Two recently discovered sextortion scam campaigns appear to be using the Necurs botnet to distribute their messages, according to security researchers. Sextortion scammers select their victims from previously leaked databases of email addresses and their corresponding passwords. By displaying the correct email and password matches, the scammers pretend to have infected the victim’s system, accessed their email address, and recorded them visiting adult websites. They then demand a ransom in cryptocurrency, promising not to publish the videos they claim to have in their possession.

Security researchers from Cisco Talosinvestigated two such campaigns. One started on August 30th and was called “Aaron Smith,” while the second started on October 5th and was called “From:header.” According to the researchers, the Aaron Smith campaign sent a total of more than 233,200 emails from 137,606 unique IP addresses.
The total number of different emails sent was 15,826, and on average each victim received 15 different sextortion messages. However, what was discovered during the investigation is that approximately 1000 IPs found in the Aaron Smith campaign are the same as those found in September in a different sextortion campaign using the Necurs botnet.
Victims who fell victim to the sextortion scam during the 60 days the campaign was active paid a total of 23.36 bitcoins, or about 130,000 euros. Researchers also noticed that some of the transactions shown in the scam wallets are smaller than the 1,000 requested via the emails. This may be because the same wallets may have been used in other spam campaigns.
