{"id":97698,"date":"2026-05-30T07:00:00","date_gmt":"2026-05-30T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=97698"},"modified":"2026-05-30T09:06:28","modified_gmt":"2026-05-30T06:06:28","slug":"odessa-scammers-busted-stealth-gpu-cryptominer-and-more-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/odessa-scammers-busted-stealth-gpu-cryptominer-and-more-cybersecurity-news\/","title":{"rendered":"Odessa Scammers Busted, Stealth GPU Cryptominer and More Cybersecurity News"},"content":{"rendered":"<p>We\u2019ve gathered the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>A new group hit crypto companies via fake interviews and macOS malware.<\/li>\n<li>A stealth GPU miner spread through search spam and AI chatbots.<\/li>\n<li>A vigilante hacker was booted from GitHub and GitLab after posting Microsoft zero-days.<\/li>\n<li>CrowdStrike and Google dismantled a network targeting open-source developers.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\">New group hit crypto firms via fake interviews and macOS malware<\/h2>\n<p>Researchers at <a href=\"https:\/\/www.wiz.io\/blog\/threat-actors-target-crypto-orgs\">Wiz<\/a> uncovered a large-scale cryptocurrency theft campaign attributed to a previously unknown group, JINX-0164.<\/p>\n<p>Since mid-2025, the attackers have targeted blockchain developers through fake online interviews. During the exchange, the victim was redirected to a spoofed videoconferencing site. There, under the pretext of installing a client or fixing a &#8220;technical error,&#8221; the developer was persuaded to download an infected file.<\/p>\n<p>The group\u2019s toolkit includes sophisticated malware adapted for both Intel and Apple Silicon architectures:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>AUDIOFIX.<\/strong> Disguised as a system audio driver. It steals passwords, SSH keys, crypto wallet data, and sessions from Discord and Telegram. The software enables lateral movement across a company\u2019s internal network, infiltration of infrastructure, and injection of malicious code into active projects;<\/li>\n<li><strong>MiniRAT.<\/strong> Previously used in a supply-chain attack. It was distributed through a trojanized version of the legitimate npm package @velora-dex\/sdk, used in <a href=\"https:\/\/forklog.com\/en\/news\/what-is-decentralised-finance-defi\">DeFi<\/a> projects. MiniRAT allows remote command execution and loading of additional modules.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-17d87df402bc8945-5685156759025245.webp\" alt=\"image\" class=\"wp-image-280743\"\/><figcaption class=\"wp-element-caption\">Source: Wiz.<\/figcaption><\/figure>\n<p>Experts note that JINX-0164\u2019s tactics \u2014 a focus on crypto, targeting developers via fake recruiting, and the use of specific VPN services (for example, Astrill VPN) \u2014 resemble the modus operandi of North Korean groups such as BlueNoroff. However, Wiz found no direct technical overlaps in infrastructure to conclusively tie JINX-0164 to Pyongyang.<\/p>\n<h2 class=\"wp-block-heading\">Stealth GPU miner spread via search spam and AI chatbots\u00a0<\/h2>\n<p>As part of an ongoing cryptomining campaign, attackers are targeting high-performance graphics processing units (GPUs), according to <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/26\/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities\/\">Microsoft<\/a>.<\/p>\n<p>Infection occurs via malicious download pages for system utilities often installed on powerful PCs. Among them: CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear.<\/p>\n<p>Microsoft researchers found the attack begins when users search for these tools and follow malicious links boosted in results via SEO. Some April reports indicate users also landed on malicious domains after interacting with AI assistants. In those cases, victims asking a chatbot for software download recommendations received poisoned links in generated responses.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-127dbf44eb5d2214-5685156160241549.webp\" alt=\"image\" class=\"wp-image-280741\"\/><figcaption class=\"wp-element-caption\">Example of an AI chatbot response with an infected link. Source: Microsoft.<\/figcaption><\/figure>\n<p>Once a system is infected, the attacker gains persistent access by deploying the standard remote management tool ScreenConnect. The core of the malware masquerades as innocuous apps like the VLC player and sets itself to autorun. To evade defenses, the malware hides its code inside legitimate Windows system files and adds itself to antivirus exclusions.\u00a0<\/p>\n<p>After establishing a stealthy foothold, it downloads and launches a miner to secretly extract cryptocurrency using the victim\u2019s GPU power. The campaign uses the gminer, lolMiner, and SRBMiner-MULTI GPU miners.<\/p>\n<p>Microsoft noted the operators\u2019 behavior stands out for its &#8220;targeting and monetization strategy built from the ground up to maximize GPU-mining revenue from each compromised device&#8221; instead of chasing scale.<\/p>\n<h2 class=\"wp-block-heading\">Vigilante hacker kicked off GitHub and GitLab after posting Microsoft zero-days<\/h2>\n<p>Microsoft blocked the GitHub account of a cybersecurity researcher known as Nightmare-Eclipse and deleted his Microsoft account. GitLab then followed suit.<\/p>\n<p>The dispute stemmed from financial disagreements and exploit disclosure policy. As <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/july-14th.html\">claimed<\/a> by Nightmare-Eclipse, Microsoft ignored his vulnerability reports and refused to pay MSRC bounties that can reach $250,000.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-6565f63e3fb56e0c-5685156243738943.webp\" alt=\"image\" class=\"wp-image-280742\"\/><figcaption class=\"wp-element-caption\">Source: GitLab.<\/figcaption><\/figure>\n<p>In response, the researcher began publishing discovered <a href=\"https:\/\/forklog.com\/en\/news\/the-zero-day-market-discover-sell-and-keep-quiet\">zero-day vulnerabilities<\/a> openly and said he will release another batch on July 14, 2026.<\/p>\n<p>He disclosed:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>BlueHammer.<\/strong> Locally elevates privileges in Windows Defender. Allows an attacker with standard user access to escalate to full SYSTEM rights;<\/li>\n<li><strong>RedSun.<\/strong> Exploits a different antivirus code flaw than BlueHammer but achieves a similar outcome;<\/li>\n<li><strong>UnDefend.<\/strong> A tool aimed at sabotaging Windows Defender. The exploit makes the system believe an endpoint is protected and the antivirus is functioning correctly, while effectively depriving Defender of the ability to detect malware;<\/li>\n<li><strong>GreenPlasma.<\/strong> A vulnerability that grants SYSTEM privileges via the CTFMon system service responsible for alternative text input and language bars;<\/li>\n<li><strong>MiniPlasma.<\/strong> A local privilege escalation exploit via the Windows cloud filter driver cldflt.sys. Successfully grants SYSTEM rights even on fully updated Windows 11 versions;<\/li>\n<li><strong>YellowKey.<\/strong> A critical vulnerability in BitLocker disk encryption. With physical access, an attacker can bypass protections and open encrypted data with minimal effort, nullifying the technology\u2019s purpose.<\/li>\n<\/ul>\n<p>In addition, Nightmare-Eclipse <a href=\"https:\/\/deadeclipse666.blogspot.com\/\">announced<\/a> the creation of a &#8220;<span data-descr=\"Dead man's switch\" class=\"old_tooltip\">dead man\u2019s switch<\/span>&#8221; \u2014 an automated system that will dump new exploits online if he is arrested or physically eliminated.<\/p>\n<h2 class=\"wp-block-heading\">CrowdStrike and Google dismantled a network targeting open-source developers<\/h2>\n<p>In a joint operation, CrowdStrike, Shadowserver, and Google <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/inside-crowdstrike-takedown-of-a-developer-targeting-botnet\/\">took down<\/a> an infrastructure used to spread malware and steal passwords from open-source software developers.<\/p>\n<p>The target was the hackers behind the Glassworm botnet, which for two years attacked supply chains in the <span data-descr=\"Open Source\" class=\"old_tooltip\">OS<\/span> ecosystem.<\/p>\n<p>Glassworm operators used several strategies to distribute malicious code, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>publishing infected extensions in developer marketplaces;<\/li>\n<li>malvertising \u2014 buying sponsored search results to trick victims into downloading malware;<\/li>\n<li>using credentials stolen in prior breaches to take over developer accounts and inject malicious code directly into their projects.<\/li>\n<\/ul>\n<p>According to CrowdStrike, the hackers managed to &#8220;poison&#8221; more than 300 GitHub repositories. Specialists dismantled four command-and-control servers that relied on the <a href=\"https:\/\/forklog.com\/en\/news\/india-arrests-trafficker-solana-used-as-a-dead-drop-and-other-cybersecurity-developments\">Solana blockchain<\/a>, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers. This severed the attackers\u2019 access to infected machines and halted further malware delivery.<\/p>\n<h2 class=\"wp-block-heading\">In Odessa, scammers used advanced AI to steal about 2.5 million hryvnias<\/h2>\n<p>Ukrainian law enforcement, together with Kazakhstan\u2019s cyber police, <a href=\"https:\/\/npu.gov.ua\/news\/v-odesi-natspolitsiia-vykryla-zlochynnu-orhanizatsiiu-shakhraiv-iaki-oshukuvaly-hromadian-cherez-merezhu-mizhnarodnykh-feikovykh-call-tsentriv\">exposed<\/a> a large criminal organization in Odessa.<\/p>\n<p>The phone scammers targeted citizens of Kazakhstan. Preliminary losses total around 2.5 million hryvnias (about $57,000 at the time of writing).<\/p>\n<p>The fraudsters used advanced social engineering tools, including deepfakes and AI-generated video. Posing as law enforcement officers, bank employees, or telecom staff, they created a sense of threat. Under the pretense of &#8220;protecting the account&#8221; or avoiding fabricated criminal charges, they convinced victims to install malware on their smartphones to steal funds.<\/p>\n<p>According to investigators, two Odessa residents organized the illegal network. The call centers operated like a streamlined business with their own CRM system and clear role distribution. Staff included HR managers, administrators, IT specialists, and operators of various levels.\u00a0<\/p>\n<p>During searches, police detained nine people and seized equipment, off-the-books accounting records, cars, and cash. The suspects face up to 12 years in prison with asset confiscation.<\/p>\n<h2 class=\"wp-block-heading\">Carnival, the world\u2019s largest cruise operator, confirms breach affecting 6 million customers<\/h2>\n<p>Carnival Corporation, the world\u2019s largest cruise line operator, officially <a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/d6729ef2-7bb3-42d3-abdd-99a1dd8f2415.html\">confirmed<\/a> a large-scale data leak impacting nearly 6 million people.<\/p>\n<p>The incident occurred on April 10, 2026, via a social-engineering attack: the intruders tricked an employee and gained access to corporate systems. The company then began mass notifications to affected individuals.<\/p>\n<p>According to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people\/\">BleepingComputer<\/a>, the ShinyHunters group claimed responsibility, saying they stole terabytes of corporate data.\u00a0<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-6d078b0824b8c806-5685156754196441.webp\" alt=\"image\" class=\"wp-image-280744\"\/><figcaption class=\"wp-element-caption\">A ShinyHunters post on the dark web. Source: BleepingComputer.<\/figcaption><\/figure>\n<p>Analysis indicates the hackers obtained databases of Holland America loyalty program members. Compromised information includes names, dates of birth, email addresses, gender, and customers\u2019 locations.<\/p>\n<p>It\u2019s another reputational blow for Carnival: in <a href=\"https:\/\/smartmaritimenetwork.com\/2020\/08\/18\/carnival-corporation-confirms-ransomware-attack\/\">2020<\/a> and <a href=\"https:\/\/www.databreachtoday.com\/2nd-breach-hits-carnivals-cruise-lines-a-16906\">2021<\/a>, the company\u2019s systems suffered successful cyberattacks that exposed passengers\u2019 and crew members\u2019 personal and financial data.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Hacker <a href=\"https:\/\/forklog.com\/en\/news\/hacker-seizes-15-million-gua-airdrop\">hijacked<\/a> a $15 million GUA airdrop.<\/li>\n<li>Fake Uniswap ads on Google <a href=\"https:\/\/forklog.com\/en\/news\/fake-uniswap-ad-on-google-nets-scammers-400000\">netted<\/a> scammers $400,000.<\/li>\n<li>Squid <a href=\"https:\/\/forklog.com\/en\/news\/squid-denies-involvement-in-3-million-contract-breach\">denied<\/a> a $3 million contract hack.<\/li>\n<li>Socket <a href=\"https:\/\/forklog.com\/en\/news\/socket-uncovers-supply-chain-attack-on-cryptocurrency-and-ai-developers\">identified<\/a> an attack targeting crypto and AI developers.<\/li>\n<li>10,000 critical vulnerabilities: Anthropic <a href=\"https:\/\/forklog.com\/en\/news\/anthropic-reveals-10000-critical-vulnerabilities-in-project-glasswings-initial-report\">reported<\/a> initial Project Glasswing results.<\/li>\n<li>StablR\u2019s EURR and USDR stablecoins <a href=\"https:\/\/forklog.com\/en\/news\/stablrs-eurr-and-usdr-stablecoins-lose-peg-after-2-8-million-hack\">lost their pegs<\/a> after a $2.8 million hack.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">What to read this weekend?<\/h2>\n<p>The weekend is a chance not only to rewatch favorites, but to rethink them. ForkLog got a head start and explored why Johnny, the protagonist of Mike Leigh\u2019s classic &#8220;Naked,&#8221; is not just a misanthrope with a Manchester accent, but an early prototype of a cypherpunk without the internet.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve compiled the week\u2019s key cybersecurity news.<\/p>\n","protected":false},"author":1,"featured_media":97699,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"This week\u2019s top cybersecurity: crypto heists, GPU cryptojacking, dev-targeted botnets, and more.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-97698","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"16","promo_type":"1","layout_type":"1","short_excerpt":"This week\u2019s top cybersecurity: crypto heists, GPU cryptojacking, dev-targeted botnets, and more.","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/97698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=97698"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/97698\/revisions"}],"predecessor-version":[{"id":97700,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/97698\/revisions\/97700"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/97699"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=97698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=97698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=97698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}