Another “sextortion” email

The scammers never give up. Obviously, it must work at some level or they would find something else to do. But with the number of people in the world, the bell curve pretty much predicts that by blasting out millions of email messages like this, they will snag someone who is untutored enough to pay their extortionate demand. It makes me very sad that the world is so full of evil creatures like this.


Greetings!

⚠️ I’ve been watching you for weeks now. ⚠️
The thing is, you’ve been infected with malware via the adult website you visited.

I have made a video showing how you satisfy yourself on the left side of the screen, and on the right side you see the video you have been watching.
With one click, I can send this video to all your contacts in the mail and social networks. I can also publish access to all your emails and messaging apps that you use.

If you want to prevent this, then:
Transfer $650(USD) to my bitcoin wallet (in case you don’t know how to do it, then type in to Google: “Buy a bitcoin”).

My Bitcoin Wallet:
obfuscated bitcoin wallet address
After receiving the payment, I will erase the video and you will never hear from me again.
I will give you 50 hours (more than two days) to pay.
I see you’re reading this email and the timer started you opened it.

Timer id: 241996031

Don’t attempt to reply me. It doesn’t make any sense (the sender’s address is created automatically).
Filing a complaint somewhere doesn’t make sense, because this email cannot be tracked, and neither can my bitcoin address.
I don’t make mistakes.

If I find that you shared this message with somebody else, the video will be distributed immediately.
Good luck with that.


Ya. Well, good luck with your blackmail attempt, since I don’t use a webcam, you waste of human cytoplasm.

As always, the takeaway is never send money to scammers, or unknown people, by bitcoin, Western Union, Gift Cards, or any other method.

The Old Wolf continues to be outraged by these antics.

More sextortion

People who send things like this out are the dung of dung-eaters. Please never fall for these shady extortion efforts.

From: “Ava Avila” <ava.avila@qwod.cia-gov-it.ga>
To: [redacted]
Subject: Central Intelligence Agency – Case #45693781

Case #45693781
Distribution and storage of pornographic electronic materials involving underage children.

My name is Ava Avila and I am a technical collection officer working for Central Intelligence Agency.
It has come to my attention that your personal details including your email address [redacted] are listed in case #45693781.
The following details are listed in the document’s attachment:

  • Your personal details,
  • Home address,
  • Work address,
  • List of relatives and their contact information.

Case #45693781 is part of a large international operation set to arrest more than 2000 individuals suspected of paedophilia in 27 countries.
The data which could be used to acquire your personal information:
Your ISP web browsing history, DNS queries history and connection logs,
Deep web .onion browsing and/or connection sharing, Online chat-room logs, Social media activity log.

The first arrests are scheduled for April 8, 2019.

Why am I contacting you ?

I read the documentation and I know you are a wealthy person who maybe concerned about reputation.
I am one of several people who have access to those documents and I have enough security clearance to amend and remove your details from this case. Here is my proposition.

Transfer exactly $10,000 USD (ten thousand dollars – about 2.5 BTC) through Bitcoin network to this special bitcoin address:

3C36DiGhcf4LvznzC6B2MWduPrL9rakgRp (note: this is a scam bitcoin address, never use it for anything.)

You can transfer funds with online bitcoin exchanges such as Coinbase, Bitstamp or Coinmama. The deadline is March 27, 2019 (I need few days to access and edit the files).

Note: I didn’t see this email until April 9, 2019 – thus far I haven’t been arrested by the CIA. 🤣😜🤣

Upon confirming your transfer I will take care of all the files linked to you and you can rest assured no one will bother you.

Please do not contact me. I will contact you and confirm only when I see the valid transfer.

Regards,

Ava Avila
Technical Collection Officer
Directorate of Science and Technology
Central Intelligence Agency

The executive summary: “I’m a corrupt CIA agent, and if you bribe me $10,000 I’ll make your child-pornography file go away.”

Look at this email address: ava.avila@qwod.cia-gov-it.ga – it’s from a domain in Gabon. These people are dumber than a pile of bricks.

Never fall for scummy tricks like this. Never give money to scammers. Be careful out there.

The Old Wolf has spoken.

The scammers are getting desperate

A friend of mine in Finland just got one of these, it falls into the same category as the sextortion scam about which I have already written: desperate bad guys blasting out millions of emails to the entire world, hoping to catch the handful of people who *do* visit adult sites, have unsecured webcams, a guilty conscience, and very little education.

In this case, they’re hoping to snare the fearful and gullible segment of the world’s populace. It astonishes me that people could be so foolish as to fall for these kinds of scams, but if it didn’t work at some level, the bad guys wouldn’t do it.

But the takeaway here is the same as always: This is a scam, there’s no truth to it, and you should never send money to criminals. Please keep your loved ones, particularly the elderly and vulnerable, educated and protected.

The Old Wolf has spoken.

The Scammers Keep Trying

Image result for sextortion

I don’t get much spam these days with Gmail, their filters are pretty good at sifting out the chaff. But I still have an account with another provider that lets a few things through.

The first one I saw this week was the old “Nigerian Prince” ploy, it amazes me that people are still trying this one.

Hello

I am contacting you to see if we can make a business together, My names are  Suvo  sarkar the Chief Executive Director of Emirates NBD  in United Arab Emirate  U.A.E. I discovered a dormant account with a holding balance of US$63M in the bank where I am working in United Arab Emirate U.A.E, Actually I do not have to involve myself officially because of my job and position in the bank, but I know what will be required to release the fund to you as I will present you as next of kin to the inheritance. I know all about the depositor who has passed away leaving no beneficiary to the account he deposited the funds.

Please get back to indicate your interest so I can give you the full details of the transaction for us to commence immediately.

Best regards,
Suvo Sarka

 

By now, everyone should know about this kind of thing – but just in case, this is 100% pure bull manure – there’s no money, you’re  not next of kin, and if you respond, there will be “taxes,” “fees,” “bribes,” “administrative stamps,” and other things to be paid until you run out of money, time, or patience.

These people are criminals, thieves, bad actors with no conscience and no morals. Many of them justify their theft by saying to themselves, “The White Man plundered our country, it’s only fair to take their money.” Others are just evil men with no conscience. Do not interact with them.


The second scam, commonly known as “sextortion,” was more interesting, I had not seen one of these before.

From: nightmarе <bogus_email@phoney.com>
To: <redacted>
Subject: You are my viсtim.

Hi, my prey.

THIS IS MY LAST WARNING!

I write you because I put a virus on the web page with pornography which you have viewed.
My trоjan caрtured аll your рrivate dаta аnd switсhed on yоur сamеrа whiсh rеcordеd thе act оf yоur solitаry sex. Just аfter thаt thе trоjаn saved your contact list.
I will erаsе thе cоmрrоmising videо rесords аnd informаtiоn if you send me 750 USD in bitcoin.
This is address fоr pаymеnt : 1PLtH8HPHQLboeFvrBN2XJPJz99TxayGCo
I give you 30 hours after yоu opеn my mеssаgе fоr making thе payment.
Аs sоon аs you reаd thе mеssаgе I’ll sеe it right аwаy.
It is nоt nесessаry to tell me that yоu hаvе sеnt mоney to mе. This аddress is connectеd to yоu, my systеm will еrased autоmаticаlly after transfer соnfirmatiоn.
If you nеed 48h just Opеn thе calculatоr on yоur desktор and press +++
If yоu don’t раy, I’ll send dirt tо all your contасts.
Let me remind you-I sеe what you’re dоing!
Yоu cаn visit thе policе officе but anybody cаn’t help you.
If yоu try to dеceivе me , I’ll know it immediately!
I dоn’t live in your cоuntry. So аnyоnе cаn not trаck my lосаtion еvеn fоr 9 mоnths.
byе. Don’t fоrgеt аbоut the shame and tо ignorе, Your lifе сan be ruined.

First:

This is sheer nonsense, blasted out to all and sundry with harvested or leaked emails in the hopes of catching a scared victim. Because some people do visit adult sites, and some people do have webcams, and it is possible for hackers to access these cameras remotely if people are foolish enough to download the appropriate malware.

Second:

  1. I don’t have a webcam, I don’t visit adult sites, and my computer is well-protected against malware, so all his noise about trojans and “compromising video records” are nothing but lies.
  2. Opening a calculator app and pressing “+++” could not possibly interact with an email program to let a scammer know that I needed 48 hours instead of 30 to send him his blackmail money.
  3. You can go to https://bitcoinwhoswho.com/ and look up bitcoin addresses like the one the scammer lists above. According to the report generated, this particular address has been reported multiple times for fraudulent activity, always the same sextortion scam but often with varying messages

Here’s another example, just for reference:

From: “Anonymous Hacker – Ma” ma-897@d.anonymous-observer.tk
To: [redacted]
Subject: This is my last warning [redacted]

LAST WARNING [redacted]

You have the last chance to save your social life – I am not kidding!!
I give you the last 72 hours to make the payment before I send the video with your [indecent activity] to all your friends and associates.
The last time you visited a erotic website with young Teens, you downloaded and installed the software I developed.
My program has turned on your camera and recorded your [indecent activity] and the video you were watching.
My software also downloaded all your email contact lists and a list of your Facebook friends.
I have both the ‘Info.mp4’ with your [indecent activity] and a file with all your contacts on my hard drive. You are very perverted!
If you want me to delete both files and keep your secret,you must send me Bitcoin payment. I give you the last 72 hours. If you don’t know how to send Bitcoins, visit Google.
Send 2000 USD to this Bitcoin address immediately:
32u7BDdEb48LXNTDDTe9q9Nce5Z9QAJG1g (copy and paste)
1 BTC = 3470 USD right now, so send exactly 0.588241 BTC to the address above.
Do not try to cheat me! As soon as you open this Email I will know you opened it.
This Bitcoin address is linked to you only, so I will know if you sent the correct amount. When you pay in full, I will remove both files and deactivate my software.
If you don’t send the payment, I will send your [perverted] video to ALL YOUR FRIENDS AND ASSOCIATES from your contact list I hacked.
Here are the payment details again:
Send 0.588241 BTC to this Bitcoin address:
32u7BDdEb48LXNTDDTe9q9Nce5Z9QAJG1g
You can visit the police but nobody will help you. I know what I am doing. I don’t live in your country and I know how to stay anonymous.
Don’t try to deceive me – I will know it immediately – my spy ware is recording all the websites you visit and all keys you press.
If you do – I will send this ugly recording to everyone you know, including your family.
Don’t cheat me! Don’t forget the shame and if you ignore this message your life will be ruined.
I am waiting for your Bitcoin payment.
Ma
Anonymous Hacker

P.S. If you need more time to buy and send 0.588241 BTC, open your notepad and write ’48h plz’.
I will consider giving you another 48 hours before I release the vid, but only when I really see you are struggling to buy bitcoin.

And one more:

From: nightmarе
To: [redacted]
Subject: You are my victim.

Good day

Dо nоt mind оn my illitеrасy, I am frоm China.

I uрlоаdеd thе mаliciоus рrоgram on your systеm.
Sinсе thаt mоment I рilfеrеd аll рrivy bасkgrоund frоm yоur systеm. Аdditiоnally I have somе morе соmрromising evidеnсе. The mоst intеrеsting еvidenсе thаt I stоlе- its а videоtаpе with your [indecent activity]. I аdjustеd virus оn а роrn web sitе аnd аftеr yоu lоadеd it. Whеn yоu dесidеd with thе vidеo аnd tарpеd on a рlаy buttоn, my dеlеtеriоus sоft at оncе sеt up on your systеm. Аfter adjusting, yоur саmerа shoоt thе vidеоtаpе with your [indecent activity], in аdditiоn it saved рreсisеly thе рorn vidеo yоu were watching. In nеxt fеw dаys my mаlwаre cоllесtеd аll your sociаl and wоrk сontaсts.
If yоu wаnt tо dеlеtе thе recоrds- pay mе 340 еuro in BTC(сryрtосurrenсy).
I provide you my Btc number – 1JRMsH8xnm2Uk3XZQfS63woi4uFyM2gBLC
Yоu hаvе 24 hours after rеаding. Whеn I gеt trаnsfer I will dеstrоy the videotaрe еvermоrе.
If you need 50 hours just Open the calculator on your desktop and press +++
Оther way I will send thе tаpе to аll yоur cоlleaguеs and friеnds.

Again, these messages are sheer nonsense, but might well frighten some people into paying. The criminals who are perpetrating these scams are very evil. Never respond to them, never send any money to them.


Ransomware that encrypts your data is a different kind of beast, and it is more prevalent, and easier to be affected by even if you don’t visit infected websites. Don’t open attachments from unknown senders, regardless of how innocent or official they may look. Verify first.

This is an example of a ransomware scam:

From: “Troy Almaguer” <bogusmail@bitbucket.com>
Subject: Wire Transfer
To: <redacted>

Did you authorize a wire transfer to our accounts?
We have acquired a sum of USD $2000,00 from your bank account and we do not understand what the funds are for.
We do not have any purchases with your firm that we know about. So why are you generating settlements to us?
Please see the attached remittance files and double check with your corporation and bank.
Password is 1234


[Attached Document with clickable link]

It looks really official, and an administrator, or assistant, or secretary might be easily fooled into clicking on that innocent-looking attachment. Don’t ever do it, you’ll likely end up with all your data encrypted and no way to get it back unless you have robust backups.

There are a lot of scumbags out there. Be careful, practice safe computing, and don’t let the criminals win.

The Old Wolf has spoken.