DeadLock expands into Polygon, Ukrainian cyber police bust a network of fake exchangers: cybersecurity digest

This week, the cyber threat landscape delivered several unexpected twists: from traditional scam schemes in an offline format to a radical evolution of ransomware moving toward decentralization. I'm breaking down the key incidents that demand close attention from the industry.
Ukrainian cyber police dismantled the offline scam Money 24/7
Ukrainian law enforcement shut down the activities of the fraudulent network Money 24/7, which masterfully imitated a legitimate exchange service. The scheme was built on creating a "perfect picture": high-quality websites, an active Telegram channel, a registered trademark, and even an office with a cash register to lull clients' vigilance. Victims left online requests to buy cryptocurrency, after which they were invited to the office to hand over cash. The money disappeared, and the assets never reached their wallets.
To buy time, the scammers used psychological tricks: they transferred part of the amount and issued "guarantee letters." During more than 20 searches in seven regions, over 20 million hryvnias in cash and equipment were seized. The organizer faces up to 12 years in prison. This is a striking example of how classic scams adapt to the crypto industry, leveraging trust in "physical" presence.
FBI records a wave of attacks stealing intimate data
The Bureau warned of a surge in cyberattacks targeting the theft of intimate photos and videos from social networks and cloud storage. Particular attention is paid to student athletes. The attacks begin with phishing SMS and emails imitating account lockouts. The attackers demand a ransom, and after payment, they often sell the content on the dark web along with personal data, triggering new waves of harassment.
Hackers from DEF CON attacked Wi-Fi on board Delta Air Lines
On Delta Air Lines flight 591, traveling from Las Vegas to Atlanta, passengers were subjected to a cyberattack. The attackers, using spoofed data packets, forcibly disconnected devices from the legitimate Wi-Fi and deployed a fake network called "Delta WiFi Fast" to collect passwords, including those for Google accounts. The crew cut off the onboard internet for 30 minutes, and after landing, police interrogated the suspects. The incident highlights the vulnerability of even isolated systems, where the passenger network can become an attack vector.
Jewelbug: the double life of Chinese hackers
Symantec analysts uncovered the activities of the Jewelbug group, which combines government espionage with crypto fraud. The hackers attacked government institutions in the Middle East and Asia through a compromised web hosting platform, injecting JavaScript code to steal session cookies. In parallel, they used neural networks to generate fake articles on spoofed domains masquerading as Binance and OKX, promoting them through botnets. Their database contained more than 580,000 stolen cookies and thousands of credentials.
DeadLock ransomware moves to the Polygon blockchain
The DeadLock group, which attacks the US, Europe, and Turkey, has taken a revolutionary step by abandoning traditional servers in favor of decentralization. As reported by Microsoft and Group-IB experts, their ransom notes are autonomous HTML applications that directly interact with smart contracts on Polygon. This allows rotating proxy server IP addresses without needing to change files on the victim's side—just updating a record in the contract is enough. Breach data is also published through decentralized protocols. This creates "endless options" for bypassing blocks and elevates infrastructure resilience to a new level.
Technically, the malware uses hybrid encryption with Curve25519 and XChaCha20, and to disguise itself, it pauses the process during high system load.
Cyberattack on a Polish combined heat and power plant: the first case of a breach via a cellular network
CERT Polska revealed details of an attack on a combined heat and power plant providing heat to 50,000 residents. The attackers infiltrated critical infrastructure through the private cellular network of the power grid operator. The attack chain began with a wind power plant lacking MFA, then through a firewall and a Teltonika router, the hackers reached a WAGO controller with a factory default password. This allowed them to stop a steam turbine by switching Siemens S7 controllers to stop mode. The uniqueness of the incident lies in the use of standard equipment functions and the first documented case of an attack via a cellular network.
My analysis: DeadLock's move to the blockchain is not just a trend but a paradigm shift. While regulators and intelligence agencies fight domains and servers, hackers are moving into an environment where there is no centralized point of failure. The industry will have to rethink its approaches to cybersecurity, viewing smart contracts as a new attack vector and a new shield for malicious actors.