The past week in cybersecurity was eventful: from court sentences for participants in high-profile attacks to sophisticated vector attacks on crypto wallets. Let's break down the key events that should alert every market participant.
Sentence for Scattered Spider hackers: £29 million in damages and five years in prison
A British court sentenced two key figures of the Scattered Spider group — 20-year-old Talha Jubaier and 18-year-old Owen Flowers. Both were found guilty of hacking the IT infrastructure of Transport for London (TfL) in August 2024. The attack disabled 148 internal systems, including digital payments and the Dial-a-Ride service, costing the city £29 million in direct damages and restoration work. According to authorities, a complete shutdown of the transport network could have caused up to £56 billion in damage to the UK economy. Both attackers were arrested two weeks after the incident, and evidence of preparations for cyberattacks on US medical institutions was found on Flowers' devices. Overall, the group is responsible for over $115 million in extortion in one year and the hacking of at least 120 networks in the US.
macOS stealer: Theft of Telegram sessions and substitution of hardware wallets
Researchers from SlowMist have uncovered a comprehensive infostealer for macOS that operates on multiple fronts. The malware intercepts authorized Telegram Desktop sessions, allowing hackers to gain access to an account bypassing 2FA by simply copying local session files. Additionally, the virus replaces legitimate applications for managing hardware wallets — Ledger Live and Trezor Suite — with their phishing copies, forcing the user to enter a seed phrase. Data from Keychain, Safari, Apple Notes, as well as databases of over a dozen crypto wallets, including Exodus, Atomic, Electrum, and Monero, have been targeted. I recommend all macOS users immediately check active Telegram sessions and, if compromise is suspected, generate a new seed phrase on a clean device.
292 fake repositories on GitHub: New wave of infostealers
Arctic Wolf specialists have identified a large-scale campaign distributing the BoryptGrab stealer through 292 fake repositories on GitHub. Attackers disguised them as popular antiviruses, crypto services, and gaming utilities. Each repository contained a link to a phishing landing page that dynamically adapted to the brand the victim was searching for. Inside the ZIP archive was an updater with a WinGUP digital signature and the libcurl.dll trojan, which operates exclusively in RAM and bypasses Google Chrome's protection. The stealer steals data from 19 browsers, 32 crypto wallets, local Telegram and Steam sessions, as well as files whose names contain keywords like "password" or "seed phrase." GitHub administration has already removed most of the repositories, but the threat remains high.
Charges against operators of Russian bulletproof hosting services
The US Department of Justice has charged three Russian citizens with operating the bulletproof hosting services Media Land and ML.Cloud. According to the investigation, their infrastructure was used by the Lockbit, Blacksuit, and Play ransomware programs, causing over $62 million in damages. Victims include banks, schools, and government structures in 20 US states. The State Department has announced a $10 million reward for information about the defendants' connections. This is already the second major blow against Russian hosting providers who deliberately ignore complaints about malicious activity.
Expert summary
The trend of the week is clear: attackers are increasingly targeting hardware wallets by substituting legitimate software and stealing session data. macOS is no longer a "safe" platform for crypto assets. I recommend using isolated browser profiles, regularly checking active Telegram sessions, and never entering a seed phrase into interfaces that were not downloaded from the manufacturer's official website. The threat is real and cannot be ignored.