KnowBe4 Security Awareness Training Blog

[Heads-up] Sextortion Crime Gang Now Uses New Tactics To Bypass Your Spam Filters

Written by Stu Sjouwerman | Jan 3, 2020 12:00:00 PM

In a business environment, employees use Google Translate on a regular basis to get access to documents they need to work with, or websites that are in another language.

Now, a sextortion crime gang is using new tactics to bypass your spam filters and secure email gateways so that their criminal emails are delivered to your users.

Sextortion scams usually state that bad guys have hacked your employee's workstation and that and they can monitor the sites that were visited and record the webcam.

Then, they claim to have a video of the employee watching adult websites and will send the video to all contacts unless the extortion amount is paid. It's a common scam and today's filters and gateways are pretty good in blocking that crap.

However...There Is A New Evasion Tactic That Uses Social Engineering

To bypass your filters, attackers have started to use a new tactic. They send sextortion emails in foreign languages and split bitcoin addresses into two parts.

This is illustrated in a new sextortion email shared with BleepingComputer where the scammers are sending the scam emails to English-speaking users but with the content written in Russian. As can be seen in the email above , the only text in English is the instructions to "Use google translator."

In addition to using a foreign language when targeting English speaking users, the scammers also break up the bitcoin address into two parts.They then provide instructions to combine the two parts to create the actual bitcoin address where an extortion payment should be sent to.

Adding these two tactics make it a bit more difficult for the recipient to understand what they are receiving, but the attackers are hoping that the potential evasion capabilities outweigh the complexity of translating the message.

As you and I know, some users will watch adult websites using the company network. Yes, there are your gateways and block lists, but they are always just a bit behind. Worst case design, a sextortion email reaches one of those never-do-well employees and they can get pretty desperate to keep their job. It's an easy path into your network because the bad guys now have leverage.  

Step all your users through new-school security awareness training to head off these black hats at the pass. Start with a free Phishing Security Test ... now in 20+ languages.