Removing spyware that screenshots banking sessions
Spyware that captures a screenshot whenever you open a banking website is a serious privacy and financial-security threat. It may record account balances, payment details, security codes, email notifications, or anything visible on the screen, even when it cannot directly read encrypted traffic.
Australian users should treat this as an active compromise rather than an ordinary browser problem. Whether you bank through an app in Sydney, use online banking from a home office in Melbourne, or manage bills over an NBN connection in Brisbane, stop using the affected device for financial activity until it has been checked and secured.
Signs of screenshot spyware
The malware may run quietly as a background process, scheduled task, startup entry, browser extension, or seemingly legitimate support tool. Possible symptoms include unexplained CPU or disk activity, sudden storage growth, fan noise, delayed screenshots, unfamiliar programs, and security alerts that return after removal.
A browser can appear normal while spyware operates outside it. Look for unusual permissions involving screen capture, accessibility, remote control, or startup execution. On Windows, inspect Task Manager, installed applications, startup items, and scheduled tasks. On macOS, review Login Items, Privacy & Security permissions, Screen Recording access, and unfamiliar profiles.
Unexpected banking prompts can provide another clue. A fake update, cloned login page, or browser redirection may be used to install the surveillance tool. If your searches or banking sessions are redirected, review the guidance in the browser hijacker category as part of the investigation.
Isolate the device before changing passwords
Disconnect the computer from Wi-Fi or Ethernet, but avoid deleting suspicious files immediately. Isolation prevents the spyware from sending newly captured images and can preserve useful evidence for a technician, your bank, or law enforcement. Do not log in to banking, email, cryptocurrency services, or government portals from the compromised system.
Use a different, trusted device—such as a clean phone or another computer—to contact your bank. Australian banks commonly provide 24-hour fraud support, and you should ask whether online banking access, cards, payees, or recent transfers need to be frozen. Report suspicious activity through your bank’s official app or website, not through a phone number shown in a pop-up.
Change passwords from the clean device, beginning with email and banking accounts. Use unique passphrases, enable multi-factor authentication, revoke unknown sessions, and replace recovery details that may have been altered. Where available, prefer an authenticator app or hardware security key over SMS, because intercepted messages and number-porting fraud can weaken text-based verification.
Remove the surveillance software safely
Start with a reputable, fully updated security product and perform a full scan. Windows users should also run Microsoft Defender Offline when a threat may hide from normal operation. On a Mac, remove unknown applications and profiles, check Screen Recording and Accessibility permissions, and install system updates from Apple rather than from pop-ups.
If the malware blocks security tools, reboot into Windows Safe Mode with Networking only when a trusted guide specifically requires it. Safe Mode can prevent some startup components from loading, making removal easier. Never follow instructions from an unknown caller who asks for remote access, gift cards, cryptocurrency, or payment to “unlock” your bank account.
After the scan, inspect browser extensions and reset the affected browser if necessary. Remove extensions you did not install, clear stored website data, and check the homepage and search engine. Do not restore extensions or applications from an old backup until they have been checked individually.
Check for stolen data and related threats
Assume that screenshots may have exposed more than banking information. Review email, cloud storage, tax records, Medicare details, identity documents, and saved passwords. In Australia, report suspected identity misuse to IDCARE and follow advice from Scamwatch or the Australian Cyber Security Centre. If money has moved, preserve transaction records and report the incident to your bank and ReportCyber where appropriate.
Keep the compromised device available if an employer, bank, insurer, or forensic specialist needs evidence. Record dates, alerts, unfamiliar programs, bank notifications, and the actions already taken. Avoid repeatedly reinstalling software or using “registry cleaner” utilities, which can destroy evidence without removing the infection.
If the incident also involved file encryption or extortion, separate recovery planning from spyware removal. Guidance on recovering deleted files explains why backups, file history, shadow copies, and forensic recovery should be assessed carefully rather than relying on random decryptor downloads.
Rebuild trust and prevent another compromise
A clean installation may be the safest option when spyware had administrator access, disabled security controls, or continued returning after removal. Back up personal documents first, scan the backup from a separate clean system, and reinstall Windows or macOS using official media. Restore data selectively, not complete system images that may contain the original malware.
Australian households often share laptops for bills, schoolwork, and streaming, so create separate user accounts and avoid daily administrator use. Keep browsers, operating systems, banking apps, routers, and password managers updated. Be cautious with emailed invoices, parcel messages, fake Australian Post notices, and urgent calls pretending to be from a bank or the ATO.
Use these checks after cleanup:
- Confirm that Screen Recording, Accessibility, and remote-control permissions contain no unknown entries.
- Review bank statements, scheduled payments, new payees, and card transactions.
- Check email forwarding rules, recovery addresses, and active sign-in sessions.
- Remove unrecognised browser extensions, startup items, and scheduled tasks.
Strengthen everyday protection with these habits:
- Download software only from official vendors or trusted app stores.
- Keep offline or versioned backups disconnected from the computer.
- Use a password manager with separate credentials for every important service.
- Treat unexpected security pop-ups and remote-support requests as suspicious.
| Area |
What to verify |
Safer response |
| Device |
Unknown processes, apps, profiles, or permissions |
Isolate, scan, and consider a clean reinstall |
| Banking |
New payees, transfers, login alerts, or changed limits |
Call the bank through an official channel |
| Accounts |
Password resets, forwarding rules, and active sessions |
Change credentials from a clean device |
| Recovery |
Backups and exported files |
Scan them before restoring |
| Reporting |
Identity misuse or financial loss |
Contact the bank, IDCARE, Scamwatch, or ReportCyber |
For a related ransomware incident, specialist guidance on LockBit file recovery can help distinguish legitimate recovery options from dangerous tools. Keep monitoring accounts for several weeks, because stolen screenshots may be used later in targeted scams or impersonation attempts.