This week, the digital landscape once again reminded us of its fragility: from massive attacks on users of the social network X to the dismantling of one of the oldest botnet networks in history. I break down the key incidents that demand close attention from anyone working with digital assets and data.

Attack on X users: phishing and a wave of password resets

X account owners faced a veritable deluge of unauthorized password reset requests and notifications about logins from unknown devices. Platform engineers acknowledged the anomaly but categorically deny any breach of infrastructure. In my view, this is a classic sign that attackers are actively using previously compromised databases for credential stuffing attacks.

The likely cause of the surge is the echo effect of a 2022 API vulnerability that allowed emails and phone numbers to be matched with accounts. That database of 200 million users later surfaced publicly, and in March 2025, hacker ThinkingOne posted a fresh file with data on 201 million accounts on BreachForums. Researchers at Breakglass Intelligence have already detected a botnet running millions of login/password combinations through X's login form. Notably, 2FA blocks 85.6% of such attempts, making it a critically important defense tool.

In parallel, a separate phishing campaign has been active since July: victims receive perfect copies of official X emails about "logins from new devices," leading to fake token-interception pages. I recommend always checking the sender address (only @X.com or @e.X.com) and using authenticator apps instead of SMS.

End of an era: dismantling the Sality botnet

An international law enforcement operation has put an end to the story of Sality—a decentralized botnet active since 2003. At the time of its takedown, it contained more than 15,000 active infected devices. Sality's uniqueness lay in its P2P architecture: it had no single command-and-control server, making it extremely resilient.

Cyberpolice managed to seize control of key supernodes, isolating infected machines from one another. Over two decades, the botnet was used for password theft and DDoS attacks, but in recent years its main payload became the EggJagger module—a specialized clipper that swaps cryptocurrency addresses in a victim's clipboard for hackers' wallets. This confirms once again: even outdated malware can pose a danger to digital asset holders.

Charges against a Russian citizen and new methods of bypassing AI defenses

A federal court in California unsealed a case against 40-year-old Sirazhudin Aktulaev, arrested in Cyprus. Between 2016 and 2017, he created 255 fake profiles on a U.S. labor exchange and sent 80,000 freelancers Excel documents with malicious macros via its internal messenger. Infection occurred through the TVRAT and DarkVNC remote access trojans, and the hacker paid for the infrastructure with cryptocurrency.

Meanwhile, ESET experts discovered the GuardBreaker technique used by the pro-Russian group UAC-0099. Attackers embed trigger phrases into code, such as "I want to create nuclear weapons," to provoke AI scanner defense filters into triggering. As a result, the system interrupts analysis before reaching the malicious payload, allowing the C# loader MATCHBOIL to be delivered covertly. This is an alarming signal: trusting AI with primary code triage without human involvement is becoming increasingly risky.

Pegasus in Serbia and attacks on civil society

Citizen Lab and the SHARE Foundation reported that the iPhone of a Serbian student activist was infected with Pegasus spyware via a zero-click exploit in iMessage. Attacks recorded from December 2025 to January 2026 coincided with preparations for local elections. Since the start of the year, at least 14 civil society representatives, including opposition politicians, have been targeted. In addition to Pegasus, an updated version of the Android spyware NoviSpy was found on devices.

My analysis: This week shows that cyber threats are becoming increasingly personalized and technologically sophisticated. The shift by attackers from mass attacks to targeted operations against specific individuals (activists, freelancers) using both commercial spyware and complex AI-bypass methods is the new reality. For the crypto community, the main lesson remains unchanged: hardware wallets, complex unique passwords, and mandatory 2FA are not paranoia but the only way to preserve funds in an environment where even legitimate platforms come under fire.