This week, we highlight significant developments in the realm of cybersecurity.
- In Ukraine, authorities dismantled a network of fake crypto exchanges, Money 24/7, seizing over 20 million hryvnias.
- The FBI reported a surge in hacking incidents aimed at stealing intimate photos and perpetrating cyberbullying.
- Hackers from DEF CON executed a cyberattack on passengers aboard a Delta Air Lines flight.
- Chinese hackers combined government espionage with cryptocurrency fraud.
Ukrainian Authorities Shut Down Fake Crypto Exchange Money 24/7: Over 20 Million Hryvnias Seized
Ukrainian law enforcement arrested the mastermind behind the fraudulent Money 24/7 network, which operated under the guise of a legitimate fiat and crypto exchange service. This information was shared by the country’s cyber police.
The scheme operated as follows:
- Illusion of Reliability. To deceive potential victims, the perpetrators created high-quality websites, actively managed a Telegram channel, registered a trademark, and established a well-equipped office that resembled a cash exchange.
- “Physical” Scam. Clients submitted online requests to buy cryptocurrency, were invited to the office, and asked to hand over cash. While the money was collected, no cryptocurrency was ever transferred to their wallets.
- Psychological Manipulation. To delay victims from reporting to the police, the scammers used tactics to stall. Some clients received small portions of the promised cryptocurrency along with “written guarantees” that the transactions would soon be completed.
In one confirmed case alone, the losses amounted to nearly 1.6 million hryvnias. The exact number of victims is still being determined.
Following over 20 raids across seven regions of Ukraine, authorities confiscated computers, phones, documents, and more than 20 million hryvnias in cash.
The organizer of this scheme faces up to 12 years in prison with asset confiscation.
FBI Alerts on Surge of Hacking Incidents Targeting Intimate Photos and Cyberbullying
The FBI has issued a warning about a rise in cyberattacks aimed at stealing intimate photos and videos from social media and cloud accounts.
In a joint statement with the National Collegiate Athletic Association, the bureau also noted that student-athletes have become specific targets for hackers.
The attacks typically begin with a fraudulent SMS or email. Victims are threatened with account suspension and are urged to follow a link for “password reset” or to send a verification code.
Once hackers gain access to an account containing explicit materials, they demand ransom, threatening to distribute the photos to the victim's family and friends or to make them public.
Even if the victim pays, the criminals often sell the stolen content on the dark web along with personal data like names, birth dates, emails, and phone numbers, leading to further harassment and extortion by other criminals.
DEF CON Hackers Launch Cyberattack on Delta Air Lines Passengers
Delta Air Lines is collaborating with law enforcement to investigate a cyber incident on Flight 591, which was traveling from Las Vegas to Atlanta on August 10. The flight included numerous attendees from the recently concluded DEF CON 34 conference, according to reports from BleepingComputer.
The attack unfolded as follows:
- Forced Disconnection. The attackers began sending fake data packets, disconnecting other passengers' devices from the legitimate onboard Wi-Fi.
- Fake Network. Simultaneously, hackers set up their own network called Delta WiFi Fast.
- Phishing and Data Theft. Witnesses reported that connecting to the fake network led users to a fraudulent login page aimed at collecting personal information and Google account passwords.
DELTA FLIGHT 591 CARRYING PASSENGERS FROM DEF CON 34 IN LAS VEGAS HIT BY SUSPECTED WI-FI ATTACK MID AIR.
Delta Flight 591 from Las Vegas to Atlanta reportedly encountered a suspected Wi-Fi attack involving passengers returning from DEF CON 34, which concluded in Las Vegas on… pic.twitter.com/6cPqvbUFfz
— Turbine Traveller (@Turbinetraveler) August 11, 2026
Aviation technician Turbine Traveller from Nairobi shared on X that messages transmitted by the crew of Flight 591 via the aircraft's communication system (ACARS) indicated the launch of a fake network onboard.
As a precaution, the crew fully powered down and disabled the onboard Wi-Fi for nearly 30 minutes. Delta Air Lines confirmed the incident, emphasizing that there was no threat to flight safety or navigation systems, as onboard electronics are isolated from passenger networks. No alerts were issued to air traffic control.
Upon arrival at the terminal in Atlanta, police boarded the aircraft. Suspects were questioned on-site, and their Wi-Fi hacking equipment was seized.
Chinese Hackers Combine Government Espionage with Crypto Fraud
The group known as Jewelbug (also referred to as Earth Alux or REF7707) has been involved in sophisticated cyber espionage and cryptocurrency theft. This dual activity was reported by Symantec.
Analysts strongly associate the financially motivated part of the attacks with a legitimate Chinese company offering SEO services, suggesting that the group operates as "hired hackers."
According to experts, in a recent campaign, the attackers targeted government and military entities in the Middle East, Southeast Asia, and South Asia. They compromised a shared web hosting platform of a state telecom provider, gaining access to email templates used by 15 different governmental ministries and agencies.
The injected JavaScript code established a WebSocket connection with the hackers' server each time officials accessed their email, stealing session cookies.
If the algorithm identified a target as particularly valuable, the user would see a fake Adobe Flash update window. Once the victim agreed, backdoor malware called Antino and a malicious browser extension named PDF Viewer were installed, allowing traffic interception and remote system control.
Upon accessing Jewelbug's control infrastructure, analysts discovered that the hackers were simultaneously running a fraudulent business:
- Their neural networks generated fake articles published on hundreds of fraudulent domains masquerading as crypto exchanges like Binance and OKX;
- Botnets were used to promote these fraudulent sites in search engine rankings;
- Besides cryptocurrencies, the traffic was linked to scam resources, sports betting, pirated streaming, and fake private detectives.
In the group's database, specialists found over a million logs of malicious activity, 580,000 stolen cookies, thousands of credentials, and over 2,300 emails.
To infect Linux servers and ASUS routers, the group employed a custom Rust-based Trojan named ClientKing. To bypass security systems, they concealed malicious payloads within public Google Docs, blending their traffic with legitimate data.
DeadLock Ransomware Group Utilizes Polygon for Infrastructure Protection
The DeadLock ransomware group, responsible for nearly a hundred victims in the US, Europe, and Turkey, has fundamentally altered its approach to building infrastructure. To evade law enforcement shutdowns, the hackers have fully transitioned to decentralized solutions, as reported by Microsoft Threat Intelligence.
Analysts noted that DeadLock, now actively used by partners of other CaaS groups such as Lynx and INC, has abandoned traditional servers in favor of a blockchain ecosystem.
A unique aspect of their attacks is the ransom note format. Instead of the usual text file, the virus leaves a file named RECOVERY_CHAT.<UID>.html on drives. This is essentially a fully autonomous web application that operates directly in the browser without a traditional server. The HTML file contains an end-to-end encrypted chat for communication with hackers, a guide to stolen data, and a log of leaks.
Microsoft emphasizes that this architecture elevates infrastructure resilience, allowing operators to easily recover from any attempts by law enforcement to disrupt their operations.
Experts from Group-IB have detailed how this decentralization works.
The JavaScript code within the HTML file directly interacts with smart contracts on the Polygon blockchain to rotate addresses. The application reads the current proxy server IP address from the smart contract for communication with operators. If law enforcement blocks it, the hackers do not need to re-register domains or change files with the victim — they just update the entry in the smart contract, and the chat is operational again.
Posts about hacks and leaked data are also linked to smart contracts and distributed via the decentralized Wasabi protocol.
Experts noted that this method enables criminals to create "literally endless variations" for circumventing blocks.
Mechanics of the DeadLock Ransomware. Source: Microsoft.Technical features of the malware include:
- Encryption. It employs a hybrid combination of elliptic curve cryptography using Curve25519 and stream cipher XChaCha20. Files are assigned the extension .dlock;
- Process Masking. To prevent users from noticing system slowdowns during encryption, the process pauses if CPU usage exceeds 70% or RAM consumption rises above 29%;
- Wiping. DeadLock is strictly blocked from launching in CIS countries and certain Middle Eastern states. After completion, the software deletes system logs, shadow file copies (VSS), and self-destructs.
Polish Power Plant Turbine Shut Down Due to Cyberattack
The Polish national cybersecurity response team CERT Polska revealed details of a cyberattack that disrupted operations at a local combined heat and power plant, which provides heat to about 50,000 residents. Although the incident occurred in December 2025, the investigation results have only been published recently.
This case is unique due to the method of penetration: attackers accessed critical infrastructure through a private cellular network of the local power grid operator. Experts note that this is the first documented instance of such a vector being used in a real attack on industrial facilities.
The campaign was executed solely using the legitimate functions of the equipment and authorized protocols.
The main steps of the breach were:
- The initial point was a wind farm, where a critical system element lacked multi-factor authentication. Hackers gained administrator rights.
- From the firewall, they accessed the Teltonika RUTX50 cellular router through a secondary Ethernet port and authenticated via SSH (the password was not standard, and the method of its breach is unknown).
- The major configuration error lay in the private network of the distribution company. The settings allowed direct traffic between clients. Hackers scanned the airwaves and identified the WAGO PFC200 controller at the target power plant.
- The WAGO was secured only with a factory default password. Through it, hackers created a tunnel directly into the internal network of the power plant.
On December 29, the attackers switched the Siemens S7 industrial logic controllers to stop mode and changed the passwords. This resulted in the actual physical shutdown of the steam turbine and water treatment system.
To complicate the investigation, the hackers methodically destroyed evidence: they deleted the partition table on the WAGO controller (making it unbootable), reset the servers, the Teltonika router, and the FortiGate firewall to factory settings, assigning them inaccessible IP addresses.
Prompt intervention by personnel allowed for the restoration of system operations.
Also on ForkLog:
- The US will intensify its fight against cybercrime with the help of the business sector.
- Trezor reported a data breach affecting nearly 14,000 customers.
- The WSJ uncovered a network of North Korean operatives in US companies.
- Government structures in Taiwan faced a cyberattack utilizing AI.
- Creators of Boltz handed the project to a group of "Bitcoin veterans" after attacks by AI hackers.
- A hacker drained $200,000 from the XRP cross-chain bridge.
- North Korea used scam networks for laundering stolen crypto assets.
- BTCPay announced a reward of up to 3 BTC for the return of stolen coins.
- North Korean hackers connected local AI to attacks on crypto companies.
- Experts revealed details of the $8 million Coinsbuy hack.
- The founder of BitMart denied allegations of misappropriating user funds.
- Hackers drained Lightning nodes through a vulnerability in BTCPay.
Weekend Reading Suggestions
In a new article from ForkLog, we discuss how attacks on management systems are becoming the norm, and how the human factor combined with AI analysis presents a gift for hackers.
