Crypto news

15.08.2026
11:31

DeadLock moves to Polygon, Ukrainian cyber police dismantled a network of fake exchangers: weekly digest

security_new4

The week was packed with events in the cybersecurity sphere. From physical scams at "exchange" offices to sophisticated attacks on critical infrastructure and the use of blockchain to protect malware — we break down the most high-profile incidents.

Ukrainian cyber police busted a network of fake Money 24/7 exchangers

Law enforcement detained the organizer of a fraudulent scheme that operated under the guise of a legitimate currency and crypto-asset exchange service. The criminals created an illusion of reliability: quality websites, an active Telegram channel, a registered trademark, and even an office with a cash register. Clients were invited in person, cash was collected, but cryptocurrency was never transferred. To buy time, the fraudsters partially returned funds and issued "written guarantees." Damages from just one episode exceeded 1.6 million hryvnias. During 20 searches across seven regions, more than 20 million hryvnias in cash and equipment were seized. The organizer faces up to 12 years in prison.

FBI warns of a wave of attacks on intimate photos

The Bureau is recording a surge in account hacks aimed at stealing explicit materials and subsequent blackmail. The attacks begin with phishing messages about "account blocking." Hackers demand ransom, threatening to publish photos, and after payment, sell the content on the darknet along with personal data. Student athletes have become a separate target.

Hacker attack aboard a Delta Air Lines flight

On flight 591, traveling from Las Vegas after DEF CON 34, attackers targeted passengers. They forcibly disconnected devices from the legitimate Wi-Fi and deployed a fake Delta WiFi Fast network with a phishing authorization page to steal Google account credentials. The crew cut power to the Wi-Fi for 30 minutes. Police questioned suspects right at the jet bridge and seized hacking equipment. Navigation systems were not affected.

Chinese Jewelbug hackers: espionage and crypto scam in one package

Symantec analysts uncovered the dual activities of a group attacking government structures in the Middle East and Asia. The hackers compromised a state operator's web hosting platform, injected JavaScript code to steal session cookies, and installed backdoors via fake Adobe Flash updates. In parallel, the group used neural networks to generate fake articles on hundreds of domains masquerading as Binance and OKX, and employed botnets to push them to the top of search engines. The database contained more than 580,000 stolen cookies and thousands of credentials.

DeadLock ransomware shifted to decentralization via Polygon

The group attacking companies in the US, Europe, and Turkey radically changed its infrastructure. Instead of traditional servers, they use the Polygon blockchain. The ransom note is now a standalone HTML application with a chat and a browser for stolen data. JavaScript code reads current IP addresses from smart contracts, allowing hackers to instantly bypass blocks. Posts about breaches are also tied to smart contracts and distributed via the Wasabi protocol. Technically, the malware uses a hybrid of Curve25519 and XChaCha20, masks processes, and self-destructs after operation.

Cyberattack on a Polish thermal power plant via a cellular network

CERT Polska revealed details of an incident that halted a steam turbine. Attackers penetrated the system through the power grid operator's private cellular network. They exploited vulnerabilities: lack of MFA at a wind power plant, SSH access to a Teltonika router, and a factory password on a WAGO controller. This is the first recorded case of using such a vector to attack an industrial facility. The hackers destroyed evidence by resetting equipment settings.

My comment: The use of blockchain to manage ransomware infrastructure is an alarming signal. Decentralization makes combating such groups fundamentally harder. Law enforcement will need to master new methods, including smart contract monitoring, to effectively counter these threats.