In the latest updates from the cybersecurity sector, several significant incidents have been reported over the past week.

  • A phishing campaign aimed at almost one million crypto investors has been uncovered.
  • Fake AML checkers designed to steal cryptocurrencies have been detected online.
  • Hackers compromised a popular Rust developer library.
  • Approximately 14,500 Dahua cameras in Ukraine and Russia were hacked.

Phishing Campaign Targets Nearly One Million Crypto Investors

Cybercriminals have stolen a database containing the phone numbers of around 885,000 crypto investors from various countries. This phishing operation, dubbed "Operation Asterix," was detailed by experts from Rapid7.

The attackers impersonated customer support representatives or sent fake emails, for instance, pretending to be from Crypto.com. Their primary objective was to trick users into visiting a phishing site or downloading a counterfeit application mimicking Ledger, Trezor, or Exodus to extract their seed phrases.

To facilitate this, hackers employed automated scripts to verify phone numbers against databases from major exchanges like Kraken and Binance.

Source: Rapid7.

According to Rapid7's findings, the campaign proved to be quite effective, with a match rate of 13.6% among a German sample, identifying 43,066 genuine crypto investors. Over 5,500 verified Binance accounts were prioritized for attacks. Analysts also noted that AI tools were actively used to generate phishing content.

The largest segment of stolen data included 316,002 phone numbers from Germany, with additional entries from the United States, the United Kingdom, Hong Kong, Bulgaria, Canadian fintech customers, and users whose data was leaked from Ledger wallet databases.

Fake AML Checkers Found Online Targeting Cryptocurrency Theft

Cybercriminals have developed counterfeit AML services to check the legitimacy of cryptocurrency wallets. This new phishing scheme was highlighted by cybersecurity experts at Malwarebytes.

The scammers replicated the designs of legitimate platforms like AMLBot or utilized generic brands such as AML Check.

The main trap involved requesting permission to connect a crypto wallet to initiate a "scan." Upon connection, the site simulated an in-depth blockchain analysis, displaying fake loading indicators. Victims consistently received reassuring results, indicating "Clean, low risk."

Source: Malwarebytes.

Under the guise of a "small fee" for the check or during the connection process, users were prompted to sign a transaction allowing a malicious smart contract to withdraw funds.

Malwarebytes noted that the scammers utilized a consistent website template, merely altering logos and names.

Hackers Compromise Popular Rust Developer Library

On August 20, hackers targeted the account of a programmer associated with the widely-used Rust package arrayref, injecting code that executed unnoticed during project compilation. In a 23-minute window, they also compromised two other libraries by the same author, append-only-vec and internment, according to experts from Wiz.

The potential scale of this threat is substantial, as arrayref alone has been downloaded over 245 million times and is a fundamental component in blockchain tools, including those for Ethereum and Solana.

The attack unfolded as follows:

  1. Hackers introduced a dependency on a malicious package named proc-macro1 (designed to resemble the popular proc-macro2).
  2. As the Cargo package manager automatically runs scripts during compilation, one such script, the fake build.rs, went unnoticed.
  3. The code analyzed the system and downloaded a loader tailored to the victim's operating system.

Experts revealed that the trojan's primary function was to gather system information and steal databases with saved passwords from popular browsers like Google Chrome, Brave, and Edge. To maintain persistence, the virus registered itself in the system's autostart.

Wiz also pointed out similarities in the network infrastructure of this campaign with recent attacks on Mastra and Axios, which Microsoft links to the North Korean group Sapphire Sleet.

Hackers Breach Approximately 14,500 Dahua Cameras in Ukraine and Russia

In just 35 days, from June 17 to July 22, 2026, hackers successfully compromised 14,530 Dahua surveillance cameras. Details of the hacking operation, dubbed CameraSwarm, were revealed by researchers at Hunt.io.

According to experts, the hackers were caught due to carelessness, having left an unsecured HTTP server from which analysts were able to copy 407 MB of data, including utility source codes, logs, credentials, and even intercepted images from the infected cameras.

Despite the global scanning of devices, the hackers primarily focused on telecom networks in Russia, Ukraine, and other countries. Comments in the hacking tools were found to be in Russian.

Source: Hunt.io.

The attackers employed three attack vectors simultaneously:

  • 12,324 cameras. Scanned open TCP port 37777, attempted password guessing, captured images from cameras, and automatically sent them to Telegram for subsequent export to the Dahua SMART PSS platform;
  • 1,923 cameras. Exploited vulnerabilities in devices that were five years old using the p2pwn tool. They created a hidden backdoor account (login p2pwn, password p2password) that persisted even after the legitimate owner changed security symbols and often survived factory resets;
  • 283 cameras. Accessed devices beyond NAT using only their serial numbers and credentials hardcoded in Dahua applications. This method allowed hackers to generate offline recovery codes and reset administrator passwords.

Experts advised Dahua camera owners to check their control panels for the hidden account p2pwn and remove it. For complete protection, they recommended disabling the P2P feature entirely (if not used for remote access) and ensuring that the firmware is updated to close vulnerabilities from 2021.

Trojan Transfers Stolen Data via Nearby Smartphones

A new Android trojan has targeted over 169 apps across various sectors, including banking, government, and cryptocurrency. Researchers from ThreatFabric reported on the malware named Manic.

This malware has been active at least since February 2026 and is distributed through third-party APK files. Hackers utilize secure loader shells to unpack the main body of the software directly into memory, effectively bypassing antivirus solutions.

Once access to Accessibility Services is granted, Manic overlays transparent layers over digital keyboards in banking apps, capturing each keystroke and classifying the stolen data: separating unlock PINs, seed phrases, SMS codes, and 2FA.

Additionally, the software can intercept system notifications, download personal files, track geolocation, and provide hackers with remote screen access in real-time via WebRTC sessions.

A unique feature of Manic is its backup data transmission mechanism. If the compromised smartphone goes offline, the virus seeks out nearby infected devices to transfer encrypted data via Wi-Fi Direct or Bluetooth. This setup forms a mesh network comprising four transit nodes, culminating in a smartphone connected to the internet.

Source: ThreatFabric.

The primary target of these hackers is users from Ukraine, as well as countries in Central and Western Europe, the UK, and Russia.

Also on ForkLog:

  • Experts warned of widespread crypto hacks using AI agents.
  • BitBox resolved two major vulnerabilities in Bitcoin wallet firmware.
  • OpenAI has slowed down AI model development due to cybersecurity risks.
  • The Maya Protocol team halted their network after a $1.7 million hack.
  • Harmony plans to roll back the blockchain following an attack that released trillions of ONE.
  • A vulnerability in Mac allowed the installation of hidden Monero miners.
  • SafePal reported a data breach affecting approximately 40,000 users.
  • A hacker stole data from 678,000 taxpayers in France.
  • Hackers stole over 1,700 BTC from vulnerable Coldcard wallets.

What to Read This Weekend?

ForkLog has compiled five stories about what happens when AI— the challenging child of technological giants—gets out of control.