Crypto news

15.08.2026
05:45

DeadLock expands into Polygon, Ukrainian cyber police dismantled a network of fake exchangers, and other cybersecurity events of the week.

security_new4

This week, several landmark events took place in the world of cybersecurity: from the dismantling of a major fraudulent scheme in Ukraine to the unconventional use of blockchain in the arsenal of extortionists. I break down the key incidents shaping new trends in digital threats.

Ukraine: Dismantling of the Fake Exchange Network Money 24/7

Ukrainian cyber police shut down the activities of the fraudulent network Money 24/7, which masqueraded as a legitimate currency and crypto-asset exchange service. The organizers created the appearance of a reliable company: quality websites, an active Telegram channel, a registered trademark, and even an office equipped with a cash register. Clients were invited to hand over cash in person, but the promised cryptocurrency never reached their wallets. To buy time and delay police reports, the fraudsters partially paid out sums and issued "written guarantees." During more than 20 searches across seven regions, over 20 million hryvnias in cash were seized. The organizer faces up to 12 years in prison. In just one confirmed episode, the damage amounted to nearly 1.6 million hryvnias.

FBI Warns of a Wave of Hacks to Steal Intimate Photos

The FBI, together with the National Collegiate Athletic Association, is recording a surge in attacks targeting the theft of personal photos and videos from social networks and cloud storage. Attackers use phishing SMS and emails, scaring victims with account lockouts. After gaining access to intimate materials, hackers demand a ransom, threatening publication. Even after payment, the stolen content is often sold on the dark web along with personal data, fueling a new wave of extortion. Special attention is being paid to student-athletes.

Cyberattack on Board a Delta Air Lines Flight

Delta Air Lines is investigating an incident on flight 591, traveling from Las Vegas to Atlanta. Among the passengers were participants of the DEF CON 34 hacking conference. Attackers sent fake data packets, disconnecting passengers' devices from the legitimate Wi-Fi, and created a fake network called Delta WiFi Fast with a phishing login page to steal data. The crew disabled the onboard Wi-Fi for 30 minutes. After landing, police interrogated suspects and seized their equipment. Flight safety was never threatened.

Chinese Group Jewelbug: Espionage and Crypto Fraud

Symantec analysts uncovered the dual activities of the group Jewelbug (Earth Alux). The hackers attacked government and military structures in the Middle East and Asia, breaching webmail through a compromised hosting platform. In parallel, they ran a large-scale fraudulent business: neural networks generated fake articles for hundreds of fake domains masquerading as Binance and OKX, while botnets pushed them to the top of search engines. The group's database contained over a million logs of malicious activity, 580,000 stolen cookies, and thousands of credentials. For infection, they used a Rust-based trojan called ClientKing.

DeadLock Ransomware Moves to Decentralization via Polygon

The ransomware group DeadLock, which attacks companies in the US, Europe, and Turkey, has introduced an innovative approach to protecting its infrastructure. Instead of traditional servers, they use the Polygon blockchain. The ransom note is a standalone HTML application that directly interacts with smart contracts to rotate proxy server addresses. When one IP is blocked, hackers simply update the record in the contract, and communication is restored. This creates "endless options" for bypassing blocks. Technically, the malware uses hybrid encryption with Curve25519 and XChaCha20, disguises processes under load, and self-destructs, removing traces.

Cyberattack on a Polish CHP Plant: First Case via a Private Cellular Network

CERT Polska revealed details of an attack on a combined heat and power plant providing heat to 50,000 residents. The uniqueness of the incident lies in the fact that attackers breached critical infrastructure through the power grid operator's private cellular network. Using factory passwords and the lack of MFA, hackers moved from a wind farm through a firewall and a Teltonika router to a WAGO controller, and then into the CHP plant's internal network. They stopped the turbine and the water treatment system, then destroyed evidence by resetting equipment settings. System operations were restored by staff.

My comment: The decentralization of ransomware infrastructure via blockchain is an alarming signal for the entire security industry. Using smart contracts to manage C2 servers makes combating such groups fundamentally more difficult. Law enforcement will have to rethink its countermeasures, and companies must prioritize basic security hygiene, since most attacks still begin with simple configuration errors.