Campaña de chantaje DDoS por email
ANÁLISIS
Se ha observado un envío masivo a múltiples direcciones de correo con una amenaza de DDoS para la cual se exige un pago por bitcoin para evitar el ataque.
El formato identificado es el siguiente:
- Asunto: Your website XXX has been hacked
- De: XXX@coronaxy.com
- Cuerpo:
We are the Cozy Bear and we have chosen your company as target for our next DDoS attack. Please perform a google search for "Cozy Bear" to have a look at some of our previous work. Your network will be subject to a DDoS attack starting at 2020 November 2nd (Monday). THIS IS NOT A JOKE, and to prove it right now we will start a small attack on XXX that will last for 30 minutes. It will not be heavy attack, at this moment. What does this mean? This means that your website and other connected services will be unavailable for everyone. Please also note that this will severely damage your reputation amongst your users / customers. How to stop this? We are willing to refrain from attacking your servers for a small fee. The current fee is $1150(USD) in bitcoins (BTC). The fee will increase by 1000 USD for each day after 2020 November 2nd that has passed without payment. Please send Bitcoin to the following Bitcoin address (cAsE-SeNsitIve): XXXXXX You can easily buy bitcoins via several websites or even offline from a Bitcoin-ATM. We suggest you coinmama.com or buy.coingate.com for buying bitcoins. Once you have paid we will automatically get informed that it was your payment. Please note that you have to make payment before the deadline (2020 November 2nd ) or the attack WILL start! What if you don't pay? ----- -- Cozy Bear team
Dichos mensajes han sido catalogados como falsas amenazas de chantaje.
RECOMENDACIONES
Se debe evitar contestar a este tipo de mensajes. Tampoco se debe pagar ningún tipo de rescate a las direcciones proporcionadas.
Bloquear los IOCs proporcionados y eliminar dichos emails.
Notificar a los empleados de la organización del timo que se está llevando a cabo, concienciando y llamando a desconfiar de interacciones similares.
IOCs
coronaxy[.]com
185.198.58[.]92