Threat reportScamTL-2026-0934

"Total Access to All Your Devices" Sextortion Email Extortion Campaign

mediumACTIVE

"Total Access to All Your Devices" Sextortion Email (TL-2026-0934), also tracked as Hello pervert sextortion, is a medium-severity scam threat, first published 2026-06-24. It has no confirmed attribution, affects N/A Email recipients (consumers and enterprise mailboxes), maps to 15 MITRE ATT&CK techniques (T1566, T1583.001, T1583.006), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0934

Threat ID
TL-2026-0934
Also known as
Hello pervert sextortion, I recorded you sextortion, I gained access to your devices scam, Total access to all your devices
Severity
MEDIUM
Status
ACTIVE
Category
SCAM
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumers, general public, enterprise email users
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in "Total Access to All Your Devices" Sextortion Email

Malware and tooling: Fabricated driver-based Trojan (claimed only; no real malware exists), TeamViewer

How "Total Access to All Your Devices" Sextortion Email works

A resurgent mass sextortion email campaign in which scammers falsely claim to have installed a driver-based Trojan granting total access to all of the victim's devices and to have recorded webcam footage of the victim watching pornography. The email demands roughly $1,490 in Bitcoin within 48 hours under threat of releasing fabricated videos to the victim's contacts. There is no malware, recording, or evidence — the scheme is pure psychological coercion delivered at spam scale.

In late June 2026 Malwarebytes Labs documented a new wave of a long-running sextortion email pattern (a descendant of the "Hello pervert" / "I recorded you" lineage) characterized by the opening claim of having gained "total access to all your devices." The email asserts the attacker silently installed a Trojan that uses a driver-based, continuously-resigning engine to evade all antivirus software, granting full control of the victim's operating systems, webcam, microphone, keyboard, social media, email, chat history, and contact lists. It claims the malware behaves "similarly to TeamViewer" and that it recorded the victim viewing adult content. The operator also boasts of having "bought an exclusive access from hackers to a long list of email accounts," framing the recipient as one of many purchased from a credential/access market.

The extortion mechanic is identical across the campaign's variants: the recipient is told to transfer approximately $1,450-$1,490 USD in Bitcoin to a wallet address within 48 hours — a timer the email says "started right after you opened this very email" — or the fabricated webcam videos will be sent to friends, colleagues, and relatives and posted online. The message employs classic social-engineering levers: urgency (a hard countdown), shame (explicit references to pornography), false technical authority (jargon about drivers, signatures, and remote-control software), and pre-emptive objection handling that warns the victim not to contact police or reinstall the operating system because "all cryptocurrency transactions remain completely anonymous." A parallel variant analyzed by MalwareTips opens "Around few months back I managed to get full access to all devices of yours" and claims to have "downloaded to my remote cloud servers all your personal data, photos and other information," demanding $1,450.

Critically, the threat is empty. No screenshots, video samples, passwords, login timestamps, or IP addresses are ever supplied because none exist; the generic threats apply to any recipient regardless of their actual behavior. Related 2026 Malwarebytes reporting shows the broader sextortion ecosystem increasingly pads credibility by reusing passwords harvested from old data breaches and from public disposable-inbox services (e.g., FakeMailGenerator), and by spoofing the sender so the email appears to come from the victim's own account. This campaign is tracked as a consumer-facing SCAM for awareness and pattern-based detection: the article redacts the operator's email and Bitcoin wallet, so the durable indicators are the distinctive verbatim email phrases, the ransom/deadline structure, and the sender-spoofing and password-reuse tradecraft rather than network IOCs.

MITRE ATT&CK techniques used in TL-2026-0934

Initial Access

T1566 Phishing

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1586.002 Email Accounts; T1650 Acquire Access

Reconnaissance

T1589 Gather Victim Identity Information; T1589.001 Credentials; T1589.002 Email Addresses; T1593 Search Open Websites/Domains; T1597.002 Purchase Technical Data; T1598 Phishing for Information

Impact

T1657 Financial Theft; T1657.001 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in "Total Access to All Your Devices" Sextortion Email

  • N/A — Email recipients (consumers and enterprise mailboxes)
    Vulnerable versions: any email user

Remediation for "Total Access to All Your Devices" Sextortion Email

Immediate actions

  • Do not pay the ransom and do not reply to the email; payment marks the address as responsive and invites repeat extortion.
  • Do not open any attachments or click any links in the message.
  • Report and delete the email; mark it as phishing/spam in the mail client.
  • If a real password of yours appears in the email, change it everywhere it was used and enable multi-factor authentication.

Workarounds

  • Enable webcam covers and OS-level camera permission controls to reduce anxiety value of the bluff.
  • Use a breach-monitoring service to know which old passwords are already public so a quoted password is recognized as stale.

Longer-term hardening

  • Deploy mail-gateway content rules that flag the campaign's distinctive sextortion phrases and Bitcoin-ransom/48-hour-deadline structure.
  • Enforce SPF, DKIM, and DMARC (p=reject) to blunt sender-spoofing that makes the email appear to come from the recipient's own account.
  • Run user-awareness training on sextortion mechanics so recipients recognize the empty-threat pattern.
  • Avoid reusing passwords and avoid entering real credentials into disposable-inbox services that scammers scrape.

Timeline of "Total Access to All Your Devices" Sextortion Email

  • Malwarebytes documents the "I sent you an email from your email account" sextortion variant that spoofs the sender so the message appears to come from the victim's own inbox.
  • Malwarebytes reports an "I recorded you" sextortion wave that adds credibility by reusing passwords harvested from public disposable-inbox services such as FakeMailGenerator.
  • MalwareTips publishes analysis of the parallel "I gained access to your devices" variant — opener "Around few months back I managed to get full access to all devices of yours," claimed cloud exfiltration of personal data, and a $1,450 Bitcoin demand within 48 hours.
  • Durable detection anchors established: distinctive verbatim email phrases, the ~$1,450-$1,490 Bitcoin / 48-hour ransom structure, and sender-spoofing plus password-reuse tradecraft (no usable network IOCs; operator email and wallet redacted in reporting).
  • Campaign ingested as TL-2026-0934 and tracked as an active consumer-facing SCAM for awareness and pattern-based detection.
  • Campaign assessed ACTIVE and broadly distributed; threat is empty (no malware, recording, or evidence) and relies entirely on psychological pressure.
  • Operators observed claiming to have "bought an exclusive access from hackers to a long list of email accounts," indicating bulk acquisition of recipient lists from credential/access markets to seed mass distribution.
  • Malwarebytes Labs publishes analysis of the resurgent "total access to all your devices" sextortion campaign demanding ~$1,490 in Bitcoin within 48 hours.

Sources cited for "Total Access to All Your Devices" Sextortion Email

Detection coverage for TL-2026-0934

As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0934 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats