{"id":24244,"date":"2025-05-24T07:00:00","date_gmt":"2025-05-24T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/darknet-crypto-millions-another-coinbase-setback-and-other-cybersecurity-developments\/"},"modified":"2025-05-24T07:00:00","modified_gmt":"2025-05-24T04:00:00","slug":"darknet-crypto-millions-another-coinbase-setback-and-other-cybersecurity-developments","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/darknet-crypto-millions-another-coinbase-setback-and-other-cybersecurity-developments\/","title":{"rendered":"Darknet crypto millions, another Coinbase setback and other cybersecurity developments"},"content":{"rendered":"<p>Here are the week\u2019s key cybersecurity developments.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Authorities seized hundreds of millions of dollars in cryptocurrency from a drug-trafficking network.<\/li>\n<li>Malicious crypto utilities were found among Chrome extensions.<\/li>\n<li>Media reported dozens of U.S. government victims from a hacked Signal clone.<\/li>\n<li>Vietnam will start blocking Telegram over its refusal to cooperate.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Authorities seize hundreds of millions of dollars in cryptocurrency from drug network<\/strong><\/h2>\n<p>Law enforcement in 10 countries seized $200m in fiat and cryptocurrencies and arrested 270 people allegedly tied to a large network of drug and weapons traffickers, the U.S. Department of Justice <a href=\"https:\/\/www.justice.gov\/opa\/pr\/law-enforcement-seize-record-amounts-illegal-drugs-firearms-and-drug-trafficking-proceeds\">said<\/a>.\u00a0<\/p>\n<p>Authorities confiscated more than two tonnes of drugs, 144 kg of fentanyl-laced substances and 180 firearms.<\/p>\n<p>U.S. prosecutors charged several major vendors, including the operators of <a href=\"https:\/\/forklog.com\/en\/news\/us-sanctions-target-darknet-marketplace-nemesis-wallets\">Nemesis<\/a> and <a href=\"https:\/\/forklog.com\/en\/news\/taiwanese-citizen-arrested-in-new-york-for-running-incognito-market\">Incognito Markets<\/a>, who used cryptocurrency to sell opioids and conceal proceeds.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Malicious crypto utilities found among Chrome extensions<\/strong><\/h2>\n<p>Security researchers at DomainTools <a href=\"https:\/\/github.com\/DomainTools\/SecuritySnacks\/blob\/main\/2025\/DualFunction-Malware-Chrome-Extensions\">discovered<\/a> more than 100 malicious Chrome extensions masquerading as legitimate applications, including crypto utilities, YouTube tools, VPNs and AI assistants.\u00a0<\/p>\n<p>Installing them risks account takeover, theft of personal data and monitoring of network activity. Ultimately they provide attackers with a backdoor into the infected browser, giving them broad scope for exploitation.<\/p>\n<p>Stolen session cookies can enable compromise of legitimate VPN devices or company accounts, opening access to corporate networks for larger-scale attacks.<\/p>\n<p>Google removed most of the extensions, though some remained in the Chrome Web Store at the time of writing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Lumma crypto-stealer loses thousands of domains and part of its servers<\/strong><\/h2>\n<p>U.S. agencies <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-seizes-domains-behind-major-information-stealing-malware-operation\">seized<\/a> the Lumma stealer\u2019s control panel; counterparts in Europe and Japan neutralised parts of the malware\u2019s infrastructure; and Microsoft, via court action, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2025\/05\/21\/microsoft-leads-global-action-against-favored-cybercrime-tool\/\">blocked<\/a> about 2,300 of its domains.<\/p>\n<p>Active since late 2022, the threat spread via GitHub comments and deepfake-generation sites. Subscriptions ranged from $250 to $1,000.<\/p>\n<p>After a breach, Lumma can steal data from browsers and applications, including crypto wallets, cookies, credentials, passwords and credit cards. The stealer has extensive detection-evasion capabilities.<\/p>\n<p>Separately, Europol <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source\">took down<\/a> about 300 servers, neutralised 650 domains and issued arrest warrants for 20 cybercriminals linked to Bumblebee, Lactrodectus, <a href=\"https:\/\/www.documentcloud.org\/documents\/25951833-qakbot-indictment\/\">QakBot<\/a>, DanaBot, TrickBot and WARMCOOKIE. More than \u20ac21.2m was seized, including \u20ac3.5m in cryptocurrency.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Media report dozens of U.S. government victims from hacked Signal clone\u00a0<\/strong><\/h2>\n<p>Hackers who breached in early May a modified Signal client from TeleMessage intercepted messages from more than 60 senior U.S. officials, <a href=\"https:\/\/www.reuters.com\/world\/us\/hacker-who-breached-communications-app-used-by-trump-aide-stole-data-across-us-2025-05-21\/\">Reuters<\/a> reported.<\/p>\n<p>Victims included first responders, customs officers, several members of the U.S. diplomatic corps, at least one White House staffer and a Secret Service member.\u00a0<\/p>\n<p>According to the report, on 4 May the attackers compromised a TeleMessage server. The company makes encrypted modifications of well-known messengers. Access to internal infrastructure allowed them to dump 410 GB of user messages in under 20 minutes.\u00a0<\/p>\n<p>The intruders also accessed internal correspondence of staff at the Coinbase cryptocurrency exchange. However, platform representatives <a href=\"https:\/\/techcrunch.com\/2025\/05\/05\/telemessage-a-modified-signal-clone-used-by-us-government-officials-has-been-hacked\/\">said<\/a> they did not use the messenger to transmit critically important client information.<\/p>\n<p>The organisation <span data-descr=\"Distributed Denial of Secrets\" class=\"old_tooltip\">DDoSecrets<\/span> announced <a href=\"https:\/\/ddosecrets.com\/article\/telemessage\">access<\/a> for researchers and journalists to a database including TeleMessage users\u2019 correspondence and metadata.<\/p>\n<h2 class=\"wp-block-heading\"><strong>EU sanctions web host Stark Industries and a Roskomnadzor unit<\/strong><\/h2>\n<p>The Council of the EU <a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2025\/05\/20\/russian-hybrid-threats-eu-lists-further-21-individuals-and-6-entities-and-introduces-sectoral-measures-in-response-to-destabilising-activities-against-the-eu-its-member-states-and-international-partners\/\">added to its sanctions list<\/a> the web-hosting provider Stark Industries and two of its executives\u2014CEO Yuriy Nekuliti and owner Ivan Nekuliti\u2014for facilitating cyberattacks on behalf of Russia.\u00a0<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cThey acted as enablers of various actors sponsored by and linked to the Russian state to carry out destabilising activities, including interference in information manipulation and cyberattacks against the EU and third countries,\u201d the statement said.<\/p>\n<\/blockquote>\n<p>Stark Industries is registered in the United Kingdom and provides <span data-descr=\"virtual dedicated servers\" class=\"old_tooltip\">VPS\/VDS<\/span> servers in the UK, the Netherlands, Germany, France, Turkey and the U.S. The provider accepts payments including bitcoin, Ethereum, Monero and Dash.<\/p>\n<p>Experts <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/european-union-sanctions-stark-industries-for-enabling-cyberattacks\/\">link<\/a> numerous disinformation campaigns and <span data-descr=\"distributed denial of service\" class=\"old_tooltip\">DDoS<\/span> attacks in Russia\u2019s favour to servers operated by Stark Industries and other services provided by the Nekuliti brothers.<\/p>\n<p>Also sanctioned was a Roskomnadzor entity \u2014 the <span data-descr=\"Federal State Unitary Enterprise\" class=\"old_tooltip\">FSUE<\/span> \u201cMain Radio Frequency Centre\u201d \u2014 for involvement in electronic warfare through GPS jamming and spoofing in the Baltic states, as well as for disrupting civil aviation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Vietnam to block Telegram over refusal to cooperate<\/strong><\/h2>\n<p>Vietnam\u2019s technology ministry accused the Telegram messenger of refusing to cooperate with law enforcement and ordered it blocked nationwide by 2 June, <a href=\"https:\/\/www.reuters.com\/sustainability\/society-equity\/vietnam-acts-block-messaging-app-telegram-government-document-seen-by-reuters-2025-05-23\/\">Reuters<\/a> reported.\u00a0<\/p>\n<p>Authorities say 68% of 9,600 channels and groups on the messenger in Vietnam violate the law, allegedly spreading \u201ctoxic\u201d information, publishing anti-government materials and facilitating crimes including fraud and drug trafficking.<\/p>\n<p>The statement stressed that Telegram has not registered its operations in the country, does not remove prohibited content at police request and does not provide the government with user data for criminal investigations.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Hackers <a href=\"https:\/\/forklog.com\/en\/news\/hackers-drain-11m-from-cetus-pool-on-sui\">drained $11m<\/a> from the Cetus pool on Sui; the team offered <a href=\"https:\/\/forklog.com\/en\/news\/cetus-offers-hacker-6-million-for-return-of-20920-eth\">$6m for the return<\/a> of funds.<\/li>\n<li>Hackers created a <a href=\"https:\/\/forklog.com\/en\/news\/hackers-develop-malicious-ledger-live-clone-for-macos\">malicious clone of Ledger Live<\/a> for macOS.<\/li>\n<li>Anthropic <a href=\"https:\/\/forklog.com\/en\/news\/anthropics-chatbots-report-users-to-authorities\">trained chatbots to \u2018snitch\u2019<\/a> on users.<\/li>\n<li>Researchers built an AI system to <a href=\"https:\/\/forklog.com\/en\/news\/ai-system-developed-to-combat-address-poisoning-attacks\">prevent \u2018poisoning\u2019 attacks<\/a> on addresses.<\/li>\n<li>A hacker linked to the $300m Coinbase theft <a href=\"https:\/\/forklog.com\/en\/news\/hacker-linked-to-300-million-coinbase-theft-swaps-45-million-via-thorchain\">swapped $45m<\/a> via Thorchain.<\/li>\n<li>Coinbase disclosed the <a href=\"https:\/\/forklog.com\/en\/news\/coinbase-reveals-number-of-users-affected-by-data-breach\">number of users affected<\/a> by the data leak.<\/li>\n<li>edgeX launched an ecosystem focused on a non-custodial design and trader <a href=\"https:\/\/forklog.com\/en\/news\/edgex-launches-ecosystem-focusing-on-non-custodial-and-private-trading\">privacy<\/a>.<\/li>\n<li>A World Liberty Financial executive was <a href=\"https:\/\/forklog.com\/en\/news\/world-liberty-financial-executive-accused-of-fraud\">charged<\/a> with fraud.<\/li>\n<li><a href=\"https:\/\/forklog.com\/en\/news\/russia-proposes-legislation-on-cryptocurrency-confiscation-and-tokenization\">Confiscation<\/a> and tokenisation: Russia prepared draft laws on digital assets.<\/li>\n<li>The author of \u201cThe Bitcoin Standard\u201d backed an initiative to <a href=\"https:\/\/forklog.com\/en\/news\/author-of-the-bitcoin-standard-backs-blockchain-spam-mitigation-effort\">fight spam<\/a> on-chain.<\/li>\n<li>Criminals have begun <a href=\"https:\/\/forklog.com\/en\/news\/criminals-target-families-of-crypto-entrepreneurs\">targeting the families<\/a> of crypto entrepreneurs.<\/li>\n<li>Bloomberg: in a replay of Coinbase, <a href=\"https:\/\/forklog.com\/en\/news\/bloomberg-hackers-target-binance-and-kraken-in-coinbase-style-attacks\">hackers targeted Binance<\/a> and Kraken.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to read this weekend?<\/strong><\/h2>\n<p>NoOnes P2P platform founder Ray Youssef told ForkLog about the project\u2019s security overhaul and offered advice for crypto maximalists.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here are the week\u2019s key cybersecurity developments. Authorities seized hundreds of millions of dollars in cryptocurrency from a drug-trafficking network. Malicious crypto utilities were found among Chrome extensions. Media reported dozens of U.S. government victims from a hacked Signal clone. Vietnam will start blocking Telegram over its refusal to cooperate. Authorities seize hundreds of millions [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24243,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-24244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"20","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/24244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=24244"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/24244\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/24243"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=24244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=24244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=24244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}