‘Bomb threat’ scammers are now threatening to throw acid on victims

0
125

0

Thursday’s massive spam campaign that sent bomb threats to hundreds of thousands of users across the US and Canada, and caused evacuations of buildings across several cities, was carried out by the same group of spammers responsible for the recent wave of sextortion scams, two cyber-security firms said on Friday.

“Multiple IPs involved in sending these bomb threats also sent various types of sextortion email that we saw in the previous campaign,” said Jaeson Schultz of Cisco Talos.

According to AppRiver, the bomb threat emails and the older sextortion campaigns all came from the 194.58.X.X IP space.

The bomb threats send on Thursday tried to scare users by threating to detonate a bomb at their workplace if the victim didn’t pay $20,000 worth of Bitcoin within a few hours.

The spammers behind this campaign stopped sending bomb threats on Friday, most likely realizing that this campaign won’t yield any results, especially after the FBI, the police, and the media told everyone to ignore the threats and not pay the ransom demand.

And according to Cisco Talos, no one did. Schultz said that Talos discovered 17 Bitcoin addresses inside the bomb threat extortion emails, but none held any money.

“Only two of the addresses have a positive balance, both from transactions received Dec. 13, the day the attacks were distributed,” Schultz said. “However, the amounts of each transaction were under $1, so it is evident the victims in this case declined to pay the $20,000 extortion payment price demanded by the attackers.”

But the spammers have not given up. Talos said that as soon as their bomb threat campaign appeared to hit a dead end, the group switched to another one.

“The attackers have returned to their empty threats of harming the individual recipient,” Schultz said. “This time, they threaten to throw acid on the victim.” A copy of an email carrying this latest threat is available below.

spam-acid-threat.png
Image:Cisco Talos

In October, another Cisco Talos report revealed that the group behind this week’s bomb threats, at that time operating using the “sextortion” scheme, made $146,380 in just three days’ work.

More cybersecurity coverage:

Facebook bug exposed private photos of 6.8 million usersSignal: We can’t include a backdoor in our app for the Australian governmentLogitech app security flaw allowed keystroke injection attacksSQLite bug impacts thousands of apps, including all Chromium-based browsersBing recommends piracy tutorial when searching for Office 2019Shamoon malware destroys data at Italian oil and gas companyHow to enable spam call filtering on your Android phone TechRepublicNew antiphishing features come to Google G Suite CNET

Related Topics:

Security TV

Data Management

CXO

Data Centers

0