The week was packed with incidents in the field of digital security. I have highlighted several key threats that require close attention from anyone connected to cryptocurrencies in any way.
The large-scale phishing operation "Asterix"
Attackers gained access to a database containing approximately 885,000 phone numbers of crypto investors worldwide. The attack scheme is classic, but refined to the point of automation: calls on behalf of technical support or emails disguised as notifications from major platforms like Crypto.com. The victim was lured to a phishing site or forced to install a fake application that visually copies the interfaces of Ledger, Trezor, or Exodus. The goal is to extract the seed phrase.
The automation of the process is particularly concerning. Scripts cross-referenced numbers with databases of the largest exchanges, including Binance and Kraken. The efficiency turned out to be frighteningly high: on a sample from Germany, the match rate was 13.6%, which made it possible to identify more than 43,000 actual holders of crypto assets. More than 5,500 confirmed Binance accounts were queued for attack. Notably, AI tools were actively used to generate phishing content, making the attacks even more personalized and dangerous. The largest data segment — 316,002 numbers — belongs to German citizens, with residents of the USA, UK, Hong Kong, and Bulgaria also on the lists.
Fake AML services as a trap for wallets
Scammers create fake platforms for checking the "purity" of crypto wallets, copying the design of legitimate services like AMLBot. The essence of the trap: the site asks to connect a wallet for scanning, after which it simulates an analysis and gives a reassuring result. However, under the guise of paying a fee or during the connection process, the user signs a transaction that gives the malicious smart contract full access to funds. Scammers use the same template, changing only the logos, which indicates the industrialization of this type of fraud.
Supply chain attack on the Rust ecosystem
A serious incident occurred in the development world. The account of the author of the popular Rust package arrayref (over 245 million downloads), which is used in blockchain tools for Ethereum and Solana, was compromised. Malicious code executed at the moment of project compilation. Within 23 minutes, hackers also "poisoned" the libraries append-only-vec and internment. The trojan, disguised as the dependency proc-macro1, collected system information and stole passwords from browsers. Experts note the similarity of the infrastructure to attacks attributed to the North Korean group Sapphire Sleet. This is a reminder that vulnerabilities in open-source code can have catastrophic consequences for the entire industry.
Compromise of Dahua cameras: 14,500 devices
From June 17 to July 22, hackers breached 14,530 Dahua video surveillance cameras. The operation was named CameraSwarm. The attackers used three vectors: brute-forcing passwords on the open port 37777, exploiting five-year-old vulnerabilities to install a hidden backdoor account "p2pwn", as well as intercepting control of devices behind NAT. The hackers made a blunder by leaving their server unprotected, from which researchers copied 407 MB of data, including logs and tools. The main focus of the attacks was on Russia and Ukraine, and comments in Russian were found in the code. I strongly recommend camera owners check their devices for the hidden p2pwn account, disable P2P, and update the firmware.
The Manic trojan: data theft via mesh network
The new Android trojan Manic targets 169 applications, including banking and cryptocurrency ones. It intercepts keystrokes, notifications, and can provide remote screen access. A unique feature is the backup data transmission channel. If the infected smartphone is offline, the virus looks for other infected devices nearby and transmits encrypted data via Wi-Fi Direct or Bluetooth, creating a mesh network of up to four nodes. This significantly complicates the detection and blocking of leaks.
My comment: This week demonstrates an alarming trend: cybercriminals are increasingly using automation and AI to improve the effectiveness of attacks, and are also mastering complex technical methods such as supply chain attacks and mesh networks to bypass traditional security measures. Crypto investors and developers need to reconsider their security protocols, betting on hardware wallets, multi-factor authentication, and thorough verification of the software used.