Cobalt Strike "Beacon"

Anonymous
2022-03-23T23:00:41+00:00

I received an email today, stating that someone or group had installed something called Cobalt Strike Beacon on all of my devices, and if I didn't pay they were going to release the information that they had "downloaded" to their servers. The email says it's from ******@powerapps.com Any suggestions other than to in and change all of my passwords. Who should I pass this email onto?

Thanks

Here is a partial of the email:

Greetings!<br><br> <br><br>I have to share bad news with you. Approximately a few months ago, I gained access to your devices, which you use for internet browsing. After that, I have started tracking your internet activities.<br><br> <br><br>Here is the sequence of events:<br><br> <br>Some time ago, I purchased access to email accounts from hackers (nowadays, it is quite simple to buy it online). I have easily managed to log in to your email account ******@outlook.com.<br><br> <br><br>One week later, I have already installed the Cobalt Strike "Beacon" on the Operating Systems of all the devices you use to access your email. It was not hard at all (since you were following the links from your inbox emails). All ingenious is simple. :).<br><br> <br><br>This software provides me with access to all your devices controllers (e.g., your microphone, video camera, and keyboard). <br>I have downloaded all your information, data, photos, videos, documents, files, web browsing history to my servers. I have access to all your messengers, social networks, emails, chat history, and contacts list.<br><br> <br><br>My virus continuously refreshes the signatures (it is driver-based) and hence remains invisible for antivirus software. Likewise, I guess by now you understand why I have stayed undetected until this letter.<br><br> <br><br>While gathering information about you, i have discovered that you are a big fan of adult websites. You love visiting porn websites and watching exciting videos while enduring an enormous amount of pleasure. Well, i have managed to record a number of your dirty scenes and montaged a few videos, which show how you **** and reach orgasms.<br><br> <br><br>If you have doubts, I can make a few clicks of my mouse, and all your videos will be shared with your friends, colleagues, and relatives. Considering the specificity of the videos you like to watch (you perfectly know what I mean), it will cause a real catastrophe for you.<br><br> <br>I also have no issue at all with making them available for public access (leaked and exposed all data). <br>General Data Protection Regulation (GDPR): Under the rules of the law, you face a heavy fine or arrest. <br>I guess you don't want that to happen.<br><br> <br><br>Let's settle it this way:<br><br> <br>You transfer $1821 USD to me and once the transfer is received, I will delete all this dirty stuff right away. After that, we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me. I keep my word.<br><br> <br><br>That is a fair deal, and the price is relatively low, considering that I have been checking out your profile and traffic for some time by now. If you don't know how to purchase and transfer Bitcoin - you can use any modern search engine.<br><br> <br><br>You need to send that amount here Bitcoin wallet: <br>1LXXqKrRWSnFoXnN54Rwhrx1Z8kGX3aCRr<br><br> <br><br>(The price is not negotiable). <br>You have 2 days in order to make the payment from the moment you opened this email.<br><br> <br><br>Do not try to find and destroy my virus! (All your data is already uploaded to a remote server). <br>Do not try to contact me. Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.<br><br> <br><br>This is an APT Hacking Group. Don't be mad at me, everyone has their own work. <br>I will monitor your every move until I get paid. <br>If you keep your end of the agreement, you won't hear from me ever again.<br><br> <br><br>Everything will be done fairly! <br>One more thing. Don't get caught in similar kinds of situations anymore in the future! <br>My advice: keep changing all your passwords frequently. <br> --- <br> --- <br> ---
Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-04-20T05:16:01+00:00

This is a spam template sent to a lot of email accounts designed as a scare tactic. It's fake. In two of my email accounts, I've been receiving these off and on for years, and one of those accounts is only ever accessed from a PC that has no camera.

You can safely leave them in your spam folder. Report as spam/phishing if your email provider supports it. Also use this as an opportunity to revisit passwords on old accounts and change them. When possible, also setup two-step authentication methods (linked to your cell or email address) for all sensitive accounts, especially financial.

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-03-29T14:37:37+00:00

I did absolutely nothing, and as far as I can tell no data was released. I did go through just to be safe and update all passwords, and login credentials, as some of them hadn't been changed in years.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

88 additional answers

Sort by: Newest
  1. Anonymous
    2023-01-08T20:06:46+00:00

    Hello Rob,

    as you said you should never answer that kind of stupid and only report it to the local authorities, just because it means that your email adress is valid.

    But I am Belgian living in Brussels Europe and my native language is french.

    I have reported this message to the Belgian Crime Unit at ******@safeonweb.be, when no virus has been found nothing happens, just an answer like "thank you for having forwarded this message" but last month I have received about another sender a response that went like "we cannot treat this email because it contains a malware/virus file".

    So I deleted it immediately.

    Thanks for your support.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-01-08T04:50:04+00:00

    Rob:

    I genuinely appreciate your informative response. I posted the comment below after receiving a Cobalt Strike "Beacon" email twice in the same day back in June 2022:

    "This happened to me a couple years ago. I knew it was spam, but I found it very offensive and rude, so I reported it to the Internet Crime Complaint Center (IC3). There is a simple online form you can fill out to file a complaint. It will make you feel like a responsible citizen - see something, say something - for a minute or two."

    After reviewing all the posts about this issue is when I stopped opening and "unsubscribing" to the spam emails I was receiving and started pushing the spam that made it into my inbox directly into my blocked mail folder without opening it. Although I have not received any more threatening emails like the Colbalt Strike Beacon I still have problems with spam, despite implementing all the actions for handling spam mail you mention in your response.

    Since you sound like you know what you are doing, I thought I would run a couple of questions your way (and the way of anyone else who can provide help). Bear with me, the second question requires a bit of a set up:

    • Is the use of a preview pane the same as clicking on an email to open it?
    • I use Outlook on my desktop (not Outlook.com) to send and receive email messages using my primary verizon.net email account. I also have a gmail and a yahoo email address that I access less frequently on gmail.com and rarely on yahoo.com, respectively (not on Outlook or Outlook.com). I have had my verizon.net email account since the beginning of email and have done what I needed to do (like I had a choice) over the years to survive the transitions from Verizon to AoL to Yahoo to Apollo Global Management. But of late, the spam mail has gotten out of control. Several times a day, using Outlook, I move spam from my inbox to my bulk mail folder, check my bulk mail folder for emails that need to move back to my Inbox before emptying my bulk mail folder. A couple of months ago, it occurred to me to try to stop the spam using the AoL account that I had to set up to continue using my verizon.net email address. On AoL, I could move the spam to the Junk mail folder and had the option to block the emails at the same time. However, there was a limit of 1,000 email addresses I could add to the blocked list. I reached that limit in a week. So, now I am back to using Outlook's Bulk mail. I understand that at some point in time I clicked on a link or links to something I shouldn't have and am not looking for an explanation of how this happened. I need a practical method to put a stop the onslaught of spam about CBD Gummies, African Manhood, Big Stomach, Hair Regrowth, Space Heaters, Diabetes, Timeshares, Horoscopes, Order Deliveries of stuff I never ordered, all the prizes I have won, and whatever this is 🚨 𝐏𝐫𝐨𝐬𝐭𝐚𝐭𝐞 𝐃𝐢𝐬𝐜𝐨𝐯𝐞𝐫ð, once and for all. Any suggestions?

    Was this answer helpful?

    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-01-07T20:39:39+00:00

    The email is completely fake:

    Scam emails demand Bitcoin, threaten blackmail | Consumer Advice

    Avoid Scams - Bitcoin

    Never reply to such spam or scam messages, if the address they sent from is even valid, it typically belongs to someone else and at best this will tell the spam/scammer that your address is active and available to send more junk mail to.

    The permanent failure was due to the fact the mailbox used to send the scam messages was disabled by the email provider, since all the major email providers cooperate by automatically reporting these to each other and getting them shut down long before most individual users typically manage to report them manually.

    If you found your copy pf this scam message in your Junk or Spam email folder, leave it there. That means your email provider already determined it was a spam/scam, but to be safe they always forward a copy to you in case their automated detection systems had a hiccup and incorrectly identified a message you truly want as spam. Your action of moving the message out of the Junk/Spam folder tells their systems that this action was incorrect, which means you're just providing invalid information and doing nothing to help.

    For this same reason, using the Oulook.com 'Mark as Junk' selection or similar Junk or Spam selections for an Inbox message in other email apps not only typically moves the message to your Junk folder, but it also automatically reports this 'bad' message to your email provider, which is far faster and simpler than looking up some obscure 3rd-party website or address to submit it by hand. In fact, since the in-app Mark as Junk or similar methods also include the full (hidden) email message headers your provider needs to properly identify the true source and path the message took to get into your mailbox, there's really no better way for the typical consumer to do this.

    All other manual methods used to report, especially those to national organizations like the US FTC are really just 'catch-all', feel good repositories that collect these as a way to tell how prevalent the problem is, they really do nothing to solve the true problem or shut down the mailboxes being abused by the spammers.

    Rob

    Was this answer helpful?

    0 comments No comments