Cobalt Strike "Beacon"

Anonymous
2022-03-23T23:00:41+00:00

I received an email today, stating that someone or group had installed something called Cobalt Strike Beacon on all of my devices, and if I didn't pay they were going to release the information that they had "downloaded" to their servers. The email says it's from ******@powerapps.com Any suggestions other than to in and change all of my passwords. Who should I pass this email onto?

Thanks

Here is a partial of the email:

Greetings!<br><br> <br><br>I have to share bad news with you. Approximately a few months ago, I gained access to your devices, which you use for internet browsing. After that, I have started tracking your internet activities.<br><br> <br><br>Here is the sequence of events:<br><br> <br>Some time ago, I purchased access to email accounts from hackers (nowadays, it is quite simple to buy it online). I have easily managed to log in to your email account ******@outlook.com.<br><br> <br><br>One week later, I have already installed the Cobalt Strike "Beacon" on the Operating Systems of all the devices you use to access your email. It was not hard at all (since you were following the links from your inbox emails). All ingenious is simple. :).<br><br> <br><br>This software provides me with access to all your devices controllers (e.g., your microphone, video camera, and keyboard). <br>I have downloaded all your information, data, photos, videos, documents, files, web browsing history to my servers. I have access to all your messengers, social networks, emails, chat history, and contacts list.<br><br> <br><br>My virus continuously refreshes the signatures (it is driver-based) and hence remains invisible for antivirus software. Likewise, I guess by now you understand why I have stayed undetected until this letter.<br><br> <br><br>While gathering information about you, i have discovered that you are a big fan of adult websites. You love visiting porn websites and watching exciting videos while enduring an enormous amount of pleasure. Well, i have managed to record a number of your dirty scenes and montaged a few videos, which show how you **** and reach orgasms.<br><br> <br><br>If you have doubts, I can make a few clicks of my mouse, and all your videos will be shared with your friends, colleagues, and relatives. Considering the specificity of the videos you like to watch (you perfectly know what I mean), it will cause a real catastrophe for you.<br><br> <br>I also have no issue at all with making them available for public access (leaked and exposed all data). <br>General Data Protection Regulation (GDPR): Under the rules of the law, you face a heavy fine or arrest. <br>I guess you don't want that to happen.<br><br> <br><br>Let's settle it this way:<br><br> <br>You transfer $1821 USD to me and once the transfer is received, I will delete all this dirty stuff right away. After that, we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me. I keep my word.<br><br> <br><br>That is a fair deal, and the price is relatively low, considering that I have been checking out your profile and traffic for some time by now. If you don't know how to purchase and transfer Bitcoin - you can use any modern search engine.<br><br> <br><br>You need to send that amount here Bitcoin wallet: <br>1LXXqKrRWSnFoXnN54Rwhrx1Z8kGX3aCRr<br><br> <br><br>(The price is not negotiable). <br>You have 2 days in order to make the payment from the moment you opened this email.<br><br> <br><br>Do not try to find and destroy my virus! (All your data is already uploaded to a remote server). <br>Do not try to contact me. Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.<br><br> <br><br>This is an APT Hacking Group. Don't be mad at me, everyone has their own work. <br>I will monitor your every move until I get paid. <br>If you keep your end of the agreement, you won't hear from me ever again.<br><br> <br><br>Everything will be done fairly! <br>One more thing. Don't get caught in similar kinds of situations anymore in the future! <br>My advice: keep changing all your passwords frequently. <br> --- <br> --- <br> ---
Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-04-20T05:16:01+00:00

This is a spam template sent to a lot of email accounts designed as a scare tactic. It's fake. In two of my email accounts, I've been receiving these off and on for years, and one of those accounts is only ever accessed from a PC that has no camera.

You can safely leave them in your spam folder. Report as spam/phishing if your email provider supports it. Also use this as an opportunity to revisit passwords on old accounts and change them. When possible, also setup two-step authentication methods (linked to your cell or email address) for all sensitive accounts, especially financial.

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-03-29T14:37:37+00:00

I did absolutely nothing, and as far as I can tell no data was released. I did go through just to be safe and update all passwords, and login credentials, as some of them hadn't been changed in years.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

88 additional answers

Sort by: Most helpful
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-01-08T23:29:46+00:00

    JDB124,

    As I think you understand, my first response was directed at the most recent poster, though I always write them in a general manner to try and aid future readers.

    I understand the confusion that most people have dealing with such technical details, since along with what I just mentioned in another reply above, I spent much of my early career in network support of users including as an administrator, which gave me direct access to all of the misdirected email that often contained early versions of the same types of Spam/Scam messages (think Nigerian scam) that exist today.

    In fact, as my career progressed deeper into security, I eventually created a manual set of operations for testing an organization's susceptibility to phishing emails, which the developers in my company then worked with me to automate and sell as a service to companies and government and is still in operation today at the security services company that later purchased it.

    Based on that background, there are various truths relating to email and the malicious attacks against it that to me are obvious. One is that fixing the problems after they've occurred never works, only prevention can keep the issues from getting out of hand, since once the cat's out of the bag, there's simply no getting it back in there whatever is attempted.

    In the case of Spam of any sort, that means the only way to truly resolve this is to keep your email address close and only provide it to a trusted few, in many cases using a separate email address for less trustworthy people or organizations as a throwaway (mine actually contains this word, though I've never needed to do it), and ensure that the address doesn't get posted publicly or distributed on any sort of lists.

    Once the email address is out to the public or distributed widely to spam lists, it's too late to fix and only dropping the address and switching to another can quickly resolve that issue. If you must inherently publish the address for use in a business for example, then use a service like Microsoft's that's specifically designed for this purpose and includes the much better filtering and source server vetting processes that those like Verizon, Aol, cable companies and other non-computer communications companies don't provide.

    One way to tell how bad your situation might be is to verify whether your email address(es) have been included in any past breaches of websites or databases on the HaveIBeenPwned.com website. This is a known safe and fast lookup through the literally billions of (overlapping) known individual recorded breached identities.

    Though being on those lists doesn't automatically mean you're still at risk if you've changed passwords, it does tell you whether your personal information is potentially compromised and associated with your email address, which will only make you more popular with spammers and others due to the breadth of additional information they may have about you. If the site says, 'Oh no - Pwned!' then look below on that same page for descriptions of the breaches your address was found within and what types of data like name, address, etc. the entire world really has access to.

    Though you can't ever get that historical data back, by changing your email and dropping the old one, along with following best practices to protect the new one including good password hygiene and limiting to whom you give the new one, you can at least partially 'break' the links to you that the spam/scam message purveyors now have. If you wish, you can retain the old account for now as the 'throwaway', only truly doing that once you're sure all of your important contacts are no longer using that vs. the new one you've created.

    Also note, you should recognize from the above that the choice of an email service is really the most critical decision, since trying to patch their problems after they've broken simply doesn't work. I've had the same email address at Microsoft for exactly 20 years, initially used for dial-up and later as my email and account identity here. Though it got on spam lists early on, my careful handling of these (no opening outside Junk, etc.) meant I slowly exited most of these and to this day receive less than one true spam message a day.

    This is a good time to mention that how exactly an email app treats the preview pane or others like the Junk folder is really specific to that app. Though in general most now avoid opening things like images by default, since those can contain 'web bugs' that indicate to the sender they've been opened, the current Mail app in Windows 10 for example doesn't even display the existence of attachments for messages in the Junk folder along with images, since these messages are likely malicious and so they don't wish to allow their users to open them by mistake. That's why I stated not to remove messages from this folder unless you know they're truly 'good', since you're not protected as well if you do.

    I realized ling ago that your email account is an important part of your identity, so I treated mine as such from early on, avoiding as many pitfalls as I could and limiting not only who had access to it, but also teaching those who did not to do things like send email blasts of things like jokes with everyone's email addresses CC'd for example. I not only limit which individuals have this, but also organizations, to limit the chance I'll be involved in a breach, which so far seems to have worked. I also have the tightest security (2FA, Authenticator, multiple alternate verification methods as backup) on both that and my mobile phone accounts, since those are how your identity can most easily be stolen.

    Note that I know I'm far different from the average person with my background but doing even the most obvious and easiest of the things I've mentioned will typically avoid the worst situations. I'm truly no different than any other person now, since I'm retired and do little within the technical world other than post here. However, dropping the highly secure profile I've created to protect myself and thus the others I communicate with as well would simply be stupid, so the day I do that is the day I die or become incapacitated.

    And my identity will still be safer after that happens as a result.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-12-28T19:12:32+00:00

    Just received the same e-mail almost verbatim except for the "extortion" money desired. They wanted 2.4 Bitcoin which is about $40,000 today. Wanted to get some info on this Cobalt Strike Beacon mentioned and am so glad I did a search with Microsoft!! It is truly a scam and I also reported it to the FTC and IC3.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-11-26T12:46:37+00:00

    Hi members! I justa have recive an identical email

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments