Cobalt Strike "Beacon"

Anonymous
2022-03-23T23:00:41+00:00

I received an email today, stating that someone or group had installed something called Cobalt Strike Beacon on all of my devices, and if I didn't pay they were going to release the information that they had "downloaded" to their servers. The email says it's from ******@powerapps.com Any suggestions other than to in and change all of my passwords. Who should I pass this email onto?

Thanks

Here is a partial of the email:

Greetings!<br><br> <br><br>I have to share bad news with you. Approximately a few months ago, I gained access to your devices, which you use for internet browsing. After that, I have started tracking your internet activities.<br><br> <br><br>Here is the sequence of events:<br><br> <br>Some time ago, I purchased access to email accounts from hackers (nowadays, it is quite simple to buy it online). I have easily managed to log in to your email account ******@outlook.com.<br><br> <br><br>One week later, I have already installed the Cobalt Strike "Beacon" on the Operating Systems of all the devices you use to access your email. It was not hard at all (since you were following the links from your inbox emails). All ingenious is simple. :).<br><br> <br><br>This software provides me with access to all your devices controllers (e.g., your microphone, video camera, and keyboard). <br>I have downloaded all your information, data, photos, videos, documents, files, web browsing history to my servers. I have access to all your messengers, social networks, emails, chat history, and contacts list.<br><br> <br><br>My virus continuously refreshes the signatures (it is driver-based) and hence remains invisible for antivirus software. Likewise, I guess by now you understand why I have stayed undetected until this letter.<br><br> <br><br>While gathering information about you, i have discovered that you are a big fan of adult websites. You love visiting porn websites and watching exciting videos while enduring an enormous amount of pleasure. Well, i have managed to record a number of your dirty scenes and montaged a few videos, which show how you **** and reach orgasms.<br><br> <br><br>If you have doubts, I can make a few clicks of my mouse, and all your videos will be shared with your friends, colleagues, and relatives. Considering the specificity of the videos you like to watch (you perfectly know what I mean), it will cause a real catastrophe for you.<br><br> <br>I also have no issue at all with making them available for public access (leaked and exposed all data). <br>General Data Protection Regulation (GDPR): Under the rules of the law, you face a heavy fine or arrest. <br>I guess you don't want that to happen.<br><br> <br><br>Let's settle it this way:<br><br> <br>You transfer $1821 USD to me and once the transfer is received, I will delete all this dirty stuff right away. After that, we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me. I keep my word.<br><br> <br><br>That is a fair deal, and the price is relatively low, considering that I have been checking out your profile and traffic for some time by now. If you don't know how to purchase and transfer Bitcoin - you can use any modern search engine.<br><br> <br><br>You need to send that amount here Bitcoin wallet: <br>1LXXqKrRWSnFoXnN54Rwhrx1Z8kGX3aCRr<br><br> <br><br>(The price is not negotiable). <br>You have 2 days in order to make the payment from the moment you opened this email.<br><br> <br><br>Do not try to find and destroy my virus! (All your data is already uploaded to a remote server). <br>Do not try to contact me. Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.<br><br> <br><br>This is an APT Hacking Group. Don't be mad at me, everyone has their own work. <br>I will monitor your every move until I get paid. <br>If you keep your end of the agreement, you won't hear from me ever again.<br><br> <br><br>Everything will be done fairly! <br>One more thing. Don't get caught in similar kinds of situations anymore in the future! <br>My advice: keep changing all your passwords frequently. <br> --- <br> --- <br> ---
Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-04-20T05:16:01+00:00

This is a spam template sent to a lot of email accounts designed as a scare tactic. It's fake. In two of my email accounts, I've been receiving these off and on for years, and one of those accounts is only ever accessed from a PC that has no camera.

You can safely leave them in your spam folder. Report as spam/phishing if your email provider supports it. Also use this as an opportunity to revisit passwords on old accounts and change them. When possible, also setup two-step authentication methods (linked to your cell or email address) for all sensitive accounts, especially financial.

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-03-29T14:37:37+00:00

I did absolutely nothing, and as far as I can tell no data was released. I did go through just to be safe and update all passwords, and login credentials, as some of them hadn't been changed in years.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

88 additional answers

Sort by: Newest
  1. Anonymous
    2022-08-23T16:49:20+00:00

    Thank you Michael for the tips.

    I have changed all my passwords and set a reminder the change every couple months. I also got a security key for google it does not work with Microsoft, but I did do the 2 factor verifications on most of my sites. Also I did report the email to FCC IC3 and Our Attorney Generals office which they were aware of this scam. At least maybe other people will not fall for this.

    Thank you and have a great week!

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-08-21T13:46:40+00:00

    As others have posted here, this particular email is a known scam. Sad, isn't it, that there are people who view breaching the web of trust between people that is all that makes it possible for us to function at any level beyond "every man for himself" as nothing more than a business model?

    This one is a scam, and so are many others similar to it. That said, however, there are people who do this kind of thing "for real.: Most often, they are aiming at businesses - healthcare organizations are a particular favorite - and most often, they notify victims not by email, but by popping up a screen after encrypting all their files. But I imagine that private individuals occasionally get hit, too.

    Here are a few things you can do for your "peace of mind":

    (1) Use good "Password hygiene." Do not re-use passwords, either between websites or repeatedly on the same website. It's a pain having a lot of passwords to remember, but using a good password manager program takes the pain out of that. Use STRONG passwords (a password manager can generate them for you). Change them periodically - I try to do this every three months or so.

    (2) If it is available, enable 2-factor authentication on your email, and for that matter, anywhere else you log in - your bank, amazon.com, etc. This means that when you log in, a message will be sent to your phone, giving you a one-time numeric code you must also enter to log in. This way, even if a hacker gets your password, they can't get into your account without that code that goes to YOUR phone not theirs. 2-factor authentication isn't perfect - there are ways to defeat it - but hackers are generally looking for the "easy targets," and using it makes you a less easy target.

    (3) If you're using Microsoft outlook, you can check the history of successful logins by clicking on the little round avatar of your account in the upper-right corner; then clicking "my microsoft account"; then clicking "security"; then clicking "see your sign-in activity." All of your log-ins should be recorded here, with the town or city from which you logged in and a notation of "successful" or "unsuccessful." Look for any locations you don't recognize, and make sure that they are "unsuccessful." I will say that it's a little unsettling to see that there actually ARE attempts to log into my account from places like Russia, China, Indonesia, and occasionally from other cities here in the United States! But it's reassuring to see that they are unsuccessful. I will note, however, that you can't entirely trust the locations that are reported, since hackers can sometimes hide their locations by hacking into a distant computer and then trying to log into your account from that, or by attempting to do their dirty work through a VPN or proxy server.

    (4) Reporting the attempted extortion attempt to the FCC and/or the IC3, of course, doesn't help...but don't hold your breath. While those groups would surely be pleased if they could put a stop to this sort of crime, the criminals are almost certainly located in a country which turns a blind eye to such shenanigans, as long as the criminals do not attack computers located in that country.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-08-07T15:29:07+00:00

    My advice is to ignore the email. I did. It is a scam. I like to believe reporting this stuff helps. I've not had any further incidents.

    Was this answer helpful?

    9 people found this answer helpful.
    0 comments No comments