2023年5月12日 星期五

詐騙勒索郵件攻擊:您有一筆未結付款。 (You have an outstanding payment.)

本文介紹的惡意郵件是屬於社交勒索詐騙攻擊的一種,目的是藉由使用者的對駭客攻擊的害怕心理,以騙取金錢,本文會去除惡意郵件中所有連結與隱私訊息。


收到此類郵件,建議直接無視,它主要是用亂槍打鳥的方式,欺騙使用者。

另外建議電腦的 Webcam 應安裝隱私配件,避免被惡意擷取影像。


這封惡意郵件跟之前英文版極為類似,可以算是改進版本,有興趣可以看一下之前的英文版:http://blog.esafe360.com/2023/04/blog-post_11.html


這次的更新版本中,提供了更加可信的資訊:

1. 入侵方式的說明改為了由郵件入侵。

2. 提供了更加明確的操作建議。


以下是郵件的原始內文與 Google 翻譯結果。

====================================

Hello there!


Unfortunately, there are some bad news for you.

Around several months ago I have obtained access to your devices that you were using to browse internet.

Subsequently, I have proceeded with tracking down internet activities of yours.


Below, is the sequence of past events: 

In the past, I have bought access from hackers to numerous email accounts (today, that is a very straightforward task that can be done online).

Clearly, I have effortlessly logged in to email account of yours (xxxxxx@xxxxxxx.xxx).


A week after that, I have managed to install Trojan virus to Operating Systems of all your devices that are used for email access.

Actually, that was quite simple (because you were clicking the links in inbox emails).

All smart things are quite straightforward. (>__<)


The software of mine allows me to access to all controllers in your devices, such as video camera, microphone and keyboard.

I have managed to download all your personal data, as well as web browsing history and photos to my servers.

I can access all messengers of yours, as well as emails, social networks, contacts list and even chat history.

My virus unceasingly refreshes its signatures (since it is driver-based), and hereby stays invisible for your antivirus.


So, by now you should already understand the reason why I remained unnoticed until this very moment...


While collecting your information, I have found out that you are also a huge fan of websites for adults.

You truly enjoy checking out porn websites and watching dirty videos, while having a lot of kinky fun.

I have recorded several kinky scenes of yours and montaged some videos, where you reach orgasms while passionately masturbating.


If you still doubt my serious intentions, it only takes couple mouse clicks to share your videos with your friends, relatives and even colleagues.

It is also not a problem for me to allow those vids for access of public as well.

I truly believe, you would not want this to occur, understanding how special are the videos you love watching, (you are clearly aware of that) all that stuff can result in a real disaster for you.


Let's resolve it like this:

All you need is $1350 USD transfer to my account (bitcoin equivalent based on exchange rate during your transfer), and after the transaction is successful, I will proceed to delete all that kinky stuff without delay.

Afterwards, we can pretend that we have never met before. In addition, I assure you that all the harmful software will be deleted from all your devices. Be sure, I keep my promises.


That is quite a fair deal with a low price, bearing in mind that I have spent a lot of effort to go through your profile and traffic for a long period.

If you are unaware how to buy and send bitcoins - it can be easily fixed by searching all related information online.


Below is bitcoin wallet of mine: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


You are given not more than 48 hours after you have opened this email (2 days to be precise).


Below is the list of actions that you should not attempt doing:

> Do not attempt to reply my email (the email in your inbox was created by me together with return address).

> Do not attempt to call police or any other security services. Moreover, don't even think to share this with friends of yours. Once I find that out (make no doubt about it, I can do that effortlessly, bearing in mind that I have full control over all your systems) - the video of yours will become available to public immediately. 

> Do not attempt to search for me - there is completely no point in that. All cryptocurrency transactions remain anonymous at all times.

> Do not attempt reinstalling the OS on devices of yours or get rid of them. It is meaningless too, because all your videos are already available at remote servers.


Below is the list of things you don't need to be concerned about:

> That I will not receive the money you transferred.

- Don't you worry, I can still track it, after the transaction is successfully completed, because I still monitor all your activities (trojan virus of mine includes a remote-control option, just like TeamViewer).

> That I still will make your videos available to public after your money transfer is complete.

- Believe me, it is meaningless for me to keep on making your life complicated. If I indeed wanted to make it happen, it would happen long time ago! 


Everything will be carried out based on fairness!


Before I forget...moving forward try not to get involved in this kind of situations anymore!

An advice from me - regularly change all the passwords to your accounts.


====================================


你好呀!


不幸的是,有一些壞消息要告訴你。

大約幾個月前,我獲得了您用來瀏覽互聯網的設備的訪問權限。

隨後,我開始追踪您的互聯網活動。


以下是過去事件的順序:

過去,我從黑客那裡購買了大量電子郵件帳戶的訪問權(如今,這是一項非常簡單的任務,可以在線完成)。

顯然,我已經毫不費力地登錄到您的電子郵件帳戶 (xxxxxx@xxxxxxx.xxx)。


一周後,我設法將特洛伊木馬病毒安裝到您所有用於訪問電子郵件的設備的操作系統中。

實際上,這很簡單(因為您單擊了收件箱電子郵件中的鏈接)。

所有聰明的事情都非常簡單。 (>__<)


我的軟件允許我訪問您設備中的所有控制器,例如攝像機、麥克風和鍵盤。

我已設法將您的所有個人數據以及網絡瀏覽歷史記錄和照片下載到我的服務器。

我可以訪問您的所有 Messenger,以及電子郵件、社交網絡、聯繫人列表甚至聊天記錄。

我的病毒不斷刷新其簽名(因為它是基於驅動程序的),因此對您的防病毒軟件不可見。


所以,你現在應該已經明白,為什麼我一直到現在都沒有被人注意了吧……


在收集您的信息時,我發現您也是成人網站的忠實粉絲。

您真的很喜歡查看色情網站和觀看色情視頻,同時享受很多變態的樂趣。

我已經錄製了你的幾個變態場景並剪輯了一些視頻,你在這些視頻中熱情地自慰時達到了性高潮。


如果您仍然懷疑我的認真意圖,只需點擊幾下鼠標即可與您的朋友、親戚甚至同事分享您的視頻。

允許公眾訪問這些視頻對我來說也不是問題。

我真的相信,你不希望發生這種情況,了解你喜歡看的視頻有多麼特別,(你清楚地意識到這一點)所有這些都會給你帶來真正的災難。


讓我們這樣解決:

您只需要將 1350 美元轉賬到我的賬戶(根據您轉賬時的匯率計算等值比特幣),交易成功後,我會立即刪除所有這些變態內容。

之後,我們可以假裝我們以前從未見過面。 此外,我向您保證,所有有害軟件都將從您的所有設備中刪除。 放心,我信守諾言。


這是一個低價的公平交易,請記住,我花了很多精力很長一段時間來瀏覽您的個人資料和流量。

如果您不知道如何購買和發送比特幣 - 可以通過在線搜索所有相關信息輕鬆解決。


下面是我的比特幣錢包:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


打開此電子郵件後,您將在 48 小時內(準確地說是 2 天)收到通知。


以下是您不應嘗試執行的操作列表:

> 不要試圖回复我的電子郵件(您收件箱中的電子郵件是我創建的,連同回信地址)。

> 不要試圖打電話給警察或任何其他安全部門。 此外,甚至不要想與您的朋友分享。 一旦我發現了這一點(毫無疑問,我可以毫不費力地做到這一點,請記住我可以完全控制您的所有系統)- 您的視頻將立即公開。

> 不要試圖尋找我——那完全沒有意義。 所有加密貨幣交易始終保持匿名。

> 不要嘗試在您的設備上重新安裝操作系統或刪除它們。 這也毫無意義,因為您所有的視頻都已經在遠程服務器上可用。


以下是您不需要關心的事項列表:

> 那我不會收到你轉賬的錢。

- 別擔心,我仍然可以跟踪它,在交易成功完成後,因為我仍然監視你的所有活動(我的木馬病毒包括一個遠程控制選項,就像 TeamViewer)。

> 在您的匯款完成後,我仍然會公開您的視頻。

- 相信我,繼續讓你的生活變得複雜對我來說毫無意義。 如果我真的想讓它發生,它早就發生了!


一切都將在公平的基礎上進行!


在我忘記之前......繼續前進,盡量不要再捲入這種情況!

我的建議 - 定期更改您帳戶的所有密碼。


====================================



沒有留言:

張貼留言