This week, we highlight significant events in the realm of cybersecurity.

  • A drug cartel laundered billions through crypto brokers in Brazil.
  • A cyberattack disrupted the operations of over 30 water systems in Minnesota.
  • The police uncovered the activities of a "crypto academy" in Ukraine.
  • The malware SparkKitty was able to recognize seed phrases from smartphone galleries.

Drug Cartel Laundered Billions Through Crypto Brokers in Brazil

Brazilian law enforcement dismantled an international drug syndicate believed to have smuggled at least 6.5 tons of cocaine and laundered money using cryptocurrencies.

During operations across the states of São Paulo, Minas Gerais, Santa Catarina, and Espírito Santo, police conducted 44 searches, made nine arrests, and issued 13 temporary detentions.

Source: Federal Police of Brazil.

According to the investigation, the criminals set up a complex network of shell companies to obscure drug proceeds, purchasing luxury real estate and high-end goods. Illegal financial brokers played a crucial role in helping convert fiat currency into cryptocurrency and transferring it abroad.

As part of the investigation, authorities froze assets totaling up to 1 billion reais (approximately $197 million at the current exchange rate).

The use of cryptocurrency by drug syndicates is becoming increasingly common. This operation in Brazil followed a May report from the U.S. Treasury, which imposed sanctions on six Ethereum addresses used by the Sinaloa cartel's financial network to convert drug profits into digital assets.

Cyberattack Disrupted Operations of Over 30 Water Systems in Minnesota

On July 26-27, unknown hackers targeted the operational technologies of more than 30 public water supply systems in Minnesota. The state's IT services agency (MNIT) urgently activated cybersecurity protocols statewide.

In the city of Braham, a water treatment plant suddenly halted operations. After three hours, the system was restored, with local authorities confirming that the failure resulted from a deliberate attack on the management computer systems. Similar equipment failures occurred in other counties, forcing staff to implement emergency plans and switch pumps and filters to manual control.

MNIT emphasized that the incident did not compromise water quality. The agency is addressing the aftermath of the attack in collaboration with the FBI and the U.S. Cybersecurity Agency.

Previously, U.S. authorities warned about mass attacks by Iranian hackers who were specifically seeking access to Rockwell Automation and Allen-Bradley programmable logic controllers to disrupt water and energy facilities.

Police Expose Activities of "Crypto Academy" in Ukraine

Authorities uncovered a fraudulent scheme where participants posed as representatives of the "Ukrainian Financial Academy." Under the guise of providing investment education in cryptocurrencies, they defrauded approximately $1.11 million from around a thousand individuals, reported the country's cyber police.

Four key figures, including two organizers, were arrested following a series of searches in Kharkiv and Dnipropetrovsk regions.

Source: Cyber Police of Ukraine.

Here's how the scheme operated:

  • The suspects heavily advertised on Facebook and Instagram, promising assistance from experienced traders and guaranteed quick profits from crypto investments;
  • Managers built trust with victims, assessed their financial situations, and persuaded them to transfer funds to controlled crypto wallets. On a specially created fake platform, they displayed graphs of "successful trading balances";
  • In some instances, victims were allowed to withdraw small amounts. When they attempted to access their principal funds, withdrawals were blocked, and the criminals demanded additional payments under the guise of "fees" or "reserve fund replenishments."

Investigators found that the fraudsters specifically targeted vulnerable individuals, such as retirees, disabled persons, and those suffering from severe illnesses. One victim undergoing cancer treatment transferred about 500,000 hryvnias, which she had saved for her treatment, to the criminals. When victims lost their funds, they were pressured into taking out loans.

Additionally, unsuspecting users were recorded providing positive video testimonials during moments of "successful trades," which were later used in advertising.

The arrested individuals face up to 12 years in prison with asset confiscation.

Malware SparkKitty Targeted Seed Phrases in Smartphone Galleries

A new cryptocurrency-stealing virus infiltrated user devices via the Apple App Store, Google Play, and third-party directories. The SparkKitty stealer was reported by Check Point.

This malware is an evolution of the SparkCat stealer, primarily focused on hunting for users' galleries. Instead of the standard keyboard logging or clipboard monitoring, the software requests access to victims' photos and videos. Once granted, the virus activates an optical character recognition (OCR) engine and continuously scans images for cryptocurrency wallet seed phrases, passwords, and QR codes.

The spread of SparkKitty:

  • iOS. The virus was hidden within the app 币coin in the App Store. Hackers bypassed Apple’s moderation by masking the malicious functions within system frameworks;
  • Android. SparkKitty was found in the SOEX messaging app with cryptocurrency exchange features. Before its removal from Google Play, it had been downloaded over 10,000 times;
  • Third-party channels. Modified Android builds were distributed through other stores, altered TikTok clients, gambling software, and manual APK installations. On rooted smartphones, the virus embedded itself into the system via Xposed modules.

According to Check Point, all recognized text from the photographs, along with basic device information, was sent to the attackers' command server.

Experts advised against storing seed phrases and passwords as screenshots or photos in phone galleries. They recommended keeping wallet backups exclusively offline—on paper or hardware devices. Additionally, users should regularly check and restrict mobile apps' access to their galleries.

Hacker Used DeepSeek for Autonomous Attacks via Telegram

A Chinese-speaking hacker employed the AI model DeepSeek to conduct fully autonomous cyberattacks. He controlled the neural network via Telegram using the Hermes Agent framework, as reported by the Unit 42 team.

The hacker, known by the aliases knaithe and KnYuan, configured the AI agent so that the operator only needed to input commands in Telegram:

  • Upon receiving a task, DeepSeek scanned the internet for vulnerable systems, using the FOFA search engine;
  • The AI independently analyzed software versions, sought out new public exploits on GitHub, downloaded them, and attempted to apply them.

Experts noted that the neural network exhibited decision-making logic: when an attack on the Langflow platform failed due to the victim's unsuitable configuration, the AI halted the campaign. After analyzing other popular systems, the agent targeted the n8n automation platform and attempted to hack it by combining two vulnerabilities: CVE-2026-21858 and CVE-2025-68613.

Attack scenario from the Hermes Agent session. Source: Unit 42.

DeepSeek's autonomous actions were unsuccessful, as the identified servers did not meet the exploit requirements. However, in manual mode, the hacker successfully extracted data from three organizations through a vulnerability in NetScaler (CVE-2026-3055) and compromised 11 Marimo objects (CVE-2026-39987). In total, over 460 targets were attacked.

Researchers were able to study the scheme in detail due to a simple error made by the operator. The Hermes Agent inadvertently launched an open HTTP server on port 8888 in the /home/worker directory, making the hacker's infrastructure public: API keys, target lists, scripts, model configurations, and complete logs of "communication" with the autonomous agent were exposed.

According to Unit 42, the hacker is likely based in Zhuhai, China. No direct links to government entities were found by experts.

Also on ForkLog:

  • Anthropic acknowledged three breaches of real systems during Claude's tests.
  • Coldcard wallet owners lost bitcoins worth $38 million.
  • A fake XRP staking scheme worth $8.5 million was dismantled in South Korea.
  • In the U.S., there are objections to Flock surveillance cameras.
  • The OpenAI AI agent accessed four external accounts.
  • The U.S. estimated the damage from crypto fraud at $80.7 billion.
  • Claude helped identify weaknesses in cryptographic algorithms.
  • Blockaid reported a record first half of the year for crypto hacks.
  • Myanmar enacted a law against scam centers.
  • Google results revealed chats involving Claude with cryptocurrency wallet keys.
  • Researchers caught AI models circumventing cybersecurity testing rules.
  • Triple-A's losses from hacks rose to $11.8 million.
  • Reports indicate that North Korea arrested IT specialists for laundering state funds through cryptocurrency.

What to Read This Weekend?

In the new weekly column "Quantum & After," we explain the differences between post-quantum cryptography and quantum physics, who is seriously preparing for new threats, and who is simply attaching a trendy label for hype.