- The company’s executives received an extortion letter by mail
- Claims to have come from Ransomware Bianlian operators
- The senders warned about stealing the company’s sensitive files
The world of security seems to have closed the circle, since spam mail has once again been physical with scammers sending its victims mail of Caracol.
Cybersecury Outlet Guidepoint recently found a couple of these letters sent to the members of the executive team of the target organization.
The letters are not their typical extinct spam, but claim to have been sent by the Bianlian Ransomware group.
There is no ransomware
“I regret to inform you that we have obtained access to [REDACTED] The systems and in recent weeks have exported thousands of data files, including ordering information and customer contact, employee information with IDS, SSN, payroll reports and other confidential documents of human resources, financial documents of the company, legal documents, investor and shareholders information, invoices and fiscal documents, “says the letter.
“His network is insecure and we could get access and intercept the traffic of his network, take advantage of his personal email address, passwords, online accounts and other information for the social engineer in which they direct us [REDACTED] Systems through its domestic network with the help of another employee. “
The researchers said the attacks are as false as the letters. There is no evidence of any commitment, and the content of the letter does not resemble Bianlian ransomware operation. Even the writing of the message is inconsistent with the rescue notes that Bianlian was seen sending in the past, they said.
In any case, the scammers demanded $ 250,000 to $ 350,000, to pay in Bitcoin, within ten days. The letter also included a QR code that leads to the Bitcoin address, but is newly generated, so it is impossible to determine if it really belongs to Bianlian or not.
The Directorate of Return of the Letters is in Boston, USA, and according to The registrationPoint out a real address for an office building.
Through The registration