CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Microsoft knows your entire browser history — and it can send it to the FBI

Virtual Private Networks are meant to shield your browsing history from all manner of prying eyes, including your internet service provider, your workplace or school, and even potential hackers. If you use a VPN with your Windows PC, though, I have some bad news: Microsoft has a full record of your browsing habits, and it can even report your activity to the FBI.

According to court documents released on July 1, a 19-year-old young man working with the cyber criminal group known as Scattered Spider was caught hacking into a computer system belonging to a luxury jewelry store. While inside, the hacker stole company data and demanded $8 million in cryptocurrency for ransom. Ultimately, the jewelry store kicked the hacker out of its system without paying the ransom, and the perpetrator was later arrested and charged.

It’s a simple case of conspiracy, digital intrusion, and fraud … but there’s a catch.

The hacker’s identity should have been hidden from the feds.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading

A Law That the People It Targets Can Defeat With a Felt-Tip Pen

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced on 24 August 2026 – the very day I arrived back in New Zealand after nearly a month away.

Readers of “A Halflings View” will be well aware of my views about bans or restrictions on access to social media platform by the young. Although the news media have trumpeted the present proposals as a “ban” it is not. It actually constitutes a form of limited restriction.

This article is very much a “first impression” view of the Bill. Much of the material and commentary is gathered from earlier writings I have produced on the subject as well as from other sources among them Ani O’Brien, “Thought Crimes” (Substack) — “Hear me out: Ban the hardware not the software”; the New Zealand Initiative; Privacy Commissioner Michael Webster; UNICEF Aotearoa (Susan Glasgow); Australia’s eSafety Commissioner three-month evaluation (July 2026); UK Ofcom/House of Lords material and reporting on the Online Safety Act; and US litigation (NetChoice; the Louisiana and Arkansas decisions).

Furthermore, this article (and indeed the Bill itself) will not be the final word.

The Bill has not yet had its First Reading and that is unlikely before Parliament rises. But Prime Minister Luxon and Erica Stanford were determined to push this ill-advised proposal ahead at pace, even although what it really amounts to is an announcement until the Bill has its First Reading. And it may even fall at that fence. If it makes it, Select Committee submissions and further commentary will accumulate quickly.

Hence the critique reflects the position as at the time of publication of this article.

What the Bill actually does

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, introduced to Parliament on 24 August 2026 by Education Minister Erica Stanford, is a stand-alone statute built on two load-bearing duties.

The first (clause 11) requires operators of “age-restricted platforms” to take reasonable steps to stop New Zealanders under 16 from holding an account. The second (clause 14) requires those operators to produce an annual, written child safety risk assessment covering all under-18s who use the platform.

Behind these sit an enforcement apparatus of warnings, enforceable undertakings, corrective notices, tiered pecuniary penalties (up to the greater of NZ$40 million or 10% of global turnover), and, as a last resort, service restriction orders and access restriction orders that would conscript ISPs, app stores and ancillary providers into preventing access to the platform from New Zealand.

The regulator is the Secretary of Internal Affairs — the chief executive of the Department of Internal Affairs (DIA). More on this disturbing aspect later.

Much of the drafting is careful.

It regulates the account, not the child, so no penalty falls on minors or parents.

It explicitly forbids treating manual date-of-birth entry as a “reasonable step”.

It goes beyond the Privacy Act by requiring destruction of age-assurance data.

The Bill is also more sophisticated than the “ban” it is marketed as. As I have argued on earlier occasions about similar proposals, this is a set of managed restrictions on account-holding, not a prohibition on children seeing content. Publicly available material remains reachable.

But the care in the drafting cannot rescue the concept.

The Bill imports a policy model that has already been trialled next door in Australia and in Britain, and the trials are in.

What follows is the case against it — a case now supported by a striking amount of hard evidence rather than speculation — followed by the specific problem of handing the whole scheme to the DIA.

The central flaw: a “targeted” measure that touches everyone

The Bill’s rhetorical appeal rests on the idea that it targets under-16s. Its mechanism does not.

To reliably prevent a 15-year-old from holding an account, a platform must satisfy itself about the age of every account-holder — which in practice means age-assuring the entire adult population as well.

Privacy Commissioner Michael Webster made the point bluntly when the policy was first floated. Keeping under-16s out means everyone over 16 has to prove they are over 16. The New Zealand Initiative put it the same way — everyone will have to demonstrate they are not under sixteen, including you.

This is the paradox the Bill never resolves, and it is not a drafting quibble but the whole problem.

Clause 11 forbids the “cheap check” (a manual date of birth entry) and forbids relying solely on formal ID or a digital identity service, which forces platforms toward either document upload, facial age-estimation, or “age inference” from behavioural and device signals.

Keep reading

Bluetooth Glitch Exposes Alibaba’s Secret Tracking Of Users, Developer Says

A San Francisco-based developer discovered that Alibaba Group’s AliExpress marketplace secretly hijacked his computer’s audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create “fingerprints” used to track devices without relying on cookies. 

The privacy-focused Brave browser revealed in a series of X posts that the AliExpress marketplace was keeping the developer’s computer audio system active through hidden browser scripts, potentially allowing the website to generate a unique identifier for his device.

The issue emerged when the developer’s Bluetooth headphones refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website’s code showed background scripts maintaining access to the computer’s audio-processing system without producing audible sound.

The scripts allegedly used the browser’s Web Audio API to process signals at zero volume. Small differences in how individual computers handle those signals can be measured and combined into an “audio fingerprint,” allowing websites to recognize devices even when cookies are deleted or blocked.

The developer also found that the scripts collected other device characteristics, including available memory, screen dimensions, and network information.

Here’s what Brave found:

1. Alibaba’s AliExpress was caught using users’ audio systems to track them. AliExpress wasn’t recording users but instead playing a silent sound and measuring how users’ specific devices processed it in order to fingerprint them.

2. Fingerprinting is a way that websites can identify you without cookies. Sites will note details about your device like your screen size or installed fonts. These details are then combined into a unique, persistent “fingerprint” that can be used to track you across the Web.

3. There are slight variations in how each device plays the same audio file due to differences in CPU, sound card, browser, etc. When AliExpress played the silent sound, it measured these small variations to help build fingerprints of users’ devices.

4. This tracking was discovered due to an unexpected side effect. A user with Bluetooth headphones noticed they couldn’t play music on their phone because the headphones were instead playing AliExpress’s silent sound from their PC.

Brave turned what it found into a sales pitch for its browser:

1. For 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser’s output so you show a different fingerprint to different sites. This fingerprint also resets across sessions.

2. Trackers are constantly finding new ways to fingerprint your device, so Brave keeps adding new protections. We recently added defenses against GPU fingerprinting, which stops sites from identifying you with your graphics card or drivers.

The findings raise new questions about browser fingerprinting, a stealthy way that uses silent audio processing for covert tracking. 

Keep reading

AG Blanche’s Warning Points Straight at Age Verification Checks

The US Department of Justice (DOJ) has managed to extract $400 million from TikTok, and this is not a story about the company being forced to change its ways – but pay up nonetheless.

The settlement, which means no admission of wrongdoing on the part of TikTok, will see the company pay $300 million now, and another $100 million once a prior consent decree is vacated.

That earlier decree came from a 2019 case, United States v. Musical.ly, an app that was later folded into TikTok. The current case, United States v. ByteDance, was filed in 2024 and is now dismissed with prejudice.

The original complaint accused ByteDance of violating the COPPA Rule by letting children slip past TikTok’s age gate and “knowingly creating accounts for children and collecting data from those children” without “verifiable parental consent.”

The 2019 consent decree also sought to ensure that the company would get “verifiable parental consent” before collecting personal information from children.

The settlement reached now requires TikTok to change absolutely nothing.

The DOJ explains this by saying that since the 2024 filing, TikTok “has undergone significant changes to its ownership, management, compliance functions, and privacy practices” and “implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.”

Those changes “have materially advanced the public interests underlying the Department’s litigation and have strengthened protections for millions of American families,” the DOJ said.

And what is “verifiable parental consent” that’s the main aspect of the original complaint and the 2019 consent decree? That’s where things get interesting. COPPA doesn’t mandate any specific method, but lists several, which escalate quickly from a signed consent form, to a payment from a parent’s credit or debit card, to submitting a government-issued ID and matching it to a face scan, or being verified over video call.

In other words, proving that a parent has given consent tends to boil down to proving who everyone is.

Keep reading

Warner Bros. DMCA Takedowns Hit Lanterns Spoiler Discussion

Warner Bros. Discovery has been using DMCA copyright takedowns to remove posts on social media that contained just discussions about the first episode of the HBO series Lanterns, a report by Puck said.

The posts in question didn’t contain any leaked stills or footage from the show – just people’s comments about a major plot twist revealed in the first episode, which had previously been rumored and reported on by some outlets.

The series, a DC one co-created by Chris Mundy, Damon Lindelof, and Tom King, premiered on Sunday, and its final moments delivered a shocking fate for one of the show’s characters.

Cosmic Book News (this link contains spoilers for Lanterns), an independent pop-culture site run by editor Matt McGloin, had spent months piecing the twist together from casting, promotional footage, and the show’s timeline; by March, McGloin was predicting the ending outright.

Warner Bros. was not happy about this, and went on to use copyright law to remove posts on X, YouTube, and Facebook. The first takedowns happened on July 10, two weeks before Comic-Con, when an anonymous Reddit post claimed to reveal the twist, and it spread to X. An HBO Max social strategist then filed a takedown notice covering six posts from five accounts, including Cosmic Book News, describing the infringement as “people discussing the spoilers of the first episode of Lanterns.”

Keep reading

X Wins Australian Case Over Private Message Scanning Rule

Australia’s eSafety Commissioner wrote a rule requiring online services to scan what their users send each other. Not to act on reports, but to run detection systems across private messages before anyone has complained, hunting child sexual abuse and pro-terror material. Top censor, Julie Inman Grant, wrote it herself, under powers the Online Safety Act hands her, and breaching it carries penalties of up to $49.5 million.

Then she took the view that it covered social media platforms as well, because they let users send each other messages.

On August 12, the Federal Court told her it does not. The Relevant Electronic Services Standard “does not apply” to X, Justice Elizabeth Raper held, ruling for the platform in a case it brought in May 2025. It “would be rather perverse for a social media service…not to enable messaging or chat between end users,” X’s barrister had argued — on eSafety’s reading, having a DM function was enough to pull a platform into a rulebook written for something else.

The distinction is important because of who writes what. Social media services in Australia are covered by a code developed with the industry, X included. The RES Standard is not a negotiated code. It is an instrument the Commissioner drafts and enforces herself. The standard says it applies “to the exclusion of any industry code” — so reading it to cover social media would have let the instrument she controls displace the one she negotiated.

Raper said so directly. “I accept X Corp’s characterisation of the facts that the RES Standard has been made by the commissioner…as a standard applicable to participants in a different section of the online industry, that are specified…as ‘providers of relevant electronic services’,” she wrote.

Keep reading

States take Meta to trial in California in the biggest fight yet over social media harms to children

Of the thousands of lawsuits Meta faces over child safety on its platforms, none may be more consequential than one going to trial this week in California.

States are seeking extensive financial damages that could, in theory, total as much as $1.4 trillion, plus changes to how the company operates Facebook and Instagram.

The lawsuit accuses the social media giant of contributing to the youth mental health crisis by knowingly and deliberately designing features that get children addicted to its platforms. It also claims that Meta routinely collects data on children under 13 without their parents’ consent, in violation of federal law.

“Meta has harnessed powerful and unprecedented technologies to entice, engage, and ultimately ensnare youth and teens. Its motive is profit, and in seeking to maximize its financial gains,” the lawsuit says.

Dozens of states filed the lawsuit three years ago. The trial set to begin Tuesday in federal court in Oakland, California, features four of the states as plaintiffs — California, Colorado, Kentucky and New Jersey. The other 25 states are expected to have trials later.

Meta said it disputes the allegations, and the trial evidence will show its commitment to supporting young people. “We’ve listened to parents, worked with experts and law enforcement, and conducted in-depth research to understand the issues that matter most,” the company said in a statement.

States seek to land a major blow against Meta
For Meta, which already lost two pivotal cases over harms to children and teens this year, the stakes are high. The company reported a rare profit decline last month, in part due to $2.4 billion in legal expenses.

The $1.4 trillion figure, which Meta disclosed in a legal filing, is almost as high as the Menlo Park, California, company’s entire market capitalization — that is, the value of all its outstanding shares on the stock market. Paying it would inevitably put Meta Platforms in bankruptcy and perhaps put the company under state ownership.

“The state attorneys general are going for the gusto,” said Eric Goldman, a professor and co-director of the High Tech Law Institute at Santa Clara University School of Law. “They are trying to set the definitive precedent in this case and they have asked for extraordinary damages and they are going to seek extraordinary structural remedies if they succeed.”

Meta calls the possible penalty “untethered to any claimed violation” by the states.

“A sanction of that size has no analog in the history of consumer protection enforcement,” Meta said in a July 6 filing with the U.S. District Court for the Northern District of California.

If Meta loses the trial, the court would have wide discretion over the size of any financial penalty, and legal experts say anything close to $1.4 trillion would be unlikely.

“It’s not plausible in the sense that Meta doesn’t have that much money and could not get it,” said James Grimmelmann, a law professor at Cornell Law School and Cornell Tech. “An award that large would put Meta into bankruptcy, wipe out its owners, and effectively result in the states owning Meta.”

Keep reading

Former Police Officer Convicted of Sharing ‘Grossly Offensive’ Meme About Islam in Britain

A former British police officer has been convicted of posting offensive content on Facebook after he reposted an image mocking Islam, sparking accusations that blasphemy laws have returned to the United Kingdom.

A former British police officer has been convicted of posting offensive content on Facebook after he reposted an image mocking Islam, sparking accusations that blasphemy laws have returned to the United Kingdom.

Retired police officer Stephen Gray, 65, has been found guilty by the Newton Aycliffe magistrates’ court of breaching Section 127(1)(a) of the Communications Act 2003 over a post he reshared on Facebook, which was deemed to be “grossly offensive”.

According to The Telegraph, Gray was reported to the Durham Constabulary for two Facebook memes by a non-Muslim neighbour of his, whom Gray had previously been in a separate dispute with.

The first post reported to the police featured the title “time for mass deportations” next to a Middle Eastern man in his 20s or 30s with the words “Children in need”. It was captioned with: “12-year-old Mohammed recently arrived at Dover. Please donate to help him move from a three-star to a five-star hotel, which has a better halal menu, free Wi-Fi, and Sky and is nearer to a girls’ school”.

This post was not deemed by the court to violate the law, as it concerned a political issue that had been debated in Parliament.

The second meme depicted a picture of a man wearing a turban next to some bacon with the caption: “Fun facts about Bacon! People who eat bacon have a lower chance of marrying a 9-year-old!”

As the post was not considered to be a political message, but rather critical of a religion, it was found to be “grossly offensive” by the court. For this, Gray was found guilty of violating the Communications Act and was ordered to pay £1,000 in fines and court costs.

Gray said of the ruling: “I made a joke, an ironic joke, about Islam. That is all it was at the end of the day. A joke. I certainly never, not for one second, thought it would be deemed abusive.”

Keep reading