News linked to both this project and an event.
According to Bitcoin.com, cybersecurity company Genians Security Center released an analysis report stating that the North Korean Reconnaissance General Bureau-affiliated hacker group Kimsuky is building and testing an AI-centric cyberattack tool suite. Researchers discovered traces of the deployment of three local AI platforms, Ollama, GPT4All, and Msty, in their infrastructure, as well as AI development framework components such as Microsoft Semantic Kernel and LLaMaSharp, indicating that the organization is systematically developing dedicated AI attack tools rather than just making temporary attempts. Since early 2026, Kimsuky has used high-quality documents created by generative AI for spear-phishing attacks targeting the virtual assets, financial investment, and game development sectors; AI-generated professional documents have significantly reduced the effectiveness of traditional phishing email identification. The attack vector consists of ZIP archives disguised as legitimate documents, containing malicious LNK files that can silently execute PowerShell commands in the background after being triggered.
Recently, the National Computer Virus Emergency Response Center of China and the National Engineering Laboratory for Computer Virus Prevention Technology, through the National Computer Virus Collaborative Analysis Platform, discovered multiple incidents within China where users were attacked by the "Sorry" ransomware. After users' important files were encrypted, the filenames were changed to the original filename + the ".sorry" suffix string. The attackers also left a ransom note on the users' hosts, requiring users to download an encrypted communication tool to contact them. (CCTV News)
Odaily News: Russia's Federal Security Service (FSB) conducted surprise raids on 9 unregistered cryptocurrency exchange service providers in Moscow, alleging they were involved in transferring funds obtained through fraud abroad via crypto assets. More than 20 employees were detained at the Moscow International Business Center.The FSB stated that these exchanges converted stolen funds from Russian phone scam victims into cryptocurrency and transferred them to accounts of what it claims are Ukrainian processors. The operation was carried out jointly by the FSB and the Russian Ministry of Internal Affairs.Russia's Ministry of Internal Affairs has launched a criminal investigation into large-scale fraud, which under Russian law carries a maximum sentence of 10 years in prison. The FSB said it is continuing to identify victims and assess potential compensation. (Cointelegraph)
the U.S. Department of Commerce's AI Standards and Innovation Center, in collaboration with the UK AI Safety Institute, tested the cyber attack capabilities of Kimi K3, emphasizing that "the United States still leads."However, the value of the evaluation is debated due to limitations in the testing scope. Due to hosting environment constraints, Kimi K3 only participated in partial testing, with its overall cyber capabilities estimated primarily based on 41 exploit benchmarks. In contrast, other models underwent more comprehensive testing, resulting in a larger margin of error for Kimi K3's results.In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2's 24%, but lower than the average of approximately 76% for leading U.S. models. In a simulated attack chain test, Kimi K3 completed an average of 17 out of 32 steps in the attack chain and successfully breached the network once in 10 attempts, while U.S. frontier models completed an average of 28.5 steps.The report notes that Kimi K3 already possesses a certain level of autonomous attack capability, and its security guardrails did not prevent the model from developing exploits or executing attacks. However, the report also emphasizes that the testing scope was limited.
the U.S. Attorney's Office for the District of Columbia, in coordination with the U.S. Secret Service's Washington Field Office, announced that investigations into multiple international cyber fraud cases have led to the seizure of over $25 million in cryptocurrency. The funds were allegedly linked to crypto investment scams targeting residents of the United States and Canada.This action is part of the "Scam Center Strike Force," an initiative launched in 2025 by District of Columbia Attorney Jeanine Ferris Pirro. To date, the task force has recovered assets totaling over $800 million. U.S. prosecutors stated that on July 21, 2026, the U.S. Attorney's Office for the District of Columbia filed five civil forfeiture complaints in the U.S. District Court, seeking the forfeiture of over $25 million in crypto assets recovered from various fraud investigations.Investigators indicated that these cases involve multiple money laundering networks with victims worldwide. Criminal groups lured victims into investing through fake crypto investment platforms and online romance scams, then laundered the funds through multi-layered wallet addresses and mixing operations to conceal the source of funds. The seized funds are associated with five major investigations:In one case, Canadian law enforcement provided the U.S. Secret Service with wallet addresses suspected of being used to transfer illicit proceeds. Investigators froze the relevant addresses and traced over 270 suspected victim transactions, involving approximately $10.4 million;The second case involved an online romance scam that defrauded over 200 victims. Illicit funds were transferred through hundreds of intermediate wallet addresses and commingled with funds from other victims, involving approximately $12.08 million;The third case involved a victim from the U.S. capital region who participated in a fraudulent crypto investment project. After failing to withdraw funds, the victim lost contact with the scammers, with the involved amount being approximately $1.23 million;In the fourth case, a victim transferred millions of dollars in cryptocurrency to a fake investment account. Investigators traced some of the funds to six wallet addresses and froze approximately $2.39 million;In the fifth case, scammers impersonated an agency that "recovers stolen funds" to trick victims into paying fees, with the involved amount being approximately $285,000.The U.S. Secret Service stated that these cases remain under active investigation. Law enforcement officials are tracking down the suspects behind the fraud network and will cooperate with international law enforcement agencies to hold them accountable.
Bybit’s Security Operations Center has identified a multi-stage malware campaign targeting macOS users of Claude Code, an AI-powered search and development tool. Attackers used search engine optimization (SEO) poisoning to push malicious domains to the top of Google search results, luring users to counterfeit installation pages. Once installed, the malware steals browser credentials, macOS Keychain data, Telegram sessions, VPN configurations, and cryptocurrency wallet information. Bybit stated that the malware can also establish persistent access via backdoor functionality and attempts to target over 250 browser wallet extensions and multiple desktop wallet applications. This malicious infrastructure was identified on March 12, and related analysis, mitigation, and detection measures were completed the same day.