Crypto news

15.08.2026
09:08

DeadLock moves to Polygon, Ukrainian fake exchangers shut down, and other cyber events of the week

security_new4

Another week brought a whole range of incidents—from the dismantling of fraudulent schemes in Ukraine to the innovative use of blockchain in ransomware attacks. I break down the key events shaping the threat landscape.

Ukraine: Dismantling the Money 24/7 Fake Exchange Network

Ukrainian law enforcement shut down the fraudulent Money 24/7 network, which masqueraded as a legitimate currency and crypto-asset exchange service. The scheme was meticulously planned: the criminals created polished websites, actively ran a Telegram channel, registered a trademark, and even rented an office equipped with a cashier's station to create an illusion of reliability.

Victims submitted online requests to buy cryptocurrency, after which they were invited to the office to hand over cash. The money disappeared, and the promised coins never arrived. To buy time, the scammers partially refunded funds or issued "written guarantees." During more than 20 searches across seven regions of the country, over 20 million hryvnias in cash were seized. The organizer faces up to 12 years in prison. This is a striking example of how classic "physical" scams adapt to the cryptocurrency theme.

FBI Warns: The Hunt for Intimate Photos

The FBI, together with the National Collegiate Athletic Association, has recorded a surge in attacks targeting the theft of intimate photos and videos from social media and cloud storage. Student-athletes are at particular risk. The attacks begin with phishing SMS or emails, where victims are frightened by the threat of account suspension and coerced into clicking a link or providing a verification code.

After breaching accounts, hackers demand a ransom, threatening to publish the material. However, even after payment, the stolen content and personal data are often sold on the dark web, triggering a new wave of extortion and harassment. This is a reminder that digital hygiene and multi-factor authentication are not just recommendations but necessities.

Cyberattack Aboard Delta Air Lines

An incident on Delta Air Lines flight 591, traveling from Las Vegas to Atlanta, drew the attention of the entire industry. On board were attendees of the DEF CON 34 hacking conference. The attackers forcibly disconnected passengers' devices from the legitimate Wi-Fi, deploying a fake "Delta WiFi Fast" network with a phishing login page to steal Google passwords.

The crew, detecting the anomaly, disabled the onboard Wi-Fi for 30 minutes. After landing, police questioned the suspects and seized portable hacking equipment. Importantly, the aircraft's navigation systems are isolated from the passenger network, so flight safety was never threatened. This case demonstrates how sophisticated attacks in the real world are becoming.

Jewelbug: Espionage and Crypto Fraud in One Package

Symantec analysts uncovered the double life of the Chinese group Jewelbug (Earth Alux). Alongside cyberespionage against government entities in the Middle East and Asia, the hackers ran a large-scale crypto fraud business. They compromised the web hosting platform of a state telecom provider, injecting JavaScript code that stole officials' session cookies.

For high-value targets, a fake Adobe Flash was used to install backdoors. The group's infrastructure included neural networks generating fake articles on hundreds of spoofed domains masquerading as Binance and OKX. Botnets promoted these sites to the top of search engines. The database contains over a million logs, 580,000 stolen cookies, and thousands of credentials. This is an alarming signal: state-sponsored hackers are increasingly monetizing their skills in the crypto sphere.

DeadLock: Next-Generation Ransomware on Polygon

The DeadLock group, with nearly a hundred victims in the US, Europe, and Turkey, has revolutionized its approach to infrastructure. Instead of traditional servers, the hackers have fully embraced decentralization. Their ransom note is a standalone HTML application with a chat feature that runs directly in the browser. The JavaScript code interacts directly with smart contracts on the Polygon blockchain.

The application reads the current IP address of the proxy server from the smart contract. If law enforcement blocks it, the hackers simply update the record in the contract—and the chat works again. Posts about breaches and leaked data are also tied to smart contracts and distributed via the decentralized Wasabi protocol. This creates "literally endless options" for bypassing blocks. Technically, the malware uses a hybrid of Curve25519 and XChaCha20, disguises itself as system load, and self-destructs after execution.

Poland: Cyberattack on a Combined Heat and Power Plant via Cellular Network

CERT Polska revealed details of an attack on a combined heat and power plant supplying heat to about 50,000 residents. The uniqueness lies in the penetration vector: hackers reached critical infrastructure through the private cellular network of the power grid operator. They exploited a wind farm without MFA, then penetrated the plant's internal network via a Teltonika router and a WAGO controller with a factory-default password.

On December 29, the attackers switched Siemens S7 controllers to stop mode, causing a physical shutdown of the steam turbine. They methodically destroyed evidence by resetting equipment settings. This is the first recorded case of such a vector being used in a real attack on industrial facilities. The human factor and neglect of basic security hygiene once again proved decisive.

My comment: DeadLock's shift to blockchain is not just a technical trick but a paradigm change. Law enforcement can no longer "switch off" ransomware infrastructure by blocking domains or servers. This raises the stakes for the entire cybersecurity industry and demands new approaches to counteraction.