The past week in the world of cybersecurity was marked by several significant events that directly affect the crypto community. From court verdicts to new, sophisticated methods of stealing digital assets, let's break down the key threats.
Scattered Spider Verdict: A Blow to One of the Most Dangerous Groups
A British court sentenced two key figures of the notorious Scattered Spider group — Talha Jubair and Owen Flowers — to actual prison terms. Their main "achievement" was hacking the IT infrastructure of Transport for London (TfL) in August 2024, which paralyzed key services for millions of passengers. The damage from this attack exceeded £29 million, and potential losses for the UK economy were estimated at £56 billion. This is a serious signal for the entire crypto community: law enforcement has learned to effectively track and punish even the most daring hackers specializing in extortion and data theft.
A New Wave of Threats for macOS and Hardware Wallets
Particular attention should be paid to malware for macOS, which demonstrates a comprehensive approach to stealing cryptocurrencies. This infostealer not only steals passwords from the keychain but also intercepts authorized Telegram sessions, bypassing two-factor authentication. However, its most dangerous feature is the attack on hardware wallets. The malware replaces legitimate Ledger Live and Trezor Suite applications with phishing copies, forcing the user to enter their seed phrase. Remember: no official developer will ever ask you to enter your seed phrase in an application. If you see such a request, it is one hundred percent phishing.
Fake Repositories on GitHub: A Trap for Developers
A massive campaign using nearly 300 fake repositories on GitHub targets developers and crypto enthusiasts. Attackers disguise malware as antiviruses, crypto services, and gaming utilities. A feature of the attack is the dynamic generation of phishing pages and updating the archive contents every minute, making it difficult to detect. The BoryptGrab virus, distributed this way, steals data from 32 crypto wallets, Telegram and Steam sessions. This is a reminder that software should only be downloaded from official websites, not from dubious repositories.
USA vs. Bulletproof Hosting Providers: A Massive Raid
The U.S. Department of Justice has charged three Russian citizens who operated the bulletproof hosting providers Media Land and ML.Cloud. Their servers were used to deploy ransomware such as Lockbit and Play, causing damages exceeding $62 million. This shows that using "secure" hosting providers that ignore law enforcement requests is no longer a guarantee of anonymity for cybercriminals. A reward of $10 million has been announced for information leading to the exposure of their connections.
OkoBot and SeedHunter: Hunting for Seed Phrases in Real Time
The malicious framework OkoBot, discovered by Kaspersky Lab experts, represents a new generation of threats. Its SeedHunter module does not just replace an application but injects malicious code directly into the processes of legitimate Ledger Live and Trezor Suite. It activates only after the hardware wallet is physically connected to the PC, displaying a fake window for entering the seed phrase. The "injection into a trusted process" technique makes this attack extremely difficult to detect, even for experienced users.
Browser Wallets in the Crosshairs of Tracking
A study of 85 popular browser-based crypto wallets revealed systemic privacy issues. It turns out that the architecture of most of them allows third-party trackers to link user addresses and de-anonymize them. MetaMask, Rabby, and OKX refused to recognize these risks as serious vulnerabilities. This clearly demonstrates that privacy in Web3 is not a given but a responsibility of the user. Using isolated browser profiles and manually clearing the list of connected sites are becoming mandatory precautions.
My Expert Opinion: The current week clearly demonstrates that cybercrime in the crypto sphere is moving to a new level — from mass attacks to targeted, multi-stage operations aimed at hardware wallets and personal data. Users need to reconsider their security model: a hardware wallet is not a panacea if it is connected to an infected computer. The only reliable way to protect your assets is cold storage of the seed phrase and using isolated, clean devices for any transactions.