Here Is A Extortion Phishing Email Of A Different Sort

For years, I’ve been covering extortion phishing emails where they have a rather predictable pattern.

  • Some “hacker” claims to have bypassed your security
  • They have caught you watching “adult content”
  • They have proof that they will send to your friends and family unless you pay them in Bitcoin

Today I am going to detail something a bit different. My honeypot captured this email early this morning:

Now this kind of fits the pattern of other extortion emails that I have reported on. But what makes this different is the use of Grafana in the email. This is a company that does visualization and analysis of metrics, logs, traces, profiles, and beyond. Which means that if you are using their products, you can spot problems easier because those problems can be surface easier.

This is the first time that I have seen something like this. Which means other threat actors might try the same thing What I am thinking is that the threat actors are using Grafana’s name to try and give themselves some legitimacy. I guess I kind of stuffed that by going public with this. And I am going to stuff it some more by alerting the company to the fact that their name is being used like this.

Other than that, this your typical extortion email. There’s nothing new or different here. If it were not for the fact that the threat actors used the name of Grafana, it would almost not be worth reporting on. But it illustrates how far threat actors will go to steal your money.

My advice when it comes to these emails goes something like this:

  • You’ll note that you’re never named by your actual name in emails like this, that should be a big hint that this is a scam.
  • Never reply to the email as it will either result in telling the threat actor that your email is live, or the email might bounce.
  • f you see this or any email like it hit your inbox, delete and go on with your life.
  • If you are the least bit paranoid about a threat actor getting into your computer, have a computer professional check your computer over. They likely won’t find anything, but at least you will be able to sleep better at night.

Happy Friday!

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading