I recived a very disturbing spam mail...

I recived a very disturbing spam mail...

Postby themightyglider » 19 Nov 2018, 21:57

Hi everyone,

this morning I found a very disturbing spam mail on my email account at tuxfamily.org:

Hello! I have bad news for you. 19/07/2018 - on this day I hacked your operating system and got full access to your account contact@rogueboxadventures.tuxfamily.org It is useless to change the password, my malware intercepts it every time. How it was: In the software of the router to which you were connected that day, there was a vulnerability. I first hacked this router and placed my malicious code on it. When you entered in the Internet, my trojan was installed on the operating system of your device. After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts). A month ago, I wanted to lock your device and ask for a small amount of money to unlock. But I looked at the sites that you regularly visit, and came to the big delight of your favorite resources. I'm talking about sites for adults. I want to say - you are a big, big pervert. You have unbridled fantasy!!! After that, an idea came to my mind. I made a screenshot of the intimate website where you have fun (you know what it is about, right?). After that, I made a screenshot of your joys (using the camera of your device) and joined all together. It turned out beautifully, do not doubt. I am strongly belive that you would not like to show these pictures to your relatives, friends or colleagues. I think $706 is a very small amount for my silence. Besides, I spent a lot of time on you! I accept money only in Bitcoins. My BTC wallet: 1H9bS7Zb6LEANLkM8yiF8EsoGEtMEeLFvC You do not know how to replenish a Bitcoin wallet? In any search engine write "how to send money to btc wallet". It's easier than send money to a credit card! For payment you have a little more than two days (exactly 50 hours). Do not worry, the timer will start at the moment when you open this letter. Yes, yes .. it has already started! After payment, my virus and dirty photos with you self-destruct automatically. Narrative, if I do not receive the specified amount from you, then your device will be blocked, and all your contacts will receive a photos with your "joys". I want you to be prudent. - Do not try to find and destroy my virus! (All your data is already uploaded to a remote server) - Do not try to contact me (this is not feasible, I sent you an email from your account) - Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server. P.S. I guarantee you that I will not disturb you again after payment, as you are not my single victim. This is a hacker code of honor. From now on, I advise you to use good antiviruses and update them regularly (several times a day)! Don't be mad at me, everyone has their own work. Farewell.


I am 100% sure the part about the hacked computer etc is nothing but bullshit.
What makes me a bit nervous is the fact that this mail seems to come from my own account. At least if you belive the header...
I know headers can be manipulated and I am almost sure this is what happened here because there is no mail in the outbox.
I will delete this mail account anyway only to be sure.

Has anyone else experienced this kind of spam as well?
User avatar
themightyglider
 
Posts: 126
Joined: 23 Feb 2016, 12:13

Re: I recived a very disturbing spam mail...

Postby eugeneloza » 19 Nov 2018, 23:17

Yeah, I've heard quiet some people had almost exactly the same message text (with the same content). At least 3 cases I can recall directly people asking for some "ideas" about such mail (or just having fun about how hackers work nowadays :)), and I guess about 5 more in comments confirmed they had this or similar message at some point - including people who don't even have a webcamrea or anything like that :).
Just forget about that :) (and changing your password never hurts).
Social engineering is a fun thing.

More serious type of such messages is when they really show people their valid passwords (some reported that those were correct passwords, but most often from accounts they never use anymore). Those are passwords leaked from poorly-protected sites (e.g. Instagram has accidentally published password hashes not long ago, same thing happens from time to time at many sites, including GameDev-related). But well, it's just another reason to think about having different passwords at different sites/services.
User avatar
eugeneloza
 
Posts: 500
Joined: 22 Aug 2014, 12:15
Location: Ukraine

Re: I recived a very disturbing spam mail...

Postby dulsi » 20 Nov 2018, 02:43

Yeah I've gotten a few of those. Some with old passwords. One password I knew was a livejournal password from over ten years ago. I tried it on livejournal but it didn't work. Probably means that wasn't my last password to the site. (But even if it was, they are welcome to the livejournal account.)
dulsi
 
Posts: 570
Joined: 18 Feb 2016, 15:24

Re: I recived a very disturbing spam mail...

Postby GunChleoc » 20 Nov 2018, 09:17

A phishing attempt, you can ignore it.

And I could send you an e-mail from your own e-mail address without even having any access whatsoever to your actual e-mail account. Can be done by running a PHP script on a webserver and using PHP's sendmail function, for example.
User avatar
GunChleoc
 
Posts: 502
Joined: 20 Sep 2012, 22:45

Re: I recived a very disturbing spam mail...

Postby themightyglider » 20 Nov 2018, 14:26

I would not go that far and call this social engeneering. But it is a spam mail of a quality I never have had before.

Another fact that came into my mind is that I got a lot of spam mails on this account in the last months that invited me to shady porn sites. Their wording was very similar to the mail above so it could be the same autor...

This stuff just makes me mad and I think I only posted it here because of this.
User avatar
themightyglider
 
Posts: 126
Joined: 23 Feb 2016, 12:13

Re: I recived a very disturbing spam mail...

Postby eugeneloza » 20 Nov 2018, 16:11

But it is a spam mail of a quality I never have had before.

The best quality spam I've ever seen (at office email, addressed to our director by name) :D
"Dear Mr. (director's name).
I'm a killer, and they payed me decent money to kill you. I've been tracking you for a few weeks by now. But I see that you are innocent of what you are being accused of. Let's put this behind for 500 USD, I'll also tell you the names of those who paid me to kill you."
User avatar
eugeneloza
 
Posts: 500
Joined: 22 Aug 2014, 12:15
Location: Ukraine

Who is online

Users browsing this forum: No registered users and 1 guest