{"id":82358,"date":"2023-07-29T07:00:00","date_gmt":"2023-07-29T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=82358"},"modified":"2025-09-12T04:31:32","modified_gmt":"2025-09-12T01:31:32","slug":"attack-on-nato-portal-malware-in-blockchain-games-and-other-cybersecurity-events","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/attack-on-nato-portal-malware-in-blockchain-games-and-other-cybersecurity-events\/","title":{"rendered":"Attack on NATO portal, malware in blockchain games and other cybersecurity events"},"content":{"rendered":"<p>We have gathered the week&#8217;s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>The founder of Group-IB was sentenced to 14 years in prison.<\/li>\n<li>Hacker group SiegedSec claimed to have breached NATO&#8217;s portal.<\/li>\n<li>Malware that steals cryptocurrency was placed in blockchain games.<\/li>\n<li>The BreachForums database was put up for sale.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Founder of Group-IB sentenced to 14 years in prison<\/strong><\/h2>\n<p>On 26 July, Ilya Sachkov, founder of Group-IB, the company specialising in preventing cyberattacks, was sentenced to 14 years in a high-security prison for treason. This was reported by <a href=\"https:\/\/www.bbc.com\/russian\/articles\/cgedq11zqn9o\">BBC<\/a>.<\/p>\n<p>The case was heard in camera, so it is unclear what exactly is charged. He did not admit his guilt.<\/p>\n<p>According to some sources, Sachkov <a href=\"https:\/\/u1f987.com\/en\/news\/fbi-access-to-messaging-apps-mandatory-2fa-at-facebook-and-other-cybersecurity-developments\">about the Russian hackers Fancy Bear<\/a> involved in attacks before the 2016 presidential election. This allegedly helped the United States identify 12 \u201cGRU agents\u201d involved in the attacks.<\/p>\n<p>The entrepreneur <a href=\"https:\/\/u1f987.com\/en\/news\/group-ib-offices-raided-founder-arrested-in-treason-case\">arrested<\/a> in September 2021. Previously he was among cybercrime experts in committees at the State Duma, <span data-descr=\"Ministry of Foreign Affairs\" class=\"old_tooltip\">\u041c\u0418\u0414<\/span> of the Russian Federation, the Council of Europe and <span data-descr=\"Organization for Security and Cooperation in Europe\" class=\"old_tooltip\">\u041e\u0411\u0421\u0415<\/span>.<\/p>\n<p>Sachkov&#8217;s defence intends to appeal the verdict and approach the president of the Russian Federation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>SiegedSec hackers claim breach of NATO portal<\/strong><\/h2>\n<p>The hacker group SiegedSec said in its Telegram channel that it breached the <span data-descr=\"Communities of Interest Cooperation Portal\" class=\"old_tooltip\">COI<\/span> \u2014 a non-classified information-sharing environment for NATO organisations and alliance member states. The incident drew the attention of experts <a href=\"https:\/\/www.cloudsek.com\/threatintelligence\/siegedsec-allegedly-breached-natos-coi-portal-affecting-31-nations-leaked-sensitive-data\">CloudSEK<\/a>.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"842\" height=\"1024\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_224236_twitter.com_-842x1024.png\" alt=\"Opera-Snimok_2023-07-28_224236_twitter.com_\" class=\"wp-image-212497\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_224236_twitter.com_-842x1024.png 842w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_224236_twitter.com_-247x300.png 247w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_224236_twitter.com_-768x934.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_224236_twitter.com_.png 878w\" sizes=\"auto, (max-width: 842px) 100vw, 842px\" \/><figcaption class=\"wp-element-caption\">Data: <a href=\"https:\/\/twitter.com\/cloudsek\/status\/1684867014408736769\">X<\/a>.<\/figcaption><\/figure>\n<p>According to their data, the total volume of files purportedly leaked amounts to 845 MB. They contain about 8,000 lines of confidential user information, non-secret documents, and access credentials.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"438\" height=\"553\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/screenshot_1-138.webp\" alt=\"screenshot_1-138\" class=\"wp-image-212496\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/screenshot_1-138.webp 438w, https:\/\/u1f987.com\/wp-content\/uploads\/screenshot_1-138-238x300.webp 238w\" sizes=\"auto, (max-width: 438px) 100vw, 438px\" \/><figcaption class=\"wp-element-caption\">Data: SiegedSec Telegram channel.<\/figcaption><\/figure>\n<p>The files include:<\/p>\n<ul class=\"wp-block-list\">\n<li>full names;<\/li>\n<li>the company or division name;<\/li>\n<li>information about the workgroup;<\/li>\n<li>position;<\/li>\n<li>corporate email ID;<\/li>\n<li>residential address;<\/li>\n<li>photos.<\/li>\n<\/ul>\n<p>CloudSEK noted that the leak could affect 31 countries.<\/p>\n<p>Representatives of the alliance are investigating the incident. The hackers themselves said the breach was a \u201cretaliatory strike against NATO countries for their attacks on human rights.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><strong>Malware that steals cryptocurrency embedded in blockchain games<\/strong><\/h2>\n<p>SentinelOne researchers detected Realst malware in fake blockchain games, designed to steal cryptocurrency from macOS users.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"814\" height=\"1024\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_232632_twitter.com_-814x1024.png\" alt=\"Opera-Snimok_2023-07-28_232632_twitter.com_\" class=\"wp-image-212495\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_232632_twitter.com_-814x1024.png 814w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_232632_twitter.com_-238x300.png 238w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_232632_twitter.com_-768x966.png 768w, https:\/\/u1f987.com\/wp-content\/uploads\/Opera-Snimok_2023-07-28_232632_twitter.com_.png 876w\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" \/><figcaption class=\"wp-element-caption\">Data: <a href=\"https:\/\/twitter.com\/SentinelOne\/status\/1684264044319113218\">X<\/a>.<\/figcaption><\/figure>\n<p>In addition, the Rust-based malware can take screenshots, steal saved passwords from browsers, and exfiltrate information from the Telegram messenger.<\/p>\n<p>The attackers promote counterfeit games on social networks and invite users to test them as part of paid collaborations. Each has its own site, as well as accounts on X (formerly Twitter) and Discord. In total, researchers identified 16 variants and 59 Realst samples.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"999\" height=\"600\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/olymp.webp\" alt=\"olymp\" class=\"wp-image-212494\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/olymp.webp 999w, https:\/\/u1f987.com\/wp-content\/uploads\/olymp-300x180.webp 300w, https:\/\/u1f987.com\/wp-content\/uploads\/olymp-768x461.webp 768w\" sizes=\"auto, (max-width: 999px) 100vw, 999px\" \/><figcaption class=\"wp-element-caption\">Site of one of the fake games. Data: iamdeadlyz.gitbook.io.<\/figcaption><\/figure>\n<p>Hackers send access codes for downloading fake game clients via direct messages, helping to avoid attention from information-security researchers.<\/p>\n<h2 class=\"wp-block-heading\"><strong>BreachForums database put up for sale<\/strong><\/h2>\n<p>A user under the nickname breached_db_person is offering on the dark web the BreachForums database of the recently shuttered hacker forum BreachForums for $100,000\u2013150,000. This is reported by <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/breachforums-database-and-private-chats-for-sale-in-hacker-data-breach\/\">Bleeping Computer<\/a>, citing the Have I Been Pwned data breach aggregator.<\/p>\n<p>A 2 GB dump dated November 29, 2022 contains 212,000 records, including usernames, IP- and email addresses, as well as private messages, hashed passwords and payment transaction information.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"563\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/breached-database-structure-1024x563.webp\" alt=\"breached-database-structure\" class=\"wp-image-212493\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/breached-database-structure-1024x563.webp 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/breached-database-structure-300x165.webp 300w, https:\/\/u1f987.com\/wp-content\/uploads\/breached-database-structure-768x422.webp 768w, https:\/\/u1f987.com\/wp-content\/uploads\/breached-database-structure.webp 1373w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Data: Bleeping Computer.<\/figcaption><\/figure>\n<p>The forum\u2019s current administrator under the nickname Baphomet confirmed the authenticity of the leak, calling it part of a \u201ccontinuing campaign to destroy the community.\u201d<\/p>\n<p>U.S. law enforcement closed BreachForums in March 2023. Its founder and administrator Conor Bryan Fitzpatrick, known by the nickname Pompompurin, <a href=\"https:\/\/u1f987.com\/en\/news\/kamikaze-usb-drive-explodes-a-popular-hacking-forum-shuts-down-and-other-cybersecurity-events\">arrested<\/a>. In late June the FBI gained <a href=\"https:\/\/u1f987.com\/en\/news\/prison-bitcoin-scheme-arrest-of-an-f-a-c-c-t-executive-and-other-cybersecurity-developments\">control over the forum&#8217;s backup domain<\/a> on the clear web.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Russian telecom regulators barred from providing communications services without installing TSPU<\/strong><\/h2>\n<p>On 26 July the State Duma, in final reading, <a href=\"https:\/\/sozd.duma.gov.ru\/bill\/1214072-7\">adopted<\/a> a law requiring owners or other holders of traffic exchange points to install technical threat countermeasures (TSPU).<\/p>\n<p>Non-compliance with the new rules would lead to the revocation of the telecom operator&#8217;s licence.<\/p>\n<p>In addition, passing traffic around TSPU without authorization risks fines from 1 million to 5 million roubles for providers, and 1.5 million roubles for the company leadership.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Experts describe crypto laundering schemes through online gambling<\/strong><\/h2>\n<p>Online gambling platforms are used by criminal syndicates to launder stolen or fraudulently obtained cryptocurrencies. This is stated in a report by analytics firm <a href=\"https:\/\/wublock.substack.com\/p\/online-gambling-channels-accelerate\">Bitrace<\/a>.<\/p>\n<p>According to their data, in 2022 more than $7.6 billion in USDT linked to online gambling was moved to hot wallets.<\/p>\n<p>A significant portion of these funds originated from addresses involved in fraud and phishing.<\/p>\n<p>Of 20 other wallets selected for analysis, more than 40% of the total earnings of payment services had links to money laundering and illicit activity.<\/p>\n<p>Analysts attribute this trend to the lack of proper Know Your Customer \/ anti-money laundering (KYC\/AML) mechanisms in crypto-processing services that enable settlements with online gaming platforms.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Experts warned of the risk of cryptocurrency losses when trading through Telegram bots.<\/li>\n<li>The French regulator doubted the legality of Worldcoin&#8217;s biometric collection.<\/li>\n<li>SlowMist uncovered a new type of attacks on Bitcoin exchanges.<\/li>\n<li>Blockchain firms will be required to inform the SEC about breaches.<\/li>\n<li>Spanish crypto billionaire was found dismembered in Argentina.<\/li>\n<li>The US prosecutors urged to keep Sam Bankman-Fried in custody, while his lawyers urged to limit witnesses&#8217; extrajudicial statements.<\/li>\n<li>A user lost bitcoins due to a key generator.<\/li>\n<li>Lazarus Group suspected of hacking CoinsPaid for $37 million.<\/li>\n<li>Australia fined Meta $14 million for covert collection of personal data.<\/li>\n<li>Study: the number of cryptojacking attacks tripled.<\/li>\n<li>South Korea formed a task force to combat crypto crime.<\/li>\n<li>USDT recognised as property in the Bybit case.<\/li>\n<li>A US family organised a pyramid scheme \u201cBlessing through Cryptocurrency.\u201d<\/li>\n<li>DeFi protocol EraLend was hacked for $3.4 million.<\/li>\n<li>Azimut Group refused to pay ransomware BlackCat.<\/li>\n<li>Losses from the Alphapo breach were estimated at $60 million.<\/li>\n<li>Kazakhstan uncovered a scheme to buy cryptocurrency with counterfeit dollars.<\/li>\n<li>App Store found malware to bypass 2FA and steal cryptocurrency.<\/li>\n<li>Arkham users announced a bounty for discovering Do Kwon&#8217;s wallets.<\/li>\n<li>A court sentenced an American woman who paid for her husband\u2019s murder with Bitcoin.<\/li>\n<li>Unknown actors posing as the FBI stole cryptocurrency from couples in New York.<\/li>\n<li>Delio warned of a potential closure after asset seizures.<\/li>\n<li>Attackers stole more than $23 million in cryptocurrencies from Alphapo.<\/li>\n<li>The U.S. Department of Justice will widen investigations into cryptocurrencies.<\/li>\n<li>TRM Labs confirmed the use of cryptocurrency by ISIS supporters.<\/li>\n<li>Defendants in the Bitfinex bitcoin laundering case pleaded guilty.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to read this weekend?<\/strong><\/h2>\n<p>In a special feature, we explain how crypto-scam channels operate in Telegram.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have gathered the week&#8217;s most important cybersecurity news.<\/p>\n","protected":false},"author":1,"featured_media":82359,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-82358","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"42","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/82358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=82358"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/82358\/revisions"}],"predecessor-version":[{"id":82360,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/82358\/revisions\/82360"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/82359"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=82358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=82358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=82358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}