The past week has seen significant developments in the realm of cybersecurity, highlighting various incidents and threats.
- Hackers potentially accessed data from approximately 6,000 South Korean diplomats.
- The Dolphin X Trojan utilized AI for victim scoring and identifying valuable cryptocurrency wallets.
- Ostium DEX suffered a loss of $23.75 million due to an attack on its off-chain infrastructure.
- Train manufacturer Stadler refused to pay $12.2 million to extortionists.
Hackers Potentially Accessed Data from Approximately 6,000 South Korean Diplomats
The South Korean Ministry of Foreign Affairs has confirmed a large-scale cyberattack on its diplomatic academy, resulting in a significant data breach. This was reported by Reuters.
Attackers exploited an unknown zero-day vulnerability and weaknesses in the configuration of the online education system of the Korean National Diplomatic Academy. Authorities suspect North Korean hackers may be involved.
The attackers gained control over the server from April to May 2025 and remained undetected until February 2026, when suspicious activity was reported by one of the agencies.
Media sources indicate that the compromised system contained educational materials and administrative data, including names and user IDs of course participants. As a result, personal data of around 6,000 current and former diplomats, including those stationed abroad and attached officials, may have been compromised.
Dolphin X Trojan Utilized AI for Victim Scoring and Valuable Wallet Identification
The new malware, Dolphin X, employed AI for sorting and ranking infected devices through its AI Profiler feature. Analyst Daniel Kelly from Varonis reported this.
This software addresses a key challenge for hackers conducting such campaigns by filtering through large volumes of stolen data, which would ordinarily be time-consuming to process. The Trojan with stealer functionality was discovered on a shadow forum, promoted by a seller under the alias Kontraktnik.
Dolphin X analyzes compromised machines, assigning a value rating to each.
The AI Profiler module tracks user activity, active software, browsed domains, and specific files, generating a summary with a ranked list of victims. The malware prioritizes devices for attack, targeting those with access to corporate networks, cloud environments, developer infrastructure, or large cryptocurrency wallets.
Source: Varonis.According to experts, the Dolphin X control panel consists of 329 functions across 10 categories and supports data theft from over 300 applications:
- Nine popular browsers based on Chromium and Gecko engines;
- 100 browser extensions and 65 desktop cryptocurrency wallets;
- 10 password managers and over 30 command-line tools for cloud services;
- Configuration files with the .env extension, SSH keys, and developer credentials.
Experts note that, unlike most known cases where AI is used for generating phishing emails or malicious code, Dolphin X employs neural networks for a different purpose—analyzing stolen information and automatically assessing the value of infected devices.
Hackers Stole $23.75 Million from DEX Ostium via Off-chain Infrastructure Attack
The decentralized trading platform Ostium experienced a loss of $23.75 million due to an attack on its off-chain price oracle infrastructure. Trading on the platform has been suspended since July 16 and has yet to resume.
Ostium operates on the Arbitrum network, enabling direct trading of traditional and cryptocurrency assets from wallets with settlements in USDC.
According to DEX management, the attacker breached the off-chain infrastructure that relays price data to the protocol. After tampering with the reports, the attacker quickly opened and closed large positions, generating artificial profits at the expense of liquidity providers’ funds.
Specifically, the attacker broadcast an artificially low Bitcoin price of $5,000.
The platform informed the community of the incident on July 16, announcing the trading halt and the referral of the matter to law enforcement.
— PeckShieldAlert (@PeckShieldAlert) July 16, 2026
PeckShieldAlert reports that the stolen USDC was converted into 12,080 ETH, with 10,540 ETH sent to the Tornado Cash mixer.
Funds from traders held in a separate smart contract were unaffected. Open long and short positions were neither closed nor liquidated; they remain frozen until trading resumes. Ostium has promised to notify users at least 24 hours before relaunching, with positions updated based on prices at the time of trading resumption.
Train Manufacturer Stadler Refused to Pay $12.2 Million to Hackers
Swiss engineering giant Stadler Rail, a leading global manufacturer of trains, locomotives, and railway automation systems, faced extortion from the Everest group. This was disclosed by the company in July reports.
Criminals demanded 10 million Swiss francs (approximately $12.2 million at the time of writing), threatening to publish stolen documents. Management firmly refused to pay and contacted the police in the canton of Thurgau.
According to Stadler, hackers breached a third-party data exchange platform that the company used in collaboration with one of its suppliers. Internal IT systems, manufacturing capabilities, and global train control systems were not compromised.
Only general technical documentation, which is not critical for security, was accessible to the attackers. Personal data of citizens and employees were not affected.
This is not the first attack on the manufacturing giant; in 2020, Stadler also faced a hack, but the company managed to quickly isolate the threat.
The Everest group has been active since 2020. Like many modern syndicates, it has shifted from file encryption to pure data theft followed by extortion. Additionally, hackers often act as brokers for initial access or buy leaked databases from other hackers for subsequent extortion.
Law Enforcement Shut Down Kratos Phishing Service
Authorities in Germany and the United States, with support from Indonesian officials, conducted a special operation to dismantle the infrastructure of Kratos, one of the world's largest phishing-as-a-service (PhaaS) platforms. This was reported by the Federal Criminal Police Office of Germany.
According to investigators, the service operated on a subscription model, with about 1,800 customers launching up to 15,000 phishing campaigns monthly. Since late 2024, hundreds of thousands of users from over 30 countries, primarily in the U.S. and Europe, have fallen victim to these attacks.
As a result of the operation, law enforcement agencies disabled around 200 servers globally. In Indonesia, the alleged organizer and developer of the service was arrested.
Cybersecurity researchers from ANY.RUN conducted reverse engineering of the attacks and identified key features:
- Bypassing 2FA through session theft. Kratos operated in reverse proxy mode based on Node.js. It real-time relayed victims' requests to the official Microsoft 365 site, intercepting not only login credentials but also session cookie files. This allowed hackers to access accounts bypassing two-factor authentication;
- Accessibility for amateurs. The platform was distributed through a closed website and a Telegram shop. Any low-skilled cybercriminal could purchase a subscription with cryptocurrency and deploy the ready-made infrastructure;
- Attacks via QR codes. In one recorded Microsoft attack, hackers sent employees emails with "W-2 tax forms" and personal QR codes redirecting to a fake login page;
- Attack chains. Stolen credentials were used to infiltrate organizations' internal networks (healthcare, retail, and industrial sectors), read correspondence, and conduct business email compromise attacks.
Experts state that although the main servers have been shut down, the source code remains with hundreds of buyers. Attacks utilizing Kratos may resume on disposable domains or hacked sites under a new name.
Adobe Acrobat Extension Vulnerability Allowed Silent Reading of WhatsApp Messages
Researchers from Guardio Labs uncovered details of a dangerous vulnerability chain in the official Adobe Acrobat browser extension for Google Chrome, which has over 314 million users.
The issue, dubbed HermeticReader, allowed attackers to stealthily steal user data from the web version of WhatsApp.
Experts indicate that no malicious software installation or session cookie theft was necessary for the attack. The sole requirement was to lure users with the installed Adobe Acrobat extension to a phishing site.
Here’s how the attack chain operated:
- The attacker loaded a malicious page that invoked an embedded iframe from the Adobe Acrobat extension resources. This element sent a command to activate the hidden Hermes engine responsible for WhatsApp integration.
- The malicious page opened WhatsApp Web in a background tab, obtained the identifier, and sent control commands through the extension.
- Hackers exploited HTML specification features (the element without a specified value attribute sends all nested text content) and the lack of a form-action directive in WhatsApp Web's content security policy. This caused the messenger to send the entire text of the page to the hacker's server.
As a result, hackers could swiftly acquire a complete archive of the WhatsApp interface: chat lists, contact names, open conversation history, and user profile data.
According to Guardio Labs experts, this vulnerability clearly illustrates the dangers of superficial integration of third-party extensions. Minor flaws in software architecture, when combined correctly, can completely undermine the basic isolation of the browser. Researchers strongly recommend updating the Adobe Acrobat extension to the latest version.
Also on ForkLog:
- India demanded GitHub remove Bitchat repositories.
- The UN estimated the damage from scam networks at $114 billion.
- AFX Trade suspended operations of a bridge after a $24.15 million USDC withdrawal.
- SecondFi will cease operations following a $16.1 million ADA theft.
- OpenAI models hacked Hugging Face during testing.
- Pakistan established a unit for investigating cryptocurrency crimes.
Weekend Reading Recommendations
ForkLog explored how the traditional model supporting the cybersecurity industry is breaking down and how this process may affect other segments of the economy.
