Page 1
Page 1
Started By
Message

Anybody ever had phishing malware talk back them?

Posted on 9/16/25 at 1:55 pm
Posted by SlowFlowPro
With populists, expect populism
Member since Jan 2004
466154 posts
Posted on 9/16/25 at 1:55 pm
So yesterday I got the classic phishing email archetype with a sketchy attachment from someone I recognized. My standard response is that I will send a separate email to the (hacked) person to advise them they were hacked. Not even to test them, but to alert them (I'd hope people do the same for me).

YESTERDAY, when I sent the email, it sent one back. It responded to my separate email with, "No, I did send that document".

Luckily, it was the phishing where it was encrypted (to avoid GWS scanning) and I realized THAT was second level fishy and just said no mas.

So I just thought this was interesting development in the malware/phishing space that I wasn't sure if y'all had run into yet.
Posted by Stexas
SWLA
Member since May 2013
6844 posts
Posted on 9/16/25 at 2:47 pm to
yeah, if the hacker has access to the email account then they respond. Always use a different form of communication to respond.
Posted by LemmyLives
Texas
Member since Mar 2019
13392 posts
Posted on 9/16/25 at 3:33 pm to
None of the people that have my email address has been hit with malware that tries to phish their address book. Maybe most of them listened to me over the years!

When you replied to the email, did you change the subject line? I'd be curious to see if the malware could recognize the "did you send this" email with a simple reply without body of the phishing email and with a different subject line.
Posted by SlowFlowPro
With populists, expect populism
Member since Jan 2004
466154 posts
Posted on 9/16/25 at 4:11 pm to
quote:

When you replied to the email, did you change the subject line?

I sent a separate email with "Email hacked" as the subject.

quote:

I'd be curious to see if the malware could recognize the "did you send this" email with a simple reply without body of the phishing email and with a different subject line.

I was thinking the same thing but with emails with subjects like the one I sent. I doubt a person actively sent that email.

That's why I made the thread. I've never had the malware write me back.
Posted by LemmyLives
Texas
Member since Mar 2019
13392 posts
Posted on 9/16/25 at 4:29 pm to
quote:

I sent a separate email with "Email hacked" as the subject.

I haven't read anything like this (malware auto response to people in the user's address book) on any of my security and tech websites.

Does he know how to scan for malware with Malwarebytes, etc.? I'm curious to know what he's infected with.
Posted by j1897
Member since Nov 2011
4299 posts
Posted on 9/16/25 at 4:55 pm to
It's all AI now, they are fishing with dynamite. Once they get someone hooked they will transfer it to a call center with literal slave labor working at it.

Crazy stuff
Posted by SlowFlowPro
With populists, expect populism
Member since Jan 2004
466154 posts
Posted on 9/16/25 at 7:09 pm to
quote:

Does he know how to scan for malware with Malwarebytes, etc.? I'm curious to know what he's infected with.


The person who sent was part of an organization and the IT head sent an email later acknowledging the breach.

Should I send him the email exchange?

quote:

I haven't read anything like this (malware auto response to people in the user's address book) on any of my security and tech websites.

I did light googling, saw nothing, and made this thread
Posted by GrammarKnotsi
Member since Feb 2013
10076 posts
Posted on 9/17/25 at 5:14 am to
quote:

I sent a separate email with "Email hacked" as the subject.



I bet you "unsubscribe" too and wonder why you get more and more junk
Posted by SlowFlowPro
With populists, expect populism
Member since Jan 2004
466154 posts
Posted on 9/17/25 at 7:06 am to
quote:

I bet you "unsubscribe" too and wonder why you get more and more junk


I get barely any junk in my primary inbox(es).

This was from a professional in an organization I deal with routinely. I know this person. Nothing ordinary this person sends me would be filtered.
Posted by ColdDuck
BR via da Parish
Member since Sep 2006
2969 posts
Posted on 9/17/25 at 7:57 am to
Malwarebytes or the like will not help. It is not the computer that got hacked, it is the email account. Victim may have clicked a bad link and signed in and that’s all they need. The bad link will steal the password AND the MFA token. They then just login to the mailbox and go to town. It is becoming an epidemic. They will make inbox rules to block responses to the spam they start sending out.
Posted by LemmyLives
Texas
Member since Mar 2019
13392 posts
Posted on 9/17/25 at 8:16 am to
quote:

t's all AI now


At what point are you idiots going to stop calling anything with programming, AI? JFC.
Posted by j1897
Member since Nov 2011
4299 posts
Posted on 9/17/25 at 10:12 am to
You need zero coding experience to run a local model that responds to emails.
Posted by SaintEB
Member since Jul 2008
23534 posts
Posted on 9/17/25 at 10:58 am to
quote:

At what point are you idiots going to stop calling anything with programming, AI? JFC.




This is exactly what an AI would say. Nice try Megan 2.0!
Posted by LemmyLives
Texas
Member since Mar 2019
13392 posts
Posted on 9/17/25 at 12:44 pm to
Megan was generally in a better mood than I am on TD.
Posted by evil cockroach
27.98N // 86.92E
Member since Nov 2007
8904 posts
Posted on 9/23/25 at 6:56 pm to
quote:

Anybody ever had phishing malware talk back them?
yep. I’ve had to call their cell phone .
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram