[Heads-up] Sextortion Crime Gang Now Uses New Tactics To Bypass Your Spam Filters



google-translateIn a business environment, employees use Google Translate on a regular basis to get access to documents they need to work with, or websites that are in another language.

Now, a sextortion crime gang is using new tactics to bypass your spam filters and secure email gateways so that their criminal emails are delivered to your users.

Sextortion scams usually state that bad guys have hacked your employee's workstation and that and they can monitor the sites that were visited and record the webcam.

Then, they claim to have a video of the employee watching adult websites and will send the video to all contacts unless the extortion amount is paid. It's a common scam and today's filters and gateways are pretty good in blocking that crap.

However...There Is A New Evasion Tactic That Uses Social Engineering

To bypass your filters, attackers have started to use a new tactic. They send sextortion emails in foreign languages and split bitcoin addresses into two parts.

This is illustrated in a new sextortion email shared with BleepingComputer where the scammers are sending the scam emails to English-speaking users but with the content written in Russian. As can be seen in the email above , the only text in English is the instructions to "Use google translator."

In addition to using a foreign language when targeting English speaking users, the scammers also break up the bitcoin address into two parts.They then provide instructions to combine the two parts to create the actual bitcoin address where an extortion payment should be sent to.

Adding these two tactics make it a bit more difficult for the recipient to understand what they are receiving, but the attackers are hoping that the potential evasion capabilities outweigh the complexity of translating the message.

As you and I know, some users will watch adult websites using the company network. Yes, there are your gateways and block lists, but they are always just a bit behind. Worst case design, a sextortion email reaches one of those never-do-well employees and they can get pretty desperate to keep their job. It's an easy path into your network because the bad guys now have leverage.  

Step all your users through new-school security awareness training to head off these black hats at the pass. Start with a free Phishing Security Test ... now in 20+ languages.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews