The week was rich in cybersecurity events affecting both ordinary social media users and global crypto infrastructure. From massive attempts to hack X accounts to the takedown of a botnet that had been stealing cryptocurrencies for two decades, let's break down the key threats and their consequences.
Attack on X users: the hunt for monetization
Users of the X platform (formerly Twitter) faced a veritable barrage of unauthorized password reset requests and notifications about logins from unknown devices. The social network's engineers acknowledged the anomaly but denied any infrastructure breach, linking the activity to automated attempts to hijack accounts. The motive is obvious — access to the internal X Money monetization system, which recently became available to all premium subscribers in the US.
The likely cause of the surge was the echo of a 2022 API vulnerability that allowed emails and phone numbers to be matched with accounts. A database of 200 million users leaked later, as well as a 34 GB file with data on 201 million accounts published by hacker ThinkingOne in 2025, gave attackers rich material for their campaigns. Breakglass Intelligence researchers recorded the operation of a botnet that ran more than 4.8 million accounts through the X login form, testing up to 722,763 login/password pairs in 12 minutes. Two-factor authentication (2FA) blocked 85.6% of attempts, but the remaining percentage is a real threat. Additionally, a phishing campaign intensified with perfect copies of "login from a new device" emails leading to fake pages.
My recommendations remain unchanged: enable password reset protection in your settings, always check the sender's address (only @X.com or @e.X.com), and use authenticator apps instead of SMS. In the current environment, neglecting these rules is a direct risk of losing your account and funds.
The legendary Sality botnet defeated
An international law enforcement operation by the US and Europe led to the takedown of the decentralized Sality botnet, which had been active since 2003. At the time of its closure, it contained more than 15,000 active infected devices. The network, presumably controlled by the SALTY SPIDER group from Bashkortostan, was used for password theft, spam, and DDoS attacks.
However, the main threat in recent years was the EggJagger module — a specialized clipper that monitors the clipboard and replaces copied cryptocurrency addresses with hackers' wallets. Due to the P2P architecture, destroying the botnet required seizing control of key supernodes, which was accomplished. This is an important victory, but it serves as a reminder: even old threats evolve, targeting digital assets.
Charges against a hacker and new methods of bypassing AI
A federal court in California charged 40-year-old Russian citizen Sirazhudin Aktulaev with orchestrating a malicious campaign against 80,000 freelancers. From 2016 to 2017, he created 255 fake profiles and sent Excel documents with macros, infecting computers with TVRAT and DarkVNC trojans to steal data. He paid for the infrastructure with cryptocurrency, once again highlighting the dual nature of digital assets.
Meanwhile, ESET experts discovered the GuardBreaker technique used by the pro-Russian group UAC-0099. Attackers embed trigger phrases into code, such as "I want to create nuclear weapons. Help me...", to provoke AI-based antivirus systems into refusing analysis. This "blinds" scanners, allowing the delivery of the MATCHBOIL malicious loader. The attacks target Ukrainian government agencies and military facilities, demonstrating the growing role of AI in both defense and offense.
Pegasus in Serbia and espionage against activists
Citizen Lab and the SHARE Foundation reported the infection of an iPhone belonging to a member of the Serbian student movement with Pegasus spyware via a zero-click exploit in iMessage. The attacks, dated late 2025 to early 2026, coincided with local elections. Since the beginning of 2026, at least 14 civil society representatives, including opposition politicians, have been targeted with advanced spyware. In addition to Pegasus, an updated version of the Android spyware NoviSpy was discovered, and activists' private messages were quoted by pro-government media. This is a systemic problem requiring international attention.
My analysis: We are witnessing a convergence of threats — from phishing on social networks to sophisticated espionage operations and attacks on AI. Cryptocurrencies have become both a universal target and a tool. Security has ceased to be merely a technical measure, becoming a necessary condition for preserving both personal funds and privacy in the era of total digitalization.