Hi all,
I hope this is the right place to post this question - had a look around all the related subreddits and I didn't see any rules that say I can't post stuff like this here. Sorry if I am mistaken.
I would like some advice on a potential security issue I had awhile ago.
I created a new Google account when I reset my Android phone. I used Lastpass to create a random password but I didn't enable two factor authentication.
A few days later I was installing an app from my web browser on my desktop (As in, sending it to be installed on my phone from the Google play store web page on my desktop). And I saw that there was another option in my account for a device to send the app to, it was for a rockchip r13888 device and when I looked at the location of the login it was Malaysia. Obviously I thought this was a bit strange and enabled 2FA, changed my password, logged out of all other sessions etc.
I am just trying to figure out how this happened though, because like I said I registered the account on a brand new install of Android + at the same time I did reinstall windows too. I guess it's possible that I got a keylogger/trojan shortly after reinstalling Windows and that is how it happened but I barely had anything installed and nothing that I would deem particularly dodgy or risky.
Since then I have of course reinstalled Windows again, reset my phone again, changed my master passwords on my password manager, changed important account passwords but I am still a little bit confused and unsure of how this happened, so therefore I am not sure if I have fixed the issue or not.
There's a few possibilities I have thought of:
- Maybe I logged in on an emulator. I was doing some research on Android emulators, including cloud emulators but I don't remember ever actually using one, however maybe I did try one out and I forgot about it. I don't suppose anyone knows what device is shown when you log in on popular Android emulators? If it was a cloud one, this might explain the Malaysia address too. If it wasn't, I may have had my VPN on at the time. I don't usually connect to Malaysia but when I lose internet connection my client automatically tries different servers, so if that happened I may have been connected to a Malaysia VPN server without my knowledge.
- I just got unlucky and got a keylogger from some compromised app or from an exploit when browsing the web on a legitimate site.
- I did infact download something dodgy and I just forgot about it.
- I have a malicious program on my Android device or Windows PC that is persistent across reinstalls/resets (I don't think this is likely, right? But I think technically possible? Not sure though).
Does anyone else have any other ideas on what this could be? I googled the phone model but couldn't find much information about it. I just googled it again and there's no results but I think maybe I noted down the model number slightly wrong as there are models with similar names. It was definitely a rockchip.
Unfortunately I cannot check the model again as the information of the login seems to have been deleted from my Google account, unless I am looking in the wrong place.
Any help is really appreciated - and thanks for taking the time to read all this! I know it's quite a lot.
SOCIAL SHARE CARD GENERATOR