Cobalt Strike "Beacon"

Anonymous
2022-03-23T23:00:41+00:00

I received an email today, stating that someone or group had installed something called Cobalt Strike Beacon on all of my devices, and if I didn't pay they were going to release the information that they had "downloaded" to their servers. The email says it's from ******@powerapps.com Any suggestions other than to in and change all of my passwords. Who should I pass this email onto?

Thanks

Here is a partial of the email:

Greetings!<br><br> <br><br>I have to share bad news with you. Approximately a few months ago, I gained access to your devices, which you use for internet browsing. After that, I have started tracking your internet activities.<br><br> <br><br>Here is the sequence of events:<br><br> <br>Some time ago, I purchased access to email accounts from hackers (nowadays, it is quite simple to buy it online). I have easily managed to log in to your email account ******@outlook.com.<br><br> <br><br>One week later, I have already installed the Cobalt Strike "Beacon" on the Operating Systems of all the devices you use to access your email. It was not hard at all (since you were following the links from your inbox emails). All ingenious is simple. :).<br><br> <br><br>This software provides me with access to all your devices controllers (e.g., your microphone, video camera, and keyboard). <br>I have downloaded all your information, data, photos, videos, documents, files, web browsing history to my servers. I have access to all your messengers, social networks, emails, chat history, and contacts list.<br><br> <br><br>My virus continuously refreshes the signatures (it is driver-based) and hence remains invisible for antivirus software. Likewise, I guess by now you understand why I have stayed undetected until this letter.<br><br> <br><br>While gathering information about you, i have discovered that you are a big fan of adult websites. You love visiting porn websites and watching exciting videos while enduring an enormous amount of pleasure. Well, i have managed to record a number of your dirty scenes and montaged a few videos, which show how you **** and reach orgasms.<br><br> <br><br>If you have doubts, I can make a few clicks of my mouse, and all your videos will be shared with your friends, colleagues, and relatives. Considering the specificity of the videos you like to watch (you perfectly know what I mean), it will cause a real catastrophe for you.<br><br> <br>I also have no issue at all with making them available for public access (leaked and exposed all data). <br>General Data Protection Regulation (GDPR): Under the rules of the law, you face a heavy fine or arrest. <br>I guess you don't want that to happen.<br><br> <br><br>Let's settle it this way:<br><br> <br>You transfer $1821 USD to me and once the transfer is received, I will delete all this dirty stuff right away. After that, we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me. I keep my word.<br><br> <br><br>That is a fair deal, and the price is relatively low, considering that I have been checking out your profile and traffic for some time by now. If you don't know how to purchase and transfer Bitcoin - you can use any modern search engine.<br><br> <br><br>You need to send that amount here Bitcoin wallet: <br>1LXXqKrRWSnFoXnN54Rwhrx1Z8kGX3aCRr<br><br> <br><br>(The price is not negotiable). <br>You have 2 days in order to make the payment from the moment you opened this email.<br><br> <br><br>Do not try to find and destroy my virus! (All your data is already uploaded to a remote server). <br>Do not try to contact me. Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.<br><br> <br><br>This is an APT Hacking Group. Don't be mad at me, everyone has their own work. <br>I will monitor your every move until I get paid. <br>If you keep your end of the agreement, you won't hear from me ever again.<br><br> <br><br>Everything will be done fairly! <br>One more thing. Don't get caught in similar kinds of situations anymore in the future! <br>My advice: keep changing all your passwords frequently. <br> --- <br> --- <br> ---
Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-04-20T05:16:01+00:00

This is a spam template sent to a lot of email accounts designed as a scare tactic. It's fake. In two of my email accounts, I've been receiving these off and on for years, and one of those accounts is only ever accessed from a PC that has no camera.

You can safely leave them in your spam folder. Report as spam/phishing if your email provider supports it. Also use this as an opportunity to revisit passwords on old accounts and change them. When possible, also setup two-step authentication methods (linked to your cell or email address) for all sensitive accounts, especially financial.

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-03-29T14:37:37+00:00

I did absolutely nothing, and as far as I can tell no data was released. I did go through just to be safe and update all passwords, and login credentials, as some of them hadn't been changed in years.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

88 additional answers

Sort by: Newest
  1. Anonymous
    2023-01-11T20:12:37+00:00

    via ironbranchhq.onmicrosoft.com  clearly an inside job, how do you think this company's like Google, Facebook Twitter and Microsoft make millions wake up people!

    Was this answer helpful?

    0 comments No comments
  2. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-01-11T18:08:48+00:00

    No name was inserted. Just "support@my actual email domain.com" in the from address field. No malware was detected on my PC and laptop by Norton. The message text spoof was fairly obvious. What surprised me was the inclusion of my email domain in the from address.

    Baby-it's-cold-outside,

    Spoofing the from address field in messages is no more difficult than any other field including the text, since their messages are most often sent from severs that aren't connected with any major email service, so the email services they use are specifically designed not to follow the technical validation and other requirements that the normal services do.

    Putting your own address in the From field is the more common method, they just took this a step further and used the "support" name instead to make it seem more official, which you can see from your own surprise had precisely the psychological effect they had intended.

    I spent several years making similar messages for organizations to perform phishing tests on their employees and there are literally an unlimited number of such mental tricks that can be used on the average person, since few look at messages with the same critical eye as someone like myself. The message that began this thread has literally dozens of red flags, but only a tiny handful of people can actually recognize them.

    Rob

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-01-11T16:08:43+00:00

    No name was inserted. Just "support@my actual email domain.com" in the from address field. No malware was detected on my PC and laptop by Norton. The message text spoof was fairly obvious. What surprised me was the inclusion of my email domain in the from address.

    Was this answer helpful?

    0 comments No comments