In questi giorni diversi utenti (tra i quali l’amico Stefano Capaccioli, che ringrazio per la segnalazione giunta fra le prime) mi scrivono di aver ricevuto una mail avente come oggetto… la propria password. Non una password inventata, ma una parola chiave attualmente in uso oppure utilizzata in passato. Il messaggio di posta continua spiegando che, essendo a conoscenza della password, l’autore è stato in grado di accedere al nostro PC tramite un sistema di RDP che gli ha permesso di osservare il monitor e la webcam mentre stavamo guardando film pornografici. Storia non nuova, che ricorda tra l’altro la puntata di Black Mirror nella quale i protagonisti vengono effettivamente ricattati da coloro che hanno avuto accesso alla webcam del loro PC registrandone scene poi oggetto di estorsione.
Qualcuno ha un video del mio PC e della mia webcam?
Colui che possiamo cominciare a definire delinquente aggiunge di aver ripreso sia il video a contenuti pornografici sia noi mentre eravamo in procinto di guardarlo, attivando a nostra insaputa la webcam del PC. Avendo poi acquisito tramite keylogger e remote desktop tutti i dati inclusi i contatti di Messenger, Facebook e posta elettronica – continua il malintenzionato – ci vuole poco a diffondere il video, a meno che non si versi un riscatto – a questo punto è chiaro trattasi di estorsione – di 1.900 dollari in bitcoin verso un indirizzo BTC precisato nell’email.
Il testo precisa poi che si ha soltanto un giorno di tempo per pagare da quando viene letto il messaggio e che l’autore – grazie a un pixel inserito nel messaggio stesso – saprà esattamente quando avremo letto la sua missiva. Trascorsa la giornata, in mancanza di pagamento, non resterà all’hacker che divulgare il filmato ai nostri famigliari, amici e parenti. Se invece verrà versato il riscatto, il video sarà cancellato immediatamente e staremo tranquilli.
Se si vuole avere una prova dell’esistenza di questo video? Non si avrà che da rispondere al messaggio – invece che pagare – e il delinquente ne invierà una copia direttamente a otto contatti – si noti bene, non a noi. In sostanza, nessuno tenterà di avere una prova del video, proprio perché significherebbe già divulgarlo.
Il messaggio originale con la richiesta di riscatto
Questo il testo del messaggio originale, la password reale è stata sostituita con “qwerty123”:
Da: __________ <_________@outlook.com>
Data: 10 luglio 2018 12:53:32 CEST
A: “__________” <_________@gmail.com>
Oggetto: qwerty123
I am aware, qwerty123, is your pass word. you may not know me and you’re most likely thinking why you are getting this e-mail, right?
Let me tell you, I placed a malware on the adult videos (pornography) and you know what, you visited this web site to experience fun (you know what I mean). When you were watching videos, your internet browser began working as a Rdp (Remote desktop) having a keylogger which gave me access to your display and also webcam. After that, my software obtained your complete contacts from messenger, fb, as well as email.
What did I do?
I created a double-screen video. 1st part displays the video you were viewing (you’ve got a nice taste rofl), and second part displays the recording of your cam.
Exactly what should you do?
Well, honestly, $1900 is a fair price for our little secret. You’ll make the payment through Bitcoin (if you do not know this, search “how to buy bitcoin” in google).
BTC ADDRESS: ___________________________
(It is CASE sensitive, so copy and paste it)
Note:
You now have one day in order to make the payment. (I have a special pixel within this email message, and now I know that you have read through this message). If I do not get the BitCoin, I definitely will send out your video recording to all of your contacts including members of your family, colleagues, and many others. nonetheless, if I receive the payment, I’ll erase the video immediately. If you want to have evidence, reply with “yes!” and I will send your video recording to your 8 contacts. It is a non negotiable offer, thus don’t waste my personal time & yours by responding to this email.
Come fanno ad avere la mia password?
La password – come avrà notato chi ha ricevuto il messaggio – è corretta e, se non attuale, è comunque una password utilizzata davvero in passato. I delinquenti hanno raccolto milioni di password sfruttando i vari leak usciti in rete, nel dark web, su Torrent, che contengono i dati rubati a colossi come Dropbox, Linkedin negli ultimi anni.
Ovviamente se non avete cambiato la password, correte subito a farlo, soprattutto perché magari l’avete modificata sul servizio sul quale è stato segnalato il leak ma non su altri dove – cosa da non fare assolutamente – avete utilizzato le stesse credenziali.
Una prova che può fare chiunque è quella di inserire la mail sulla quale avete ricevuto la richiesta di riscatto nel servizio Have I Been Pwned, che permette di conoscere se il nostro indirizzo è inserito nei vari elenchi di password e credenziali usciti nel dark web.
Hanno davvero un filmato della mia webcam?
No, non lo hanno, fanno finta di averlo nella speranza che la vittima paghi, sentendosi in difetto (magari perché qualche video pornografico l’ha effettivamente guardato) e incutendo la paura di divulgare le immagini compromettenti.
In genere quando vengono avviate forme di estorsione – in stile sextortion – il ricattatore mostra alla vittima il malloppo, il materiale che minaccerà di divulgare in caso di mancato pagamento. Il fatto di non mostrarlo è spesso un indice di un mero tentativo d’ingannare la vittima sperando che si convinca di essere davvero ricattabile.
Nel dubbio, serve pagare il riscatto?
Pagare il riscatto non è mai la soluzione. O meglio, in alcuni casi – es. numerosi ransomware – effettivamente permette di ottenere i propri dati, ma a scapito di un favore ai delinquenti che aumenteranno il loro potere distruttivo realizzando sistemi di estorsione sempre più performanti.
Nel caso del ricatto con la mail contenente la nostra password, pagare il riscatto non serve proprio a nulla, dato che il ricattatore non ha i nostri dati (a meno che ovviamente la password non fosse quella attuale e non sia magari andato a scaricarsi il contenuto della nostra casella di posta elettronica). Ci sono poi casi di sextortion nei quali pagando il riscatto si è avviato un meccanismo impossibile da interrompere, fatto di continue richieste di versamento, in genere tramite western union, molto più raramente in bitcoin.
Cercando in rete si trovano riferimenti all’indirizzo bitcoin 1Dvd7Wb72JBTbAcfTrxSJCZZuf4tsT8V72 sul quale alle vittime viene richiesto il pagamento del riscatto, indirizzo tra l’altro che effettivamente ha ricevuto del denaro. Altre segnalazioni mostrano indirizzi diversi, mai utilizzati, non è quindi chiaro se i delinquenti utilizzino un insieme d’indirizzi da ruotare tra le vittime, oppure ci siano più organizzazioni criminali a fare uso di questo sistema di estorsione, ognuna con un indirizzo BTC diverso.
Cosa posso fare per prevenire questo tipo di problemi?
Innanzitutto non usare mai la stessa password su più di un servizio. Usarne una per Facebook, una per la posta elettronica, una per Twitter, una per Linkedin e così via. Cambiarle ogni tanto ma soprattutto quando escono dei leak che coinvolgono servizi dove ci siamo registrati.
Per rimanere aggiornati sui leak di password, ci si può iscrivere al servizio Notify Me di HaveIBeenPwned che ci permetterà di ricevere gratuitamente una mail non appena usciranno degli elenchi di password dove è presente anche il nostro indirizzo di posta elettronica.
In secondo luogo, impostare sempre i servizi dove siamo registrati con la protezione di sicurezza chiamata “autenticazione a due fattori”, che fa sì che per accedere al nostro account da un nuovo PC sia necessario inserire non solo la password ma anche un codice che riceveremo sul nostro numero di telefono o visualizzeremo sul nostro smartphone.
In ultimo, per quanto possa sembrare una leggenda metropolitana, male non fa coprire la webcam quando non la si usa: non tutti i notebook o PC hanno il led che ci segnala l’attivazione della webcam e sembra che comunque anche quello sia ingannabile.
Per chi ha Mac OS, un buon software che previene l’attivazione involontaria di audio o video è OverSight, sviluppato proprio per avvisare l’utilizzatore quando qualche processo – all’insaputa di tutti – sta attivando il microfono o la registrazione della video proveniente dalla webcam.
Aggiornamento: 10 settembre 2018
Nuova ondata di email che tentano di spaventare chi le riceve con minacce di diffusione di documenti privati e presunti filmati fatti tramite la webcam durante la visione di materiale pornografico, chiedendo un riscatto in bitcoin.
Cambia il testo – non di molto in realtà – ma la novità è la sostituzione della password della vittima con il suo numero di telefono, riportato per intero o parzialmente. Anche in questo caso, i criminali sono in grado di reperire il cellulare della vittima da data leak presenti nel dark web (e non solo) oppure da informazioni pubbliche, accessibili a chiunque.
Riportiamo un esempio di messaggio di posta estorsivo contenente il numero di cellulare della vittima:
Mittente: “support*******”
Oggetto:”part num your phone. ****”
A: ******@ransomware.it
Da: support32886
Hey. It’s me! Your future friend or enemy.
You do not know me and think why I received this letter.
I am sorry for my english, its not my native language.
I learn more machine language – code.
I hack phones and save information from them.
I installed you a program with the functions of saving video and saving typing.
When you visited the sites that interest me. (Sites containing porn.)
My program recorded video from your screen with simultaneous connection to your camera.
Saying thanks you to the phone manufacturers. This mode – Split Screen.
Also, I saved a full backup of your phone, which contains all your files.
History of correspondence, browser history and all telephone contacts during the hacking.
Saying thanks you to the phone manufacturers. This mode – backup.
At the moment the program is deactivated, and I am writing to you.
You think what I should do. And, of course, you are furious.
You have to make a choice.
And remember. You make choice, what will happen next in your life.
1. You can delete and ignore this email. When I return, I will see that the letter is being viewed.
In this case, I will be able to share this personal record with your contacts.
To track the reading of a message and the actions in it, I use the facebook pixel.
Thanks to them. (Everything that is used for the authorities can help us.)
More you can find out by the link.
https://www.facebook.com/business/help/898185560232180?helpref=faq_content
2. You can write to the police, and they will investigate the hacked ip and hacked mail.
In order to find me and protect you. I think time is too small for this, 48 hours before sending the files.
In this case, I will be able to share this personal record with your contacts.
The police will not save you from the ridicule of friends, colleagues and family. You want live with this?
In my practice, there were cases when people had to change the whole way of life and place of residence.
They wanted to pay, but it was too late. It’s time, and the files have been sent.
Everything that is downloaded on the Internet there and will remain forever.
More information you can find on request in Google
“Beyonce delete photo from internet”
3. I want to get paid for the work done. We all want our work to be paid.
(Even if it was not a wanted job.)
I want 1000 USD. In Bitcoin
My wallet BTC Address:
1EkAVVDg8Rbwwa7j9DbvHQ7VmQ4FkBdEGT
(CASE sensitive, copy and paste it carefully)
If you have any questions, you can write me. Email will be available for short-term support.
For payment after opening the letter 48 hours.
Pay me and you make new choice.
4. Receiving video only personally.
5. Delete all the data.
Time has begun.
Molto interessante anche il fatto che il criminale, per rendere maggiormente credibile il fatto che è in grado di conoscere il momento in cui la vittima legge il messaggio, riporta un link alla guida di Facebook dove spiega il funzionamento del sistema di “Facebook pixel base code”, che permette a chi fa uso dell’advertising fornito da Facebook di conoscere come si comportano gli utenti una volta finiti sul proprio sito web:
Understand your pixel event data in Events Manager
The Facebook pixel helps you measure the effectiveness of your advertising by understanding the actions people take on your website as the result of your Facebook ads. After you add the Facebook pixel base code and event code to your website, you can see your pixel event data on the Pixel page. Learn more about the benefits of using a Facebook pixel.
Il fine è proprio quello di convincere chi riceve la mail che la lettura è stata in qualche modo “tracciata” utilizzando gli strumenti forniti da Facebook stesso.
Aggiornamento: 27 settembre 2018
Nuova ondata di messaggi con richiesta di ricatto in bitcoin, sempre in inglese, sempre con la password dell’utente che li riceve riportata nel testo e prelevata da data leak.
Da: Ring Palmer
A: info@**********.it
Oggetto: info – *******
I am well aware ******* is your password. Lets get directly to purpose. absolutely no one has compensated me to check you. You do not know me and you’re most likely wondering why you are getting this e-mail?|You may not know me and you’re probably wondering why you’re getting this e mail? Neither anyone has paid me to check about you.}
actually, i actually installed a software on the X videos (porn) website and guess what, you visited this site to experience fun (you know what i mean). When you were viewing video clips, your browser began operating as a RDP that has a keylogger which gave me access to your display screen and also cam. immediately after that, my software program collected your entire contacts from your Messenger, Facebook, and e-mailaccount. Next i created a double video. First part displays the video you were watching (you have a nice taste : )), and 2nd part shows the view of your cam, and its you.
You have got two different options. Let us go through these options in particulars:
Very first option is to dismiss this email message. Consequently, i most certainly will send your actual video clip to each one of your personal contacts and then just consider about the disgrace you will get. and consequently if you happen to be in a committed relationship, exactly how this will affect?
Number 2 solution should be to pay me $1000. We are going to refer to it as a donation. as a result, i most certainly will straightaway remove your video footage. You can go forward your way of life like this never took place and you will not hear back again from me.
You’ll make the payment by Bitcoin (if you do not know this, search for ‘how to buy bitcoin’ in Google search engine).
BTC address to send to: 1N1vAmdsphvCccDymK6yehsMsDWhLV6XvS
[case sensitive so copy and paste it]
if you may be curious about going to the cop, look, this e mail cannot be traced back to me. i have covered my actions. i am just not looking to charge a fee very much, i want to be paid for. i’ve a special pixel within this message, and right now i know that you have read this e mail. You have one day in order to pay. if i don’t get the BitCoins, i will definately send your video recording to all of your contacts including members of your family, co-workers, and many others. However, if i do get paid, i’ll erase the video immediately. it is a non:negotiable offer, that being said don’t waste my time and yours by replying to this email message. if you want to have evidence, reply Yeah! & i will certainly send your video to your 11 contacts.
Altro testo, leggermente diverso dal precedente, che in realtà è in circolazione già da luglio:
I am well aware ********* is your password. Lets get right to the point. You do not know me and you are probably thinking why you’re getting this e-mail? Absolutely no one has compensated me to investigate you.
actually, I placed a malware on the X videos (sex sites) website and do you know what, you visited this website to have fun (you know what I mean). When you were viewing videos, your internet browser began functioning as a RDP that has a keylogger which gave me access to your screen and web camera. after that, my software program gathered all your contacts from your Messenger, Facebook, and emailaccount. After that I made a video. 1st part displays the video you were viewing (you have a fine taste : )), and next part shows the view of your cam, yeah it is u.
You have got two different alternatives. Lets review each one of these solutions in details:
Very first solution is to dismiss this e-mail. In this scenario, I will send your actual video to almost all of your personal contacts and think about concerning the disgrace you feel. Not to mention should you be in an intimate relationship, how it will affect?
Number 2 solution is to compensate me $7000. We are going to describe it as a donation. In this instance, I most certainly will promptly erase your video. You can keep daily life like this never occurred and you will never hear back again from me.
You’ll make the payment by Bitcoin (if you do not know this, search for “how to buy bitcoin” in Google search engine).
BTC Address: 18u3FSpavagGw4LFoUbnzp7t3KZrsg54k4
[case-SENSITIVE copy and paste it]
If you are looking at going to the cops, anyway, this e mail can not be traced back to me. I have dealt with my moves. I am not looking to charge a fee a whole lot, I would like to be paid for. You now have one day to make the payment. I’ve a specific pixel in this email message, and now I know that you have read through this email message. If I do not receive the BitCoins, I will definitely send out your video to all of your contacts including relatives, coworkers, and many others. Nevertheless, if I receive the payment, I will destroy the recording immediately. If you really want proof, reply Yeah then I will send your video recording to your 8 friends. This is the non-negotiable offer therefore please don’t waste mine time & yours by replying to this message.
Aggiornamento: 23 ottobre 2018
La mail con richiesta di riscatto muta e si evolve, in questi giorni si sta diffondendo un’ondata con contenuto simile a questo:
Hello!
I’m a hacker who cracked your email and device a few months ago.
You entered a password on one of the sites you visited, and I intercepted it.
This is your password from info@ransomware.it on moment of hack: kAw523SfL
Of course you can will change it, or already changed it.
But it doesn’t matter, my malware updated it every time.
Do not try to contact me or find me, it is impossible, since I sent you an email from your account.
Through your email, I uploaded malicious code to your Operation System.
I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources.
Also I installed a Trojan on your device and long tome spying for you.
You are not my only victim, I usually lock computers and ask for a ransom.
But I was struck by the sites of intimate content that you often visit.
I am in shock of your fantasies! I’ve never seen anything like this!
So, when you had fun on piquant sites (you know what I mean!)
I made screenshot with using my program from your camera of yours device.
After that, I combined them to the content of the currently viewed site.
There will be laughter when I send these photos to your contacts!
BUT I’m sure you don’t want it.
Therefore, I expect payment from you for my silence.
I think $825 is an acceptable price for it!
Pay with Bitcoin.
My BTC wallet: 1JTtwbvmM7ymByxPYCByVYCwasjH49J3Vj
If you do not know how to do this – enter into Google “how to transfer money to a bitcoin wallet”. It is not difficult.
After receiving the specified amount, all your data will be immediately destroyed automatically. My virus will also remove itself from your operating system.
My Trojan have auto alert, after this email is read, I will be know it!
I give you 2 days (48 hours) to make a payment.
If this does not happen – all your contacts will get crazy shots from your dark secret life!
And so that you do not obstruct, your device will be blocked (also after 48 hours)
Do not be silly!
Police or friends won’t help you for sure …
p.s. I can give you advice for the future. Do not enter your passwords on unsafe sites.
I hope for your prudence.
Farewell.
Rimane valido il fatto che si tratta di mail false, senza alcun fondamento, la password spesso è corretta ma soltanto perché è stata ricavata da liste pubbliche (leak, dump, etc…) dato che non è stato bucato nessun PC né casella di posta elettronica.
Aggiornamento: 29 ottobre 2018
La mail che viene diffusa in questi giorni anche in Italia è in inglese e riporta quanto segue (la password “password123” ovviamente è di fantasia ma nella mail viene riportata una password che l’utente ha utilizzato effettivamente in passato:
Da: info@ransomware.it <info@ransomware.it>
Inviato: lunedì 29 ottobre 2018 13:53:31
A: password123
Oggetto:info@ransomware.it has password password123. Password must be changed
Hello!
I’m a programmer who cracked your email account and device about half year ago.
You entered a password on one of the insecure site you visited, and I catched it.
Your password frominfo@ransomware.it on moment of crack: password123
Of course you can will change your password, or already made it.
But it doesn’t matter, my rat software update it every time.
Please don’t try to contact me or find me, it is impossible, since I sent you an email from your email account.
Through your e-mail, I uploaded malicious code to your Operation System.
I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources.
Also I installed a rat software on your device and long tome spying for you.
You are not my only victim, I usually lock devices and ask for a ransom.
But I was struck by the sites of intimate content that you very often visit.
I am in shock of your reach fantasies! Wow! I’ve never seen anything like this!
I did not even know that SUCH content could be so exciting!
So, when you had fun on intime sites (you know what I mean!)
I made screenshot with using my program from your camera of yours device.
After that, I jointed them to the content of the currently viewed site.
Will be funny when I send these photos to your contacts! And if your relatives see it?
BUT I’m sure you don’t want it. I definitely would not want to …
I will not do this if you pay me a little amount.
I think $809 is a nice price for it!
I accept only Bitcoins.
My BTC wallet: 1HQ7wGdA5G9qUtM8jyDt5obDv1x3vEvjCy
If you have difficulty with this – Ask Google “how to make a payment on a bitcoin wallet”. It’s easy.
After receiving the above amount, all your data will be immediately removed automatically.
My virus will also will be destroy itself from your operating system.
My Trojan have auto alert, after this email is looked, I will be know it!
You have 2 days (48 hours) for make a payment.
If this does not happen – all your contacts will get crazy shots with your dirty life!
And so that you do not obstruct me, your device will be locked (also after 48 hours)
Do not take this frivolously! This is the last warning!
Various security services or antiviruses won’t help you for sure (I have already collected all your data).
Here are the recommendations of a professional:
Antiviruses do not help against modern malicious code. Just do not enter your passwords on unsafe sites!
I hope you will be prudent.
Bye.
Aggiornamento: 7 novembre 2018
Cominciano ad arrivare segnalazioni di un nuovo testo, sempre riportante la richiesta di riscatto in bitcoin e una password attendibile, spesso obsoleta, prelevata certamente dai vari data leak disponibili in rete.
Da: info@ransomware.it
Inviato: info@ransomware.it
A: password123
Oggetto: info@ransomware.it is compromised (password123)
Hi there
So I’m a hacker who broke your e-mail as well as device a few weeks back.
You typed in your passcode on one of the web sites you visited, and I intercepted it.
This is your security password of info@ransomware.it on moment of hack: password123
Obviously you can will change it, or even already changed it.
Nevertheless it doesn’t mean much, my malware modifie ;d it each and every time.
Do not necessarily consider to get in touch with me or find me, it is impossible, since I sent you mail from your account only.
Through your own email, I uploaded harmful code to your Operation System.
I saved all of your contacts together with friends, colleagues, family members plus a comprehensive histo ;ry of visits to the World-wide-web resources.
Additionally I set up a Virus on your device.
You are not my only prey, I normally lock personal computers and ask for the ransom.
Nevertheless I ended up being struck by the web sites of passionate content that you often take a look at.
I am in impact of your current fantasies! I’ve certainly not observed something like this!
So, when you had fun on piquant web pages (you know what I am talking about!) I made screen shot with using my program from your camera of yours system.
Next, I put together them to the content of the particular currently seen site.
Now there will certainly be giggling when I send these photographs to your contacts!
Yet I am sure you don’t want it.
Therefore, I expect payment from you for my quiet.
I think $900 is an appropriate cost regarding it!
Pay with Bitcoins.
My Bitcoin wallet address is 1CzZc2deyhtxABm3MxJZQdj7sYSG4z2dKi
In case you do not understand how to do this – enter in to Google ‘how to send money to the bitcoin wallet’. It is not difficult.
Right after receiving the specified amount, all your info will be promptly eliminated automatically. My trojan will also remove itself out of your computer.
My Computer virus possess auto alert, so I know when this specific email is opened.
I give you 2 days (48 hrs) for you to make a payment.
In case this does not take place – all your associates will get insane pictures from your darkish secret life and your system will be blocked as well after two days.
Do not end up being silly!
Cops or friends won’t assist you for sure …
PS I can present you with advice with regard to the future. Never key in your security passwords on unsafe web sites.
I expect for your discretion.
Hasta la vista.
Aggiornamento: 12 novembre 2018
La richiesta di riscatto si fa più alta (7.000 dollari) e il testo si evolve illustrando esattamente le conseguenze del mancato pagamento di riscatto in bitcoin:
Da: Florry Cader <nkzaramr@outlook.com>
Data: 12 novembre 2018 02:46:48 CET
A: “info@ransomware.it”>
Oggetto: info – password123
password123 one of your pass. Lets get right to purpose. Not one person has compensated me to check about you. You don’t know me and you are most likely wondering why you’re getting this e mail?
Well, i setup a malware on the adult video clips (adult porn) web site and guess what, you visited this site to have fun (you know what i mean). While you were viewing videos, your internet browser began functioning as a RDP that has a keylogger which provided me access to your display as well as cam. immediately after that, my software collected all your contacts from your Messenger, FB, as well as email . Next i created a video. First part displays the video you were watching (you have a good taste lol), and 2nd part shows the recording of your cam, & its you.
You got two choices. Lets check out the solutions in details:
1st choice is to just ignore this e mail. in this scenario, i am going to send out your very own tape to almost all of your personal contacts and then just think about the disgrace you will see. Do not forget if you are in a romantic relationship, exactly how this will affect?
Number 2 alternative will be to compensate me 7000 USD. Lets regard it as a donation. Consequently, i most certainly will straight away delete your video footage. You could resume your way of life like this never occurred and you will not ever hear back again from me.
You will make the payment through Bitcoin (if you do not know this, search ‘how to buy bitcoin’ in Google search engine).
BTC address: 1HViUyJoWXoCFHiiCLiBE6keyNrJWgSdDM
[CaSe-sensitive, copy & paste it]
if you may be planning on going to the cop, well, this e-mail can not be traced back to me. I have covered my steps. i am just not attempting to charge a fee very much, i simply want to be compensated. i have a special pixel within this message, and now i know that you have read this e-mail. You now have one day to pay. if i don’t receive the BitCoins, i will definitely send out your video recording to all of your contacts including members of your family, co-workers, and so on. However, if i do get paid, i will erase the recording immediately. This is a non:negotiable offer and thus please don’t waste my personal time & yours by replying to this e-mail. if you want evidence, reply Yes! and i will certainly send your video recording to your 9 friends.
Aggiornamento: 23 novembre 2018
Nuovo contenuto della mail di ricatto, decisamente aggiornato rispetto alle precedenti, mantenendo sempre la password del proprio account bene in vista atta a rendere la minaccia credibile.
Oggetto: info@ransomware.it has been hacked! Change your password immediately!
Date: 23 Nov 2018 15:02:29 -0300
From: info@ransomware.it
To: password123 <info@ransomware.it>
Hello!
I have very bad news for you.
03/08/2018 – on this day I hacked your OS and got full access to your account info@ransomware.it
On this day your account info@ransomware.it has password: password123
So, you can change the password, yes.. But my malware intercepts it every time.
How I made it:
In the software of the router, through which you went online, was a vulnerability.
I just hacked this router and placed my malicious code on it.
When you went online, my trojan was installed on the OS of your device.
After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).
A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock.
But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
I’m talk you about sites for adults.
I want to say – you are a BIG pervert. Your fantasy is shifted far away from the normal course!
And I got an idea….
I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
After that, I made a screenshot of your joys (using the camera of your device) and glued them together.
Turned out amazing! You are so spectacular!
I’m know that you would not like to show these screenshots to your friends, relatives or colleagues.
I think $880 is a very, very small amount for my silence.
Besides, I have been spying on you for so long, having spent a lot of time!
Pay ONLY in Bitcoins!
My BTC wallet: 18YDAf11psBJSavARQCwysE7E89zSEMfGG
You do not know how to use bitcoins?
Enter a query in any search engine: “how to replenish btc wallet”.
It’s extremely easy
For this payment I give you a little over two days (exactly 55 hours).
As soon as this letter is opened, the timer will work.
After payment, my virus and dirty screenshots with your enjoys will be self-destruct automatically.
If I do not receive from you the specified amount, then your device will be locked, and all your contacts will receive a screenshots with your “enjoys”.
I hope you understand your situation.
– Do not try to find and destroy my virus! (All your data, files and screenshots is already uploaded to a remote server)
– Do not try to contact me (you yourself will see that this is impossible, I sent this email from your account)
– Various security services will not help you; formatting a disk or destroying a device will not help, since your data is already on a remote server.
P.S. You are not my single victim. so, I guarantee you that I will not disturb you again after payment!
This is the word of honor hacker
I also ask you to regularly update your antiviruses in the future. This way you will no longer fall into a similar situation.
Do not hold evil! I just do my job.
Good luck.
27 dicembre 2018
Anche dopo Natale, torna la truffa con la richiesta di riscatto in bitcoin e la mail con la password ricavata dai leak online, il testo è simile ai precedenti, leggermente aggiornati in alcune parti.
Subject:
Your account has been hacked! You need to unlock.
From:
<info@ransomware.it>
Date:
27/12/2018, 10:32 +0000
To:
password123 <info@ransomware.it>
Hi, stranger!
I know the password123, this is your password, and I sent you this message from your account.
If you have already changed your password, my malware will be intercepts it every time.
You may not know me, and you are most likely wondering why you are receiving this email, right?
In fact, I posted a malicious program on adults (pornography) of some websites, and you know that you visited these websites to enjoy
(you know what I mean).
While you were watching video clips,
my trojan started working as a RDP (remote desktop) with a keylogger that gave me access to your screen as well as a webcam.
Immediately after this, my program gathered all your contacts from messenger, social networks, and also by e-mail.
What I’ve done?
I made a double screen video.
The first part shows the video you watched (you have good taste, yes … but strange for me and other normal people),
and the second part shows the recording of your webcam.
What should you do?
Well, I think $772 (USD dollars) is a fair price for our little secret.
You will make a bitcoin payment (if you don’t know, look for “how to buy bitcoins” on Google).
BTC Address: 16LBDius3vg6ufFvnc7PGXfiTZgphuZgr5
(This is CASE sensitive, please copy and paste it)
Remarks:
You have 2 days (48 hours) to pay. (I have a special code, and at the moment I know that you have read this email).
If I don’t get bitcoins, I will send your video to all your contacts, including family members, colleagues, etc.
However, if I am paid, I will immediately destroy the video, and my trojan will be destruct someself.
If you want to get proof, answer “Yes!” and resend this letter to youself.
And I will definitely send your video to your any 16 contacts.
This is a non-negotiable offer, so please do not waste my personal and other people’s time by replying to this email.
Bye!
L'articolo Avete ricevuto una mail con la vostra password e richiesta di riscatto in bitcoin? sembra essere il primo su Ransomware Blog.