The week was packed with events in the cybersecurity sphere directly affecting cryptocurrency users. I analyzed the key incidents so you can assess the risks and take timely action.
Malware for macOS: Theft of Telegram Sessions and Substitution of Hardware Wallets
My colleagues from SlowMist thoroughly analyzed a new infostealer for macOS that demonstrates a frightening level of complex attack. The malware doesn't just steal data; it intercepts authorized sessions in Telegram Desktop, thus bypassing two-factor authentication. Once in the system, it copies local session files, allowing the attacker to log into the account on another device without entering a phone number or 2FA code.
Of particular danger is its ability to substitute legitimate applications for managing hardware wallets — Ledger Live and Trezor Suite. Exact copies are launched instead, whose sole purpose is to extract the seed phrase. Dozens of wallets were affected, including Exodus, Atomic, Electrum, as well as full node clients for Bitcoin Core and Litecoin Core. If you suspect your Mac is compromised, immediately terminate all active Telegram sessions and regenerate your seed phrase on a clean device.
Scattered Spider: Verdict for the Attack on London Transport
A British court sentenced two key members of the Scattered Spider group — 20-year-old Talha Jubair and 18-year-old Owen Flowers. They each received five and a half years in prison for hacking the IT infrastructure of Transport for London (TfL) in August 2024. The attack paralyzed 148 internal systems, disabling Dial-a-Ride services, digital payments, and the refund system. Damages and recovery costs amounted to £29 million, and in the event of a complete shutdown of the transport network, losses to the UK economy could have reached £56 billion.
Notably, during searches, evidence was found at Flowers' home of preparations for cyberattacks on American medical companies. The NCA called Scattered Spider the most serious cyber threat to the country in recent years. The group is responsible for extorting over $115 million in one year and hacking major retail chains. This is a clear example of how cybercrime is transitioning from the digital realm into a real threat to critical infrastructure.
Fake Repositories on GitHub: 292 Traps for Crypto Enthusiasts
Arctic Wolf specialists identified a large-scale phishing campaign that deployed 292 fake repositories on GitHub. They were disguised as popular antivirus software, developer utilities, and cryptocurrency services. Each repository contained a link to a landing page that dynamically adapted to the brand the victim was searching for. The user was prompted to download a ZIP archive, the contents of which were regenerated every minute to bypass signature analysis.
Inside the archive was a modified stealer, BoryptGrab, which operated exclusively in RAM. It stole data from 19 browsers, 32 crypto wallets, local Telegram sessions, Steam, and Discord tokens. I particularly note its ability to bypass Google Chrome protection by directly injecting code into the browser process. Most of the repositories have already been removed, but this does not guarantee new ones won't appear. Be extremely careful when downloading files from GitHub.
USA vs. Bulletproof Hosting: Charges Against Operators of Media Land and ML.Cloud
The US Department of Justice has charged three Russian citizens with operating Bulletproof hosting services Media Land and ML.Cloud. According to the investigation, their infrastructure was used by ransomware programs Lockbit, Blacksuit, and Play, causing damages exceeding $62 million. The hosting services deliberately ignored complaints about malicious activity and law enforcement demands. The owners — Alexander Volosovik (Yalishanda) and Yulia Pankova — along with payment collector Kirill Zatolokin, are charged with aiding cybercriminals.
The State Department announced a $10 million reward for information regarding the defendants' connections. The USA, UK, and Australia have already imposed sanctions, joined by the EU. This underscores the global nature of the fight against cybercrime and shows that even "protected" hosting services will not go unpunished.
OkoBot: SeedHunter Module Targets Hardware Wallet Seed Phrases
Kaspersky Lab discovered the malicious OkoBot framework attacking Windows users. Its SeedHunter module represents an advanced threat for owners of Ledger and Trezor devices. Instead of simply substituting the application, it injects malicious code into the processes of legitimate Ledger Live and Trezor Suite. The module does not manifest itself until the user connects the hardware wallet to the PC. At that moment, it blocks the interface and displays a fake window demanding the seed phrase, with the request originating from within the official program.
Besides SeedHunter, the framework contains over 20 malicious payloads: from hidden SSH tunnels to keyloggers and screen recording when password managers are opened. Hundreds of infections have been recorded in 25 countries, with attackers avoiding attacks on IP addresses from Russia and the CIS. This indicates a targeted selection of victims.
Browser Crypto Wallets: Study Reveals Privacy Issues
Researchers from KU Leuven analyzed 85 popular browser crypto wallets with an audience of over 35 million users. The results are shocking: the architecture of most allows third-party trackers to link user addresses, track their movements, and de-anonymize their identity. Key issues include linking addresses into a single profile (17 wallets), tracking after logout (36 wallets), and de-anonymization through hidden frames.
Particularly alarming is that major players like MetaMask and OKW have refused to acknowledge the problem, calling it a "known nuance." Only Coinbase Wallet, Coin98, and Hana Wallet have made corrections. This calls into question the very concept of privacy in Web3. I recommend regularly clearing the "list of connected sites" and using isolated browser profiles for crypto activity.
My Expert Opinion: This past week clearly demonstrates that cyber threats to the crypto industry are evolving from simple phishing attacks into complex, multi-layered schemes targeting hardware wallets and session data. The industry urgently needs to reconsider security standards at the application and browser extension level; otherwise, user trust in decentralized finance will be undermined.