# "Total Access to All Your Devices" Sextortion Email Extortion Campaign

> A resurgent mass sextortion email campaign in which scammers falsely claim to have installed a driver-based Trojan granting total access to all of the victim's devices and to have recorded webcam footage of the victim watching pornography. The email demands roughly $1,490 in Bitcoin within 48 hours under threat of releasing fabricated videos to the victim's contacts. There is no malware, recording, or evidence — the scheme is pure psychological coercion delivered at spam scale.

- **Published:** 2026-06-24T00:00:00Z
- **Last reviewed:** 2026-06-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0934
- **ID:** TL-2026-0934
- **Severity:** MEDIUM
- **Category:** SCAM
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In late June 2026 Malwarebytes Labs documented a new wave of a long-running sextortion email pattern (a descendant of the "Hello pervert" / "I recorded you" lineage) characterized by the opening claim of having gained "total access to all your devices." The email asserts the attacker silently installed a Trojan that uses a driver-based, continuously-resigning engine to evade all antivirus software, granting full control of the victim's operating systems, webcam, microphone, keyboard, social media, email, chat history, and contact lists. It claims the malware behaves "similarly to TeamViewer" and that it recorded the victim viewing adult content. The operator also boasts of having "bought an exclusive access from hackers to a long list of email accounts," framing the recipient as one of many purchased from a credential/access market.

The extortion mechanic is identical across the campaign's variants: the recipient is told to transfer approximately $1,450-$1,490 USD in Bitcoin to a wallet address within 48 hours — a timer the email says "started right after you opened this very email" — or the fabricated webcam videos will be sent to friends, colleagues, and relatives and posted online. The message employs classic social-engineering levers: urgency (a hard countdown), shame (explicit references to pornography), false technical authority (jargon about drivers, signatures, and remote-control software), and pre-emptive objection handling that warns the victim not to contact police or reinstall the operating system because "all cryptocurrency transactions remain completely anonymous." A parallel variant analyzed by MalwareTips opens "Around few months back I managed to get full access to all devices of yours" and claims to have "downloaded to my remote cloud servers all your personal data, photos and other information," demanding $1,450.

Critically, the threat is empty. No screenshots, video samples, passwords, login timestamps, or IP addresses are ever supplied because none exist; the generic threats apply to any recipient regardless of their actual behavior. Related 2026 Malwarebytes reporting shows the broader sextortion ecosystem increasingly pads credibility by reusing passwords harvested from old data breaches and from public disposable-inbox services (e.g., FakeMailGenerator), and by spoofing the sender so the email appears to come from the victim's own account. This campaign is tracked as a consumer-facing SCAM for awareness and pattern-based detection: the article redacts the operator's email and Bitcoin wallet, so the durable indicators are the distinctive verbatim email phrases, the ransom/deadline structure, and the sender-spoofing and password-reuse tradecraft rather than network IOCs.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1589.001 Credentials
- T1589.002 Email Addresses
- T1593 Search Open Websites/Domains
- T1597.002 Purchase Technical Data
- T1598 Phishing for Information
- T1650 Acquire Access
- T1583.006 Web Services
- T1585.002 Email Accounts
- T1586.002 Email Accounts
- T1583.001 Domains
- T1566 Phishing
- T1684.001 Impersonation
- T1657 Financial Theft
- T1657.001 Financial Theft

## Sources

- [Total access to all your devices: sextortion scammers strike again](https://www.malwarebytes.com/blog/scams/2026/06/total-access-to-all-your-devices-sextortion-scammers-strike-again)
- [Sextortion "I recorded you" emails reuse passwords found in disposable inboxes](https://www.malwarebytes.com/blog/news/2026/03/sextortion-i-recorded-you-emails-reuse-passwords-found-in-disposable-inboxes)
- ["I sent you an email from your email account," sextortion scam claims](https://www.malwarebytes.com/blog/news/2025/04/i-sent-you-an-email-from-your-email-account-sextortion-scam-claims)
- [The "I Gained Access To Your Devices" Sextortion Email Scam](https://malwaretips.com/blogs/i-gained-access-to-your-devices/)
- [Sextortion Scams - University of Michigan Safe Computing](https://safecomputing.umich.edu/protect-yourself/phishing-scams/common-scams/sextortion)
- [MITRE ATT&CK T1657 Financial Theft](https://attack.mitre.org/techniques/T1657/)
- [MITRE ATT&CK T1566 Phishing](https://attack.mitre.org/techniques/T1566/)
- [MITRE ATT&CK T1656 Impersonation](https://attack.mitre.org/techniques/T1656/)
- [MITRE ATT&CK T1589 Gather Victim Identity Information](https://attack.mitre.org/techniques/T1589/)
- [MITRE ATT&CK T1650 Acquire Access](https://attack.mitre.org/techniques/T1650/)
- [MITRE ATT&CK T1597 Search Closed Sources](https://attack.mitre.org/techniques/T1597/)
- [MITRE ATT&CK T1598 Phishing for Information](https://attack.mitre.org/techniques/T1598/)
- [MITRE ATT&CK T1583.006 Acquire Infrastructure: Web Services](https://attack.mitre.org/techniques/T1583/006/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0934
