This week’s cybersecurity highlights include the dismantling of a drop network, a new Trojan targeting Ukrainian officials, Google account theft via compromised domains, and fake AI services stealing credentials.
- A drop network was uncovered in Vinnytsia Oblast.
- The UAC-0099 group launched attacks on Ukrainian officials using a new Trojan.
- Hackers acquired Google certificates through the hijacking of national domain zones.
- Fake AI services targeted advertisers, stealing accounts and 2FA codes.
Drop Network Uncovered in Vinnytsia Oblast
On October 5, the Cyber Police reported suspicions against five individuals aged 22 to 25 in Vinnytsia Oblast for managing financial flows for fraudsters, including the use of cryptocurrency.
The suspects created a network of about 300 people. For a small fee, participants (drops or money mules) gave organizers access to their payment details and crypto wallets.
Between 2024 and 2025, the group took a cut from cashing out and laundering funds obtained through scams. The money came from prepaid sales without delivery, fake government aid payments, calls from supposed bank collectors, and phishing sites. Eventually, those involved in the scheme began committing fraud themselves. The estimated damage from their activities reached nearly 2 million hryvnias.
A significant portion of the intermediaries' accounts were blocked by bank security services and the Cyber Police's Antifraud project. To circumvent restrictions, the criminals found accomplices among bank employees to help "resolve issues."
Criminal accounting. Source: Cyber Police of Ukraine.During 40 searches, law enforcement seized 255 payment cards, dozens of smartphones and SIM cards, approximately 2 million hryvnias, $147,000, €22,000, and luxury vehicles. The turnover from the "plastic" exceeded 127 million hryvnias.
The suspects face up to eight years in prison. Four accomplices, currently abroad, were charged in absentia and placed on an international wanted list.
UAC-0099 Group Attacks Ukrainian Officials with New Trojan
On October 7, TrendAI experts released a report on the pro-Russian group Earth Sirrush (UAC-0099), which has been conducting campaigns against Ukrainian government bodies, defense structures, border guards, and logistics companies since 2022.
The researchers detailed a previously unknown info stealer and remote access Trojan called ASHVEIN, which the developers referred to as TelemetryBrowser.
This software can:
- steal credentials from Chrome and Firefox;
- take screenshots and gather files;
- execute commands via PowerShell;
- detect analysis tools like Wireshark and IDA.
ASHVEIN receives commands from operators through hidden HTML elements, with GitHub serving as a backup channel in some versions. One delivery method is the AnswerFromPolice dropper, which opens a fake document from the National Police of Ukraine and installs the Trojan in the background.
According to specialists, over four years, Earth Sirrush has created more than ten families of malware. In 2026, hackers began hiding payloads in PNG images and, in one campaign, posed as suppliers of drone components.
Graphic interface of MATCHBOIL, used for manual execution by the victim. Source: ESET.Other researchers have also studied the group’s arsenal. On October 8, ESET published an analysis of MATCHBOIL, a loader through which UAC-0099 delivers the MATCHWOK backdoor to infected computers. The tool has been evolving since April 2024, with recent builds featuring advanced obfuscation, sandbox launch checks, and disguises as harmless utilities like planners.
Using this tool, the group attacked transportation companies in Ukraine in the summer of 2025, followed by a manufacturing enterprise, and in June 2026, targeted an organization in the energy sector. ESET believes UAC-0099 may provide initial access for Sandworm, which is linked to destructive cyber operations in the same region.
Hackers Obtained Google Certificates via Domain Hijacking
On October 6, Google reported the hijacking of domains in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) top-level domains. The company became aware of the incidents a week earlier.
Criminals compromised third-party operators of these ccTLDs and altered authoritative DNS records. This allowed them to obtain valid HTTPS certificates for several Google resources and other organizations. Google emphasized that its internal systems were unaffected, and there were no complaints against the certificate authorities.
Chrome began rejecting the unauthorized certificates through the CRLSets mechanism, while Google worked to revoke them. Certificate Transparency logs indicated other affected parties, including several leading global brands. The browser also implemented bans for them. The specifics of the attacked entities and the number of issued certificates remain undisclosed.
The company does not guarantee that all hijacked domains have been identified, and blocking in Chrome does not protect against other browsers. Google advised website owners to monitor Certificate Transparency logs and publish restrictive CAA records.
Fake AI Services Target Advertisers, Stealing Accounts and 2FA Codes
A phishing platform disguised itself as advertising products from ChatGPT, Gemini, Claude, Perplexity, and Manus. Its victims included agency employees, media buyers, and administrators managing Google Ads accounts, according to Island.
On September 8, Meta introduced the AI agent Muse, and just eight days later, a fake Muse Ads appeared on the domain museads.ai, presenting itself as an "AI manager" for paid campaigns.
Fake Muse page. Source: Island.Each landing page promised promotional assistance and prompted users to click a "Connect" button, which opened a fake Google authorization window directly on the page, complete with the accounts.google.com address and a lock icon. This technique is known as Browser-in-the-Browser (BitB), and the interface adapts to Windows, macOS, iOS, and Android.
Next, a live operator managed the process, performing tasks such as:
- rejecting the password and asking for it again, up to three times;
- requesting a code from SMS or an authenticator app;
- showing a Google confirmation request or an Okta push notification;
- keeping the victim on a waiting screen or ending the scenario.
The platform supported logins through Google, Meta, TikTok, and Okta. The same engine also facilitated fake payment refund forms and job postings in the names of Tesla, Nike, and Louis Vuitton. Researchers established a connection between them due to mistakes made by the criminals, as old source code was left in public GitHub repositories.
According to the report, victims shared hundreds of credential sets with the attackers, and the campaign was ongoing at the time of publication.
Experts recommended verifying "beta programs" of AI companies on their official websites and transitioning to passkeys.
Botnet Seeks Command Server in Poem on GitHub for Hidden Monero Mining
On October 7, Black Lotus Labs cyber threat researchers reported on the malware PoeLLM, which infects AI platforms and mines cryptocurrency on them.
The primary targets are vulnerable installations of LiteLLM and Ollama, as well as the PDF converter Gotenberg and the development system Gitea. These servers are often poorly configured and equipped with powerful GPUs.
The PoeLLM command server coordinates are calculated in an unusual way. It downloads the poem "On the Nature of Connection" from the dash.css file in a fork of the Node.js repository and extracts four key words from the text. According to an embedded dictionary, these words are converted into an IPv4 address. To transfer control to a new machine, the operator modifies the stanzas.
Source: Black Lotus Labs.The malware includes a remote shell, XMRig (Monero) miners, Iron (Iron Fish), and a vulnerability scanner. Infected devices connect to the Russian pool Kryptex, with some turning into new analyzers on ports 3000 and 4000. The CVE-2026-42271 vulnerability is exploited for attacks on LiteLLM.
PoeLLM campaign scheme. Source: Black Lotus Labs.According to researchers, PoeLLM has affected over 3,400 servers, primarily in the US and Western Europe. On peak days, up to 800 nodes were active. Some of the infrastructure was likely hosted on compromised routers.
Black Lotus Labs connects the campaign to an Italian-speaking cybercriminal. Specialists advised securing services from external access and reviewing logs for signs of compromise.
Additionally, on ForkLog:
- Glassnode assessed the share of bitcoins with disclosed public keys.
- 79thVault lost $12.5 million following an attack via a privileged function.
- Starknet considered a transition to L1 due to quantum threats.
- Justin Drake suggested the potential for ECDSA breaches using AI before quantum computers arrive.
- ZachXBT uncovered a money laundering scheme linked to Lazarus.
- The US imposed sanctions against a funding network for Hamas through funds and cryptocurrency.
- Apple will tighten app access to Mac data due to AI agent risks.
What to Read This Weekend?
Leaders in the AI industry have called for a slowdown in the race for models, but in Anthropic's IPO application, existential risks are addressed on 80 out of 261 pages, while the company's long-term infrastructure commitments have reached $518 billion. In a new longread, ForkLog discusses where safety concerns end and market competition begins.
Follow ForkLog on social media
Telegram (main channel) Facebook X