Tell HN: Got a spam about “I recorded you” but with a twist

3 points by 2Gkashmiri ↗ HN
The meat of the spam text is pretty run of the mill spammy "i recorded you" (through your cam) SATISFYING YOURSELF.

But the problem is,

If you think this is some bad joke, no, I know your password: Something@234

which is the password i've used in some places so i suspect the spammer has gotten my email from some dump but this is pretty ingenious because all you have to give is the password and people might freak out.

edit: yes the email is in HIBP since ages

5 comments

[ 3.3 ms ] story [ 25.0 ms ] thread
what is interesting is the email is from one

JohnBlue@5420.com

but that site is not accessible so maybe something something?

the ip address shows china ASN which is not surprising but yeah, first time seeing this targeted email..

oh, beyond using aliexpress, i have not used a chinese website in ages (btw which has the same password so maybe they had a breach?)

Lots of email hosts are like that, btw.

There was a time, when the Internet didn't look much like it does today - especially when UUCP reigned supreme - when nearly all email domains did not have associated IP addresses. Local ISP's that give custom email addresses to their users also nearly always do the same thing. If you want to go down a rabbit hole, look up how to do bang path email routing. It still works today, even if nobody does it.

The only part that matters is that the sending mail server can find an MX record for the receiving domain's mail server. There is no requirement for the named domain to have its own IP address as long as whatever domain the MX points to knows where to send the incoming mail.

This kind of phishing has been around for quite a while, in exactly the form you describe.

I use a password manager, and change the passwords fairly often. So the first time I got one of these phishing attempts, I laughed and thought "Oh, so that's what my passwords look like!"

By that time, it was long-retired and so I don't even have a way to find out what site it was that had been compromised.

I went to reply one time to one of these emails and wrote up a whole thing and sent it. The next thing I noticed I received an email... from myself. Not sure how the spoofing of my own email address could ever convince me to pay the included Bitcoin Wallet address. The other thing that is always wrong with these emails: I have very little invested into Bitcoin and surely never enough to pay them in Bitcoin. I think I've received at least 10 of these emails, always from my own email address. Again... can't really even take that seriously. Nothing has ever happened by ignoring it. Besides... the fact that they try to trick you that they have anything on you without showing an ounce of proof... I'd be surprised how many people are tricked into believing the hype.
What's the twist? They've included passwords for a while now...