DeadLock expands into Polygon, Ukrainian cyber police dismantled a network of fake exchangers: weekly digest
The week was rich in cybersecurity events directly affecting the crypto industry. From the dismantling of an offline scam in Ukraine to the use of blockchain in ransomware infrastructure, I break down the key incidents shaping the threat landscape.
Ukraine: A Blow to "Physical" Crypto Scams
Ukrainian law enforcement shut down the fraudulent network Money 24/7, which masqueraded as a legitimate exchange service. The scheme was meticulously planned: the criminals created high-quality websites, rented an office for cash operations, and even registered a trademark. Clients who submitted online applications were invited to the office, where they handed over cash but never received cryptocurrency. To stall for time, victims were returned a small portion of the amount and given "guarantee letters."
During more than 20 searches across seven regions of the country, over 20 million hryvnias in cash, equipment, and documentation were seized. In one episode alone, the damage amounted to nearly 1.6 million hryvnias. The organizer faces up to 12 years in prison. This is a telling example that hybrid schemes combining online outreach and offline meetings remain a serious threat.
A New Era of Ransomware: DeadLock on Polygon
The most notable event for me was the disclosure of details about the ransomware group DeadLock. Instead of traditional servers, they have fully transitioned to decentralized infrastructure based on the Polygon blockchain. Victims are left not with a text file, but with a standalone HTML application called RECOVERY_CHAT that directly interacts with smart contracts.
This approach radically changes the game. The JavaScript code reads the proxy server's IP address from the smart contract, and if law enforcement blocks it, the hackers only need to update the record on the blockchain—the chat instantly works again. Data leaks are also published via the decentralized Wasabi protocol. This creates "endless options" for bypassing blocks and elevates the resilience of cybercriminal infrastructure to a fundamentally new level.
Other Notable Incidents
- FBI Warning: A surge in attacks on social media users aimed at stealing intimate photos and subsequent blackmail has been recorded. Student athletes are often the victims.
- Attack on Board: On a Delta Air Lines flight from Las Vegas, hackers returning from DEF CON created a fake network called Delta WiFi Fast, forcibly disconnecting passengers from legitimate Wi-Fi and collecting their data through a phishing page.
- Jewelbug's Double Life: A Chinese group targeting governments has been implicated in a large-scale crypto scam. They generated fake articles using neural networks and promoted counterfeit Binance and OKX sites through botnets.
My Commentary
DeadLock's transition to blockchain is a wake-up call for the entire community. Using public networks to manage malicious infrastructure makes combating it significantly harder, blurring the lines between legitimate DeFi and cybercrime. The industry urgently needs to develop new methods of analytics and response, as traditional approaches to blocking domains and servers are losing effectiveness.