Share this article

Crypto Extortion on the Rise, Says Academic Study

Hackers can make up to $130,000 a month for a $10,000 investment.

Updated Sep 13, 2021, 11:36 a.m. Published Oct 23, 2019, 4:00 a.m.
malware code skull

Crypto-based extortion – basically the process of using spam-flinging botnet armies to "ransom" dirty pictures and compromising information in exchange for bitcoin – has turned virtual crime into child's play.

Speaking this week at the Advances in Financial Technology conference in Zurich, an international team comprised of researchers from the Austrian Technology Institute and security provider GoSecure sampled a population of email spam and found that the extortion process was quick, easy, and very lucrative.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Using public data hack info, the researchers found that a single instance of the popular Necurs botnet launched over 80 campaigns and in the 4.3 million emails surveyed by the team. In almost all cases the criminals had no incriminating information on the victims.

The team said that the botnet was surprisingly lucrative. By renting a botnet for $10,000 per month, the extortionists have been making at least $130,000. Compared to most extortion schemes, the spam campaign is incredibly simple, largely due to its employment of cryptocurrencies, said GoSecure's Masarah Paquet-Clouston.

As such, the researchers expect crypto-backed email extortions to increase.

"If you look at traditional [product] spam, it's much more complicated ... [crypto] extortion spam is much simpler," Paquet-Clouston said.

Examples provided in the paper describe an email informing the victim that the hacker will release compromising personal information if bitcoin isn’t provided in a timely manner. For example, one email claimed the hackers were performing surveillance via malware:

"Hello! As you may have noticed, I sent you an email from your account. This means that I have full access to your account. I’ve been watching you for a few months now. The fact is that you were infected with malware through an adult site that you visited."

Tracking the bitcoin addresses used and languages employed in emails allowed the researchers to further understand how botnets operate. For instance, whoever was behind the botnet charged certain nationalities higher prices than others, with English speakers topping out around $745 per recipient compared to Spaniards on the lowest end at $249.

The botnet reused bitcoin addresses, backing up similar research which saw one address used 3 million times. The researchers speculate address re-use is employed to increase the tactics overall simplicity.

Only 0.135 percent of bitcoin extorted could be traced to publicly verifiable wallets on exchanges, signifying the use of CoinJoins and other measures to mask transactions before off-ramping funds into fiat currency.

Knowledge about bitcoin and methods to track payments have lead botnet campaigns to other cryptos, the team said, particularly litecoin. Counterintuitively, privacy coins like monero and zcash are not being heavily used.

Hacker image via Shutterstock

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Fed’s Hammack tilts hawkish on rates, questions CPI drop as distorted

Beth Hammack

"My base case is that we can stay here for some period of time," Cleveland Fed President Beth Hammack told the WSJ.

What to know:

  • Cleveland Fed President Beth Hammack, who will be a voter on the central bank's policy-making FOMC in 2026, says interest rates need to remain on hold for several months.
  • She threw shade on last week's surprisingly soft CPI report, noting data-collection distortions created by the government shutdown.
  • Other things being equal, bitcoin would typically benefit from easier Fed monetary policy, but that hasn't at all been the case in 2025.