Crypto news

15.08.2026
05:05

DeadLock moves to Polygon, Ukrainian cyber police dismantled a network of fake exchangers, and other key cybersecurity events of the week.

security_new4

The week was packed with events in the world of cybersecurity. I analyzed the key incidents, from large-scale fraud schemes to groundbreaking attacks on critical infrastructure. Here are my main takeaways.

Ukraine: Dismantling the Money 24/7 Fake Exchange Network

Ukrainian cyber police dealt a serious blow to organized crypto fraud. The organizer of a network masquerading as a legitimate exchange service has been charged. The scheme was meticulously planned: the attackers created high-quality websites, actively ran a Telegram channel, registered a trademark, and even rented an office with a cash register. Clients were lured with promises of favorable exchange rates, invited to the office where cash was collected, but the cryptocurrency was never transferred. To keep victims from going to the police, they used stalling tactics with partial payments and "written guarantees." During more than 20 searches across seven regions of the country, over 20 million hryvnias in cash and equipment were seized. The organizer faces up to 12 years in prison with asset confiscation.

FBI Warns of a Wave of Attacks on Intimate Photos

The American bureau is recording a surge in cyberattacks targeting the theft of explicit photos and videos from social networks and cloud storage. Particular attention is being paid to student-athletes. The attack mechanics are standard: phishing SMS or emails demanding a "password reset." Upon discovering compromising material, hackers demand a ransom, threatening to make it public. Notably, even after payment, victims' data is often sold on the dark web, leading to a new wave of harassment and extortion.

Attack Onboard Delta Air Lines: Hackers from DEF CON Test the Wi-Fi's Strength

The incident on a Delta Air Lines flight from Las Vegas to Atlanta is a striking example of cyberattacks in the physical world. Passengers returning from the DEF CON hacking conference encountered spoofed data packets that forcibly disconnected their devices from the legitimate Wi-Fi. Simultaneously, the attackers deployed a fake "Delta WiFi Fast" network with a phishing login page. The crew was forced to power down the onboard Wi-Fi for 30 minutes. After landing, police questioned suspects and seized their equipment. This case highlights the vulnerability of aviation systems to attacks aimed at data collection, although navigation systems are, fortunately, isolated.

Jewelbug: The Double Life of Chinese Hackers

Symantec analysts have uncovered the group Jewelbug (Earth Alux), which combined government cyberespionage with large-scale crypto fraud. On one hand, they attacked government and military structures in the Middle East and Asia, breaching webmail through compromised hosting. On the other, they used neural networks to generate fake articles and hundreds of fake domains masquerading as Binance and OKX, with botnets pushing them to the top of search engines. The group's database contained over a million logs, 580,000 stolen cookies, and thousands of credentials. They even used a custom trojan written in Rust and hid malicious payloads in Google Docs. These are no longer just hackers, but a full-fledged "criminal business conglomerate."

DeadLock: The Ransomware That Went Blockchain

The most technologically interesting event of the week is the transition of the DeadLock ransomware group to decentralized infrastructure based on the Polygon blockchain. Instead of traditional servers, they use smart contracts to rotate proxy server addresses. The ransom note is a standalone HTML application with a built-in chat and a browser for stolen data. If law enforcement blocks a server, the hackers simply update the record in the smart contract. This creates "endless options" for bypassing blocks. Technically, the malware uses hybrid cryptography with Curve25519 and XChaCha20, and cleverly masks its activity by pausing the process during high system load. This is a worrying signal: we are seeing cybercriminals adapt to decentralized technologies, making their infrastructure nearly invulnerable.

Poland: The First-Ever Attack on a Combined Heat and Power Plant via a Private Cellular Network

CERT Polska has revealed details of an attack on a combined heat and power plant supplying heat to about 50,000 residents. The uniqueness of the case lies in the penetration vector: through the private cellular network of the local power grid operator. The attack chain included breaching a wind power plant without MFA, infiltrating via a Teltonika router and a WAGO controller with a factory password. Ultimately, the hackers switched the Siemens S7 industrial controllers to stop mode, leading to a physical shutdown of the steam turbine. They methodically destroyed evidence by resetting equipment settings. This is the first documented case of using such a vector in a real attack on an industrial facility, forcing a rethink of security approaches in the energy sector.

My analysis: The main takeaway of the week is that cybercrime is becoming increasingly professional and diversified. We are seeing a convergence of state-sponsored espionage with financial fraud, as well as the shift of ransomware groups to "unsinkable" decentralized platforms. Regulators and companies will have to radically rethink their defense strategies, betting on proactive monitoring and multi-factor authentication not only for employees but also for all connected equipment.