Share this article

Crypto Extortion on the Rise, Says Academic Study

Hackers can make up to $130,000 a month for a $10,000 investment.

Updated Sep 13, 2021, 11:36 a.m. Published Oct 23, 2019, 4:00 a.m.
malware code skull

Crypto-based extortion – basically the process of using spam-flinging botnet armies to "ransom" dirty pictures and compromising information in exchange for bitcoin – has turned virtual crime into child's play.

Speaking this week at the Advances in Financial Technology conference in Zurich, an international team comprised of researchers from the Austrian Technology Institute and security provider GoSecure sampled a population of email spam and found that the extortion process was quick, easy, and very lucrative.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Using public data hack info, the researchers found that a single instance of the popular Necurs botnet launched over 80 campaigns and in the 4.3 million emails surveyed by the team. In almost all cases the criminals had no incriminating information on the victims.

The team said that the botnet was surprisingly lucrative. By renting a botnet for $10,000 per month, the extortionists have been making at least $130,000. Compared to most extortion schemes, the spam campaign is incredibly simple, largely due to its employment of cryptocurrencies, said GoSecure's Masarah Paquet-Clouston.

As such, the researchers expect crypto-backed email extortions to increase.

"If you look at traditional [product] spam, it's much more complicated ... [crypto] extortion spam is much simpler," Paquet-Clouston said.

Examples provided in the paper describe an email informing the victim that the hacker will release compromising personal information if bitcoin isn’t provided in a timely manner. For example, one email claimed the hackers were performing surveillance via malware:

"Hello! As you may have noticed, I sent you an email from your account. This means that I have full access to your account. I’ve been watching you for a few months now. The fact is that you were infected with malware through an adult site that you visited."

Tracking the bitcoin addresses used and languages employed in emails allowed the researchers to further understand how botnets operate. For instance, whoever was behind the botnet charged certain nationalities higher prices than others, with English speakers topping out around $745 per recipient compared to Spaniards on the lowest end at $249.

The botnet reused bitcoin addresses, backing up similar research which saw one address used 3 million times. The researchers speculate address re-use is employed to increase the tactics overall simplicity.

Only 0.135 percent of bitcoin extorted could be traced to publicly verifiable wallets on exchanges, signifying the use of CoinJoins and other measures to mask transactions before off-ramping funds into fiat currency.

Knowledge about bitcoin and methods to track payments have lead botnet campaigns to other cryptos, the team said, particularly litecoin. Counterintuitively, privacy coins like monero and zcash are not being heavily used.

Hacker image via Shutterstock

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Altcoins jump as dollar slides, bitcoin holds steady: Crypto Markets Today

US dollars loan (Frederick Warren/Unsplash/Modified by CoinDesk)

The Dollar Index hit a four-year low, while altcoins surged led by HYPE, JTO and Solana memecoin PIPPIN.

What to know:

  • Bitcoin held near $89,200 and ether topped $3,000, supported by a sharp drop in the U.S. dollar index (DXY).
  • Altcoins outperformed, with Hyperliquid’s HYPE up 25% and Solana staking token JTO extending a 31% three-day rally.
  • Speculative tokens led gains, including Solana-based memecoin PIPPIN up 64%, as CoinDesk’s altcoin-heavy CD80 index beat CD20.