Threat reportScamTL-2026-0934
"Total Access to All Your Devices" Sextortion Email Extortion Campaign
"Total Access to All Your Devices" Sextortion Email (TL-2026-0934), also tracked as Hello pervert sextortion, is a medium-severity scam threat, first published 2026-06-24. It has no confirmed attribution, affects N/A Email recipients (consumers and enterprise mailboxes), maps to 15 MITRE ATT&CK techniques (T1566, T1583.001, T1583.006), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0934
- Threat ID
- TL-2026-0934
- Also known as
- Hello pervert sextortion, I recorded you sextortion, I gained access to your devices scam, Total access to all your devices
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- SCAM
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumers, general public, enterprise email users
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in "Total Access to All Your Devices" Sextortion Email
Malware and tooling: Fabricated driver-based Trojan (claimed only; no real malware exists), TeamViewer
How "Total Access to All Your Devices" Sextortion Email works
A resurgent mass sextortion email campaign in which scammers falsely claim to have installed a driver-based Trojan granting total access to all of the victim's devices and to have recorded webcam footage of the victim watching pornography. The email demands roughly $1,490 in Bitcoin within 48 hours under threat of releasing fabricated videos to the victim's contacts. There is no malware, recording, or evidence — the scheme is pure psychological coercion delivered at spam scale.
In late June 2026 Malwarebytes Labs documented a new wave of a long-running sextortion email pattern (a descendant of the "Hello pervert" / "I recorded you" lineage) characterized by the opening claim of having gained "total access to all your devices." The email asserts the attacker silently installed a Trojan that uses a driver-based, continuously-resigning engine to evade all antivirus software, granting full control of the victim's operating systems, webcam, microphone, keyboard, social media, email, chat history, and contact lists. It claims the malware behaves "similarly to TeamViewer" and that it recorded the victim viewing adult content. The operator also boasts of having "bought an exclusive access from hackers to a long list of email accounts," framing the recipient as one of many purchased from a credential/access market.
The extortion mechanic is identical across the campaign's variants: the recipient is told to transfer approximately $1,450-$1,490 USD in Bitcoin to a wallet address within 48 hours — a timer the email says "started right after you opened this very email" — or the fabricated webcam videos will be sent to friends, colleagues, and relatives and posted online. The message employs classic social-engineering levers: urgency (a hard countdown), shame (explicit references to pornography), false technical authority (jargon about drivers, signatures, and remote-control software), and pre-emptive objection handling that warns the victim not to contact police or reinstall the operating system because "all cryptocurrency transactions remain completely anonymous." A parallel variant analyzed by MalwareTips opens "Around few months back I managed to get full access to all devices of yours" and claims to have "downloaded to my remote cloud servers all your personal data, photos and other information," demanding $1,450.
Critically, the threat is empty. No screenshots, video samples, passwords, login timestamps, or IP addresses are ever supplied because none exist; the generic threats apply to any recipient regardless of their actual behavior. Related 2026 Malwarebytes reporting shows the broader sextortion ecosystem increasingly pads credibility by reusing passwords harvested from old data breaches and from public disposable-inbox services (e.g., FakeMailGenerator), and by spoofing the sender so the email appears to come from the victim's own account. This campaign is tracked as a consumer-facing SCAM for awareness and pattern-based detection: the article redacts the operator's email and Bitcoin wallet, so the durable indicators are the distinctive verbatim email phrases, the ransom/deadline structure, and the sender-spoofing and password-reuse tradecraft rather than network IOCs.
MITRE ATT&CK techniques used in TL-2026-0934
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts; T1586.002 Email Accounts; T1650 Acquire Access
Reconnaissance
T1589 Gather Victim Identity Information; T1589.001 Credentials; T1589.002 Email Addresses; T1593 Search Open Websites/Domains; T1597.002 Purchase Technical Data; T1598 Phishing for Information
Impact
T1657 Financial Theft; T1657.001 Financial Theft
Defense Evasion
Affected products and versions in "Total Access to All Your Devices" Sextortion Email
- N/A — Email recipients (consumers and enterprise mailboxes)
Vulnerable versions: any email user
Remediation for "Total Access to All Your Devices" Sextortion Email
Immediate actions
- Do not pay the ransom and do not reply to the email; payment marks the address as responsive and invites repeat extortion.
- Do not open any attachments or click any links in the message.
- Report and delete the email; mark it as phishing/spam in the mail client.
- If a real password of yours appears in the email, change it everywhere it was used and enable multi-factor authentication.
Workarounds
- Enable webcam covers and OS-level camera permission controls to reduce anxiety value of the bluff.
- Use a breach-monitoring service to know which old passwords are already public so a quoted password is recognized as stale.
Longer-term hardening
- Deploy mail-gateway content rules that flag the campaign's distinctive sextortion phrases and Bitcoin-ransom/48-hour-deadline structure.
- Enforce SPF, DKIM, and DMARC (p=reject) to blunt sender-spoofing that makes the email appear to come from the recipient's own account.
- Run user-awareness training on sextortion mechanics so recipients recognize the empty-threat pattern.
- Avoid reusing passwords and avoid entering real credentials into disposable-inbox services that scammers scrape.
Timeline of "Total Access to All Your Devices" Sextortion Email
- Malwarebytes documents the "I sent you an email from your email account" sextortion variant that spoofs the sender so the message appears to come from the victim's own inbox.
- Malwarebytes reports an "I recorded you" sextortion wave that adds credibility by reusing passwords harvested from public disposable-inbox services such as FakeMailGenerator.
- MalwareTips publishes analysis of the parallel "I gained access to your devices" variant — opener "Around few months back I managed to get full access to all devices of yours," claimed cloud exfiltration of personal data, and a $1,450 Bitcoin demand within 48 hours.
- Durable detection anchors established: distinctive verbatim email phrases, the ~$1,450-$1,490 Bitcoin / 48-hour ransom structure, and sender-spoofing plus password-reuse tradecraft (no usable network IOCs; operator email and wallet redacted in reporting).
- Campaign ingested as TL-2026-0934 and tracked as an active consumer-facing SCAM for awareness and pattern-based detection.
- Campaign assessed ACTIVE and broadly distributed; threat is empty (no malware, recording, or evidence) and relies entirely on psychological pressure.
- Operators observed claiming to have "bought an exclusive access from hackers to a long list of email accounts," indicating bulk acquisition of recipient lists from credential/access markets to seed mass distribution.
- Malwarebytes Labs publishes analysis of the resurgent "total access to all your devices" sextortion campaign demanding ~$1,490 in Bitcoin within 48 hours.
Sources cited for "Total Access to All Your Devices" Sextortion Email
- Total access to all your devices: sextortion scammers strike again
- Sextortion "I recorded you" emails reuse passwords found in disposable inboxes
- "I sent you an email from your email account," sextortion scam claims
- The "I Gained Access To Your Devices" Sextortion Email Scam
- Sextortion Scams - University of Michigan Safe Computing
- MITRE ATT&CK T1657 Financial Theft
- MITRE ATT&CK T1566 Phishing
- MITRE ATT&CK T1656 Impersonation
- MITRE ATT&CK T1589 Gather Victim Identity Information
- MITRE ATT&CK T1650 Acquire Access
- MITRE ATT&CK T1597 Search Closed Sources
- MITRE ATT&CK T1598 Phishing for Information
- MITRE ATT&CK T1583.006 Acquire Infrastructure: Web Services
Detection coverage for TL-2026-0934
As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0934 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.