Crypto news

15.08.2026
05:26

Cybercrime at the intersection of blockchain: the DeadLock extortionist masters Polygon, and Ukrainian police busted a network of fake exchangers

security_new4

The week was packed with events in the field of digital security: from physical scams with "offices" to decentralized ransomware infrastructures. I break down the key incidents and their significance for the crypto industry.

Ukrainian cyber police dismantled a network of fake Money 24/7 exchangers

Law enforcement officers detained the organizer of a fraudulent scheme that mimicked a legitimate exchange office. The criminals created a full-fledged "storefront": quality websites, an active Telegram channel, a registered brand, and even an office with a cash register. Clients wishing to buy cryptocurrency were invited in person, where they handed over cash but never received the coins. To buy time, victims were given back part of the funds or issued fictitious "guarantee letters."

Damages from one of the episodes exceeded 1.6 million hryvnias. During more than 20 searches in seven regions, over 20 million hryvnias in cash were seized. The organizer faces up to 12 years in prison. This is a telling example of how classic scams adapt to the crypto market, using psychological pressure and theatrical props.

FBI warns of a wave of hacks targeting intimate content

The Bureau is recording a surge in attacks aimed at stealing personal photos and videos from cloud storage. Particular attention is being paid to student athletes. The scheme is standard: phishing SMS or emails threatening account suspension, data theft, and then blackmail. Even after the ransom is paid, the content is often sold on the dark web, triggering a wave of repeat harassment. This is a reminder that digital hygiene is not just a buzzword but a necessity.

Cyberattack aboard a Delta Air Lines flight: hackers from DEF CON tested the Wi-Fi's strength

On flight 591, traveling from Las Vegas to Atlanta, an incident occurred that could have been the plot of a spy thriller. Passengers, many of whom were returning from the DEF CON 34 hacking conference, faced a forced disconnection from the legitimate Wi-Fi. The attackers deployed a fake network called "Delta WiFi Fast," which displayed a phishing page to steal Google passwords upon connection.

The crew quickly powered down the onboard network for 30 minutes. After landing, police interrogated the suspects and seized their equipment. It is important to note that the aircraft's navigation systems are isolated from the passenger network, so flight safety was not compromised. This case is a vivid illustration of the vulnerability of public networks, even at 10,000 meters altitude.

Jewelbug: a two-faced group combining espionage and crypto scams

Symantec analysts uncovered the dual activities of the Jewelbug (Earth Alux) group. On one hand, they conducted sophisticated operations against government structures in the Middle East and Asia, hacking webmail through compromised hosting. On the other, they simultaneously ran a large-scale fraudulent business: neural networks generated fake articles for hundreds of fake domains masquerading as Binance and OKX, while botnets promoted them in search engines.

The group's database contained millions of logs, hundreds of thousands of stolen cookies, and thousands of credentials. A custom trojan called ClientKing, written in Rust, was used to infect Linux servers. This hybrid model—from state-sponsored espionage to run-of-the-mill crypto scams—shows that the line between cyberwarfare and cybercrime is becoming increasingly blurred.

DeadLock: a new-generation extortionist based on Polygon

The DeadLock group, which attacks companies in the US, Europe, and Turkey, has revolutionized its infrastructure. Instead of traditional servers, they have fully transitioned to decentralization. The ransom note is now a full-fledged HTML application that directly interacts with smart contracts on the Polygon network. This allows hackers to instantly rotate proxy server IP addresses by simply updating data on the blockchain, rendering law enforcement blocklists useless.

Technically, the malware uses hybrid encryption with Curve25519 and XChaCha20, and skillfully masks its activity by pausing during high system load. Using a public blockchain to manage attacks is a wake-up call for the entire security community.

Cyberattack on a Polish thermal power plant: the first case of a hack via a private cellular network

CERT Polska revealed details of an incident that led to the physical shutdown of a steam turbine. The attackers infiltrated the system through the power grid operator's private cellular network, exploiting configuration vulnerabilities. They gained access to a wind farm without MFA, then penetrated the thermal power plant's internal network via a Teltonika router and a WAGO controller with a factory password. On December 29, they stopped Siemens S7 controllers, causing a real accident. This is the first documented case of such an attack vector being used against industrial facilities, highlighting the critical importance of network segmentation and changing default passwords.

My comment: The trend toward decentralization in cybercrime is a direct consequence of law enforcement pressure. Using blockchain to manage ransomware infrastructure is not just a trend but a new reality that must be reckoned with. The security industry needs to find asymmetric responses, as traditional methods of blocking and domain registries are losing effectiveness.