Luis Mijangos would hack his victims and then spy on them using their own webcams and microphones A 32-year-old paraplegic was sentenced to six years in prison for infecting more than 100 computers in a quest for financial information, nude photographs and thrills.Luis Mijangos worked as a freelance computer consultant in Santa Ana, California, earning about US$1,000 per week writing programs and building websites. But he lived a double life, also earning as much as $3,000 per day hacking and stealing financial information from his victims. He built virtually undetectable malware and used a variety of techniques to trick his victims into installing it on their computers. Then, he did more than just steal bank account numbers. “He read victims’ e-mails and IMs, watched them through their webcams, and listened to them through the microphones on their computers,” prosecutors said in court filings. “Often, he then used the information he obtained to play psychological games with his victims.”One victim, a juvenile identified by prosecutors only as S.G., sent Mijangos pornographic photos after he hacked into her computer and tricked her over instant message into believing he was her boyfriend. Mijangos then threatened to post the photos online if she didn’t send him more pictures. “It made me untrusting and paranoid to this day,” S.G. wrote in a victim impact statement. “I didn’t know who this man was, why he was doing it or [if] he would come back. Not knowing is the worst, most dreaded feeling.”Mijangos stole nude photos from the laptop of another victim — a college student identified as A.V. — and then listened in on her computer’s microphone when the scared girl reported the incident to campus police. He then sent threatening e-mails to A.V. and her boyfriend to punish them for contacting authorities. According to court filings, “She reported feeling ‘terrorized’ by [Mijangos], was afraid for her safety, and did not leave her dorm room for a week after the episode.” As part of his criminal hacking life, Mijangos told police that he used open-source cryptor software to make malicious programs undetectable by antivirus programs. He worked with other criminals he met in an international online IRC (Internet Relay Chat) forum for identity thieves called CC Power.He spread his malware — often remote access tools such as Poison Ivy or SpyNet – by disguising it as a song on peer-to-peer networks or e-mailing or instant messaging it to victims disguised as a video.Mijangos pleaded guilty to hacking and wiretapping in March. He was sentenced Thursday in Los Angeles at the U.S. District Court for the Central District of California.He’s the latest in a string of hackers to be accused of “sextortion” — breaking into computers or e-mail accounts and then threatening to post compromising photographs unless his victims provide him with more pictures.In January, George Bronk of Sacramento, California, pleaded guilty to charges that he broke into more than 3,200 e-mail accounts looking for sexy photos, which he then threatened to post to the Internet. He was sentenced to four years in prison. In February, James Dale Brown of Fremont, California, admitted that he tried to coerce a 14-year-old girl into sending him a pornographic video by threatening to post explicit pictures of her online.The U.S. Federal Bureau of Investigation has seen a rise in this type of case, said Steven Martiniez, the assistant director of the FBI’s Los Angeles field office, in a statement. Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert’s e-mail address is robert_mcmillan@idg.com Related content news Google Chrome zero-day jumps onto CISA's known vulnerability list A serious security flaw in Google Chrome, which was discovered under active exploitation in the wild, is a new addition to the Cybersecurity and Infrastructure Agency’s Known Exploited vulnerabilities catalog. By Jon Gold Oct 03, 2023 3 mins Zero-day vulnerability brandpost The advantages and risks of large language models in the cloud Understanding the pros and cons of LLMs in the cloud is a step closer to optimized efficiency—but be mindful of security concerns along the way. By Daniel Prizmant, Senior Principal Researcher at Palo Alto Networks Oct 03, 2023 5 mins Cloud Security news Arm patches bugs in Mali GPUs that affect Android phones and Chromebooks The vulnerability with active exploitations allows local non-privileged users to access freed-up memory for staging new attacks. By Shweta Sharma Oct 03, 2023 3 mins Android Security Vulnerabilities news UK businesses face tightening cybersecurity budgets as incidents spike More than a quarter of UK organisations think their cybersecurity budget is inadequate to protect them from growing threats. By Michael Hill Oct 03, 2023 3 mins CSO and CISO Risk Management Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe