An old botnet has learned new tricks. It's leveraging our fear of privacy invasion via webcam to scam people with an email spam attack.
Cyber-security firm Check Point is detailing the latest evolution of the Phorpiex botnet (also known as Trik) into a sextortion attack. The attacking malware spams victims with emails claiming to have compromising videos of them and demanding payment or else the photos will be released into the wilds of the web.
According to Check Point, the Phorpiex bot downloads an email database from a command and control server, randomly selects an email address from the database, and sends its spam message to the address, claiming to have the victim's private data and a video of the victim "SATISFYING YOURSELF" via the victim's webcam.
But the bot ups the spam game by using databases that include leaked passwords and including those in the email, thus making the attack seem more authentic to victims. The email, of course, demands payment via Bitcoin to prevent the alleged video from being spread.
Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up! A sample email involved in the current scamCredit: Check Point / ScreenshotThe breadth of the operation is breathtaking; Check Point says the bot can shoot out up to 30,000 of these emails per hour and each campaign could affect up to 27 million users in total. According to the firm, the scam has a transfer of 14 Bitcoins in the five months they've been tracking it, which, as of Wednesday, is worth a little over $111,000.
Alexey Bukhteyev, Reverse Engineer at Check Point, told ZDNet that the emails exploited thus far were available in the Have I Been Pwned database, a growing collection of email addresses whose passwords have been affected by various hacks and breaches.
Phorpiex has previously been used to spread ransomware such as Gandcrab and the malware attack known as Pony. This new sadistic twist is simply the bot upping its game and a reminder to up your own password security game, remain skeptical of anything that might seem like a spam email, and, hey, cover your webcam while you're at it.
Just in case.
顶: 4533踩: 56
Botnet evolves to use 'sextortion' threat to scam users
人参与 | 时间:2024-09-23 04:25:41
相关文章
- Number Representations in Computer Hardware
- Richard Sherman thinks Thursday Night Football is an 'absolute poopfest'
- PGA, LIV Golf stars battle for major title at US Open
- 揭牌!揭西坪上高速服务区“百千万工程——助农驿站”运营
- Alcaraz, Sinner survive US Open wobbles
- Oklahoma's public bathrooms will soon be forced to post anti
- Korea to cut class size of high schools
- North Korea seeking outside information ban via smartphone
- 高温难耐,工会驿站化身“清凉小屋”
- N. Korea holds party meeting to discuss 'important policy issues'
评论专区