DeadLock is mastering Polygon, Ukrainian fake exchangers have been shut down, and other cyber threats of the week

Another week brought a whole spectrum of incidents—from run-of-the-mill scams with offices and cash registers to a revolutionary use of blockchain in ransomware infrastructure for cybercrime. I break down the key events that will shape the threat landscape in the near future.
Ukrainian cyber police dismantled the fake exchange network Money 24/7
A large-scale fraudulent scheme masquerading as a legitimate exchange service has ceased to exist. The organizers operated on a grand scale: they created polished websites, ran an active Telegram channel, registered a trademark, and even rented an office equipped as a cash desk. Clients who submitted online applications to buy cryptocurrency were invited to this office, where they handed over cash but never received the digital assets. To stall for time, the scammers transferred a small portion of the amount to victims and issued "written guarantees." During more than 20 searches across seven regions, over 20 million hryvnias in cash and equipment were seized. The organizer faces up to 12 years in prison. This is a telling example of how attackers try to combine offline trappings with online scams to create a false sense of reliability.
FBI reports an epidemic of hacks to steal intimate photos
The Bureau warns of a surge in attacks on social media accounts and cloud storage. Attackers use phishing SMS and emails with threats of account blocking, forcing victims to click links or share confirmation codes. After gaining access to explicit material, blackmail begins. Notably, even after the ransom is paid, the content is often sold on the dark web along with personal data, triggering a new wave of harassment. Student athletes have become a particular target for hackers. This is no longer just data theft, but a full-fledged industry of exploitation and bullying.
Attack on board: hackers at DEF CON tested Delta Air Lines Wi-Fi
The incident on Delta Air Lines flight 591, traveling from Las Vegas to Atlanta, is a vivid example of "physical" cyber impact. Passengers, many of whom were returning from the DEF CON hacker conference, faced their devices being forcibly disconnected from the legitimate onboard Wi-Fi. Simultaneously, attackers deployed a fake network called "Delta WiFi Fast" with a phishing login page to steal Google passwords. The crew cut power to the Wi-Fi for 30 minutes, and upon arrival in Atlanta, police detained suspects. This case highlights the vulnerability of even isolated passenger networks and demonstrates that hackers are ready to use any environment for attacks.
Jewelbug: the double life of Chinese hacker-spies and crypto scammers
Symantec analysts uncovered the activities of the Jewelbug group (Earth Alux, REF7707), which combined sophisticated government espionage with large-scale crypto fraud. On one hand, the hackers attacked government and military structures in the Middle East and Asia, breaching webmail through a compromised hosting platform. On the other, their infrastructure was used to generate fake articles and hundreds of counterfeit domains masquerading as Binance and OKX. Botnets were employed to push scam sites to the top of search engines. The group's database contained millions of logs, hundreds of thousands of stolen cookies, and thousands of credentials. Such diversification is an alarming signal: state-sponsored hackers are increasingly monetizing their skills on a private basis.
DeadLock: ransomware operators move to the Polygon blockchain for invulnerability
The most technologically advanced move in recent times was made by the DeadLock group. Instead of classic servers, they built their infrastructure on smart contracts in Polygon. Victims are left with an HTML file, RECOVERY_CHAT, which is a standalone web application with a chat and a browser for stolen data. The JavaScript code inside the file reads the current IP address of a proxy server from the smart contract. If law enforcement blocks it, operators only need to update the record in the contract, and the chat works again. This creates "literally endless options" for bypassing blocks. Technically, the malware uses hybrid encryption with Curve25519 and XChaCha20, masks its processes, and avoids running in CIS countries. This is not just evolution, but a paradigm shift: decentralization makes fighting ransomware fundamentally harder.
Cyberattack on a Polish CHP plant: first case of a breach via a private cellular network
CERT Polska revealed details of an attack on a combined heat and power plant providing heat to 50,000 people. Attackers penetrated critical infrastructure through the power grid operator's private cellular network—the first recorded case of such a vector. The breach chain included a wind farm without MFA, a Teltonika cellular router, and a WAGO controller with a factory password. Ultimately, the hackers stopped the steam turbine and the water treatment system, then methodically destroyed evidence. This incident is a stark reminder that the security of critical infrastructure depends on the smallest configuration details.
My comment: The shift of ransomware operators to blockchain infrastructure is not just a trend, but a new stage in the arms race. Law enforcement agencies will have to develop fundamentally different countermeasures, as traditional mechanisms for blocking domains and servers lose effectiveness. The security industry urgently needs to adapt to a reality where attackers use the same decentralized technologies as the legitimate crypto market.