukla 0 Reputation points
    2026-02-26T06:12:42.2+00:00

    What you’re describing is almost always not a real RAT on your phone, but an email account takeover with a malicious inbox rule or forwarding rule inside your Microsoft Outlook account, attackers commonly create hidden rules that replace, delete, or rewrite incoming emails with ransom text; to fix it, sign in to Outlook on the web (browser) → Settings → Mail → Rules and delete anything suspicious, then check Forwarding, Sweep rules, Blocked/Allowed senders, and Connected apps / Sessions (sign out of all devices), disable POP/IMAP if not needed, remove unknown app passwords, verify your recovery email/phone were not changed, and keep 2FA enabled; on your Samsung/Android phone a true RAT is very unlikely unless you installed unknown APKs, but for safety update the OS, uninstall unknown apps, and if the problem persists after cleaning Outlook rules, back up your phone and perform a factory reset, once those hidden mail rules are removed, the ransom message behavior should stop immediately.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.