Bitcoin Extortion Group DD4BC Now Targeting Financial Services
An anonymous reader writes: Akamai is detailing the activities of DD4BC, a cyber-extortionist group that has launched distributed denial-of-service (DDoS) attacks against numerous organizations and demanded Bitcoin payments to stop the attacks. The group is sending ransom emails requiring payments of 25 to 100 Bitcoin, which is about $6,000 — $24,000 (€5,350 — €21,400). Social media shaming is also part of the deal, threatening to expose the DDOS on Twitter if payment is not made.
Publishing this story is doing no favors to anyone. As many others have pointed out in the past, if your company receives one of these emails, the best strategy is to ignore it.
These extortionists will send emails to hundreds or thousands of different companies, but they can't DDOS all of them at once. Furthermore, they have no idea if their emails even make it past the spam filters of their targets. So how do they decide who to DDOS? By seeing who responds to the blackmail message. Once you respond, and they know you are listening to them, you are now in their sights - not just this time, but the next time they decide to shake you down.
Ignore them. If they DDOS you, deal with it, but never acknowledge their demands. They can never be certain that you are receiving their emails, and if you never respond to them, eventually they'll move on to someone else.
It's not logical because you're not dealing with mature people. Keep in mind that these guys are almost certainly a group of young, socially maladjusted individuals. To a professional criminal, 50 BTC is chump change, but to a group of kids who want BTC to buy drugs without Mom and Dad finding out, it's a lot of cash.
To a kid who grew up on social media, social shaming of your victim might seem an extremely potent weapon, just like school bullying. The rest of us will just scratch our heads and shrug our shoulders.