Pages:
Author

Topic: Blackmail - Need a Hacker/Catfish/Social Engineer - recommend - will pay BTC (Read 836 times)

copper member
Activity: 2562
Merit: 2510
Spear the bees
If the hacker always use vpn then there might have low chance to caught him, but still it should be reported on FBI. Less is better than never. And if the person become careless for a while then there will be high chance to catch the hacker.
VPNs are not the be-all, end-all. The only difference is that now you're passing through some other network as a proxy but it's not as if the culprit can't be found out via other methods than IP detection.

The Facebook account is definitely going to be a dead end (at least analytically) - unless he's a total moron, there won't be information to be gleaned from investigating a fake account and the sign-up process is accessible enough to where you can probably create one in a few minutes.
hero member
Activity: 1456
Merit: 624
Maintain Social Distance, Stay safe.
If this guy is always on a VPN, running an "invisible" image off a hosted site to get the IP connection won't work. But, if they happen to be a little careless, then depending on the way you can contact him you could glean something from this.
If the hacker always use vpn then there might have low chance to caught him, but still it should be reported on FBI. Less is better than never. And if the person become careless for a while then there will be high chance to catch the hacker.
jr. member
Activity: 48
Merit: 3
FYI I’m limited to only two messages a day, so I’ll reply to your message tomorrow. If you want to chat before then  send me a way to contact you via pm
legendary
Activity: 3038
Merit: 1104
This is what I do. I drink and I know things.
Honestly, though, I don't have high hopes when it comes to these ransom attempts. If you give in, they will ask for more: the leverage is on their end and only increases every time they are paid. If this guy has these images, then they may as well already be in the public domain. Of course, the underage pictures are certainly illegal, but I don't think he will do something as stupid as post those to your friend's companies.

The "weird" in this case is that the blackmailer doesn't want money. He/ she/ they want more pics....

I also think it is someone that knows her, because he is trying to blackmail her for more pics/vids, which is weird to me.. He isn't asking for any kind of payment like $$ or BTC, but more pics..

You can call it "stupidity" but he can call it "cunningness", show her that he can do whatever he wants and no cost for his side. This way of thinking though, lead the person to be careless and make mistakes. Unfortunately, police can't run things up so if somebody can run an investigation from his own pocket and deliver them to the police, might have some better chances.
@eddie13: I strongly believe that you have to talk with a lawyer, tell the whole story and listen to his suggestions. Either way, your friend will have to file a lawsuit despite that she consent and gave the material or that she doesn't know the real perpetrator etc. At least you will know/ learn how things are (legally) and what paths your friend has available to choose from. To go illegally, well, is tricky. DW though is there... Undecided
copper member
Activity: 1666
Merit: 1901
Amazon Prime Member #7
I believe it is theoretically possible to embed a virus into an image file that can run arbitrary code on someone's computer. This is probably the only way you will be able to get more than the creep's IP address on your own. How this is done is outside of my area of expertise, and I would caution that sending a file with a virus is almost certainly illegal.

It's practical. There's a science around it called steganography which embeds arbitrary bytes into an image, and the quality reduction of it is minimal and barely noticeable.
Yes I know. Steganography can also be used to hide messages 'in plain sight', somewhat similar to the timestamps on videos by al qaeda and the Taliban in the early 2000's. 


The "virus"
Any code that does something without the consent of the end user is malware, and is likely illegal to be sending to others. Gathering information about a computer without the consent of the user, I believe crosses the threshold to sending malware.

Even if you were able to identify the person behind the blackmail, I don't think there is much the girl or Eddie can do. If you tell the person you know his identity, he can destroy evidence of his crimes, and possibly disseminate the pictures you want to keep private.
copper member
Activity: 2562
Merit: 2510
Spear the bees
If this guy is always on a VPN, running an "invisible" image off a hosted site to get the IP connection won't work. But, if they happen to be a little careless, then depending on the way you can contact him you could glean something from this.
Honestly, though, I don't have high hopes when it comes to these ransom attempts. If you give in, they will ask for more: the leverage is on their end and only increases every time they are paid. If this guy has these images, then they may as well already be in the public domain. Of course, the underage pictures are certainly illegal, but I don't think he will do something as stupid as post those to your friend's companies.

Maybe it's some obsessed creep, deluding themselves?
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
I believe it is theoretically possible to embed a virus into an image file that can run arbitrary code on someone's computer. This is probably the only way you will be able to get more than the creep's IP address on your own. How this is done is outside of my area of expertise, and I would caution that sending a file with a virus is almost certainly illegal.

It's practical. There's a science around it called steganography which embeds arbitrary bytes into an image, and the quality reduction of it is minimal and barely noticeable. You can put the image on an image host, set up a webpage that decodes it (using some javascript library like this) using some free service like Github Pages or Netlify, and then attempt to trick the blackmailer to go there.

The "virus" in this case won't be something destructive, installing Wireshark in the background and run it to sniff the attacker's network packets should disclose his IP address from which you can roughly derive which town he lives in, since there should be packets in there showing his real IP as he connects to a VPN. I think that's what eddie13 wants. The procedure is similar for Windows and MacOS there are just different privilege escalation vulnerabilities (and whatever code you'd want to run in the OS after that will be in C language) to exploit*, because you don't want to display a confirmation message for him to see then he will know he is being hacked.

There is no wireshark for android but if the attacker is using that then you can use something like androiddump instead. There's no wireshark for iOS either but regardless it is a PITA to exploit anything on with a small budget because of its security and iOS not lending itself well to background jobs.


* After exploiting a remote code execution vuln depending on the browser he's using, and different vulns can be embedded in the image that can be chosen after you inspect the User Agent to check which browser it is.



Your best bet is to find a coder whose willing to write a package to this spec. Web devs with Javascript knowledge are abundant the tricky part is finding one who is OK with doing a grey hat activity like this. I can go research these things more if you want.

Usual disclaimer: I don't condone any of this. I don't have the infrastructure or technical skills to help with anything either. I'm just explaining how it can be done. Though I also think law enforcement will handle your case very slowly and it could drag on for months.
uk1
copper member
Activity: 546
Merit: 500


1. Go to github and search - xHak9x
Open the first result.


All this will do is download the public information on everyone on your friend's list (according to my reading of the code). I believe this is also against Facebook's TOS.

if the account in question as a email, phone number listed it will get it, just after be on your friend's list.
Maybe it is against Facebook's TOS and blackmail is not against Facebook's TOS, I think so.
If you can view the Facebook profile of the blackmailer, you may also look and check the previous posts if it's shown publicly. Find any hint/clue on his comments or the comments on his posts. If he is posting a kind of stuff that is searchable that may lead to the connection.

Why not make also a dummy/fake account? Be friends to his list of friends and try to contact them, maybe you can find any related pieces of information.

1+
hero member
Activity: 2464
Merit: 594
If you can view the Facebook profile of the blackmailer, you may also look and check the previous posts if it's shown publicly. Find any hint/clue on his comments or the comments on his posts. If he is posting a kind of stuff that is searchable that may lead to the connection.

Why not make also a dummy/fake account? Be friends to his list of friends and try to contact them, maybe you can find any related pieces of information.
copper member
Activity: 1666
Merit: 1901
Amazon Prime Member #7


1. Go to github and search - xHak9x
Open the first result.


All this will do is download the public information on everyone on your friend's list (according to my reading of the code). I believe this is also against Facebook's TOS.
uk1
copper member
Activity: 546
Merit: 500
Has he mentioned just a few close friends, family or a long list?
Mostly close but a couple that are often associated with her on facebook.. The connection is facebook common tags/comments..

Could be anyone, not just someone she knows.

Has he sent nude proofs/ no nude images to her?
Yes.. And started sending to others..

Not Good.

Were any of the non nudes uploaded to her facebook account?
No.

link could be the person who died or as she told someone about the pics/nudes

how long as the threats of blackmail been going on?
Since January..

long time really  

who was the Vpn provider, they may keep logs.
Hosting Services, Inc.

police matter to get the logs, plus the evidence from the fake profile on facebook.

Have you reversed image searched the nudes/ none nudes for any results.
Yes, no results..

Is she friends with the blackmailer on facebook?
Have not accepted his friend req but that is where he is contacting her and others..

three choices 1 close her fb account down, hope it all stops, 2 get the police involved, 3, she adds him on fb to see if there is an email cone ted to the fake fb account, then dox the email, phone number hopefully to find more details, accounts etc.
she does a live vid or fake vid to get is real ip it needs to be live or fake live to leak his real ip, even through a vpn through flash.


First of all, to find the email of a facebook account you have to be friend with that person.

(P.S. - You have to use linux)

1. Go to github and search - xHak9x
Open the first result.

2. Clone or download it to your system.

  Clone it at any location by typing on terminal.

3. After it has cloned, go to the folder and you might see these files
  (i) fbi.py
  (ii) LICENSE
  (iii) README.md
  (iv) requirements.txt

4. type - pip install -r requirements.txt

After the success message has been displayed

5. type - python fbi.py

6. You will see " Hak9>> " instead of you root@whatevername (root path)

7. type - token

8. It will ask you your facebook username and password. Provide it. Don't worry, it's just asking because it wants to get your friends data.
  Your password will not be visible to you because of some security reasons.

  But here's a tricky part. Even if you have provided correct details you will get an erron message that it has failed to generate access token and it will tell you to check your  internet    connection / email or password.
  To fix this you have to go to your browser (don't close the terminal) and login into facebook and confirm that it was you.

9. After you have confirmed the security questions on facebook, come back to terminal and type - token (again).
  Again provide your username and password in the terminal(remember: type token when you are seeing " Hak9 >> ". You will get an _error_ if you are typing it on your root@whatevername).

10. After that you will get a message that - successfully generated token and you token is stored in cookie. AND YOU WILL ALSO COME OUT"Hak9 >> " to your root path.

11. Type - python fbi.py

12. You will again see "Hak9 >> ".

13. Type - help. You will see the various features of this app.

14. Type - dump_phone(for your friends phone numbers)
   Type - dump_mail(for your friends email) and likewise.

The results will be stored by default in the fbi folder it OUTPUT or you can just copy the results from terminal and store it to your desired location.

After you're done, type "exit" to exit the program.

cant help any further with the ip live ect or the linux. will send you to the right forum if you want me to.

can do the doxxing part


copper member
Activity: 2338
Merit: 4543
Join the world-leading crypto sportsbook NOW!
She says that the guy she originally sent the pics to a long time ago is dead, died, and has been dead for quite a while now..

I also think it is someone that knows her, because he is trying to blackmail her for more pics/vids, which is weird to me.. He isn't asking for any kind of payment like $$ or BTC, but more pics..
Creepy AF..

This is a job for the authorities, especially since some of the photos are of her as a minor.  The person in possession of the photos is very likely related to the dead guy, it shouldn't be hard for the cops to track down who ever it was that took possession of his electronic devices.
legendary
Activity: 2296
Merit: 2262
BTC or BUST
Has he mentioned just a few close friends, family or a long list?
Mostly close but a couple that are often associated with her on facebook.. The connection is facebook common tags/comments..

Has he sent nude proofs/ no nude images to her?
Yes.. And started sending to others..

Were any of the non nudes uploaded to her facebook account?
No

how long as the threats of blackmail been going on?
Since January..

who was the Vpn provider, they may keep logs.
Hosting Services, Inc.

Have you reversed image searched the nudes/ none nudes for any results.
Yes, no results..

Is she friends with the blackmailer on facebook?
Have not accepted his friend req but that is where he is contacting her and others..

uk1
copper member
Activity: 546
Merit: 500
Has he mentioned just a few close friends, family or a long list?

Has he sent nude proofs/ no nude images to her?

Were any of the non nudes uploaded to her facebook account?

how long as the threats of blackmail been going on?

whatever she does do not send more pics, vids to the blackmailer, it wont end doing that.

who was the Vpn provider, they may keep logs.

Have you reversed image searched the nudes/ none nudes for any results.

Is she friends with the blackmailer on facebook?
legendary
Activity: 2296
Merit: 2262
BTC or BUST
legendary
Activity: 2296
Merit: 2262
BTC or BUST
USA and early 20's.. (girl)

Thought I'd find more skills around here than this..
hero member
Activity: 1456
Merit: 624
Maintain Social Distance, Stay safe.
Friend is being blackmailed with nude pics, even some of when she was a minor..
This could (depending on the country) be a very serious crime, so I'd say report this to the police.

She is.. But I doubt they will do anything.. .
Nowadays cyber crime is spreading and police is also working very hard to solve the cases. In this situation it will be the best way if you report it to the police. Also you may try to hire ethical hacker from freelance marketplace if possible.
hero member
Activity: 2814
Merit: 618
Leading Crypto Sports Betting & Casino Platform
She says that the guy she originally sent the pics to a long time ago is dead, died, and has been dead for quite a while now..

So this is the mistake of the girl herself to send her nude pictures to stranger or anyone. These days no one is trustable and the girl should be taught about this. Even if the guy is dead, the picture can be leaked from the phone or pc.
Will you give us the nationality of the girl and what was her age  Sad
legendary
Activity: 2646
Merit: 2842
Shitcoin Minimalist
Maybe she should just contact the FBI. He could probably get nailed on child pornography charges, among other things, if he actually has nude pictures of her as a minor.
copper member
Activity: 1666
Merit: 1901
Amazon Prime Member #7
I can get you his exact house address and most basic information (full name, zip code if he's in the us, isp, etc). We can use an escrow. The payment will be much higher than $100 though, and I'd say around $900-$1,400 depending on a few factors.

Sounds like a bit much for clicking around a bit TBH..


Snagged an Ip off of him but it belongs to "Hotspot commercial VPN network"..
Totally didn't notice the logger though..  (Thanks "Hacker" Wink but no dice on that try..)


So.. The guy knows what he's doing a bit..
I would suggest your friend block the creep, and report the account to Facebook. Facebook may or may not report him to the police, but they will ban the person for having a fake profile (in addition to the blackmail). Facebook should be able to provide information about the person's IP addresses used to access the Facebook account to law enforcement.

I believe it is theoretically possible to embed a virus into an image file that can run arbitrary code on someone's computer. This is probably the only way you will be able to get more than the creep's IP address on your own. How this is done is outside of my area of expertise, and I would caution that sending a file with a virus is almost certainly illegal.

Deal with law enforcement.
Pages:
Jump to: