Top

Kaspersky Says Crypto Phishing on the Rise in the Philippines

Policy & Regulation·July 13, 2023, 12:55 AM

The Philippines witnessed a significant increase in detected cryptocurrency-related attacks last year while Vietnam recorded the highest level in Southeast Asia, according to cybersecurity firm Kaspersky.

Photo by Markus Spiske on Unsplash

 

Ease of crypto access

Vietnam topped the list with over 64,000 detections. Meanwhile, the Philippines recorded 24,737 cases of crypto-phishing attacks in 2022, up from 9,164 cases in 2021, making it the second-highest number in Southeast Asia.

Adrian Hia, Managing Director for Asia Pacific at Kaspersky, attributed the rise to the ease of accessing cryptocurrency in the Philippines. He explained that as users increasingly turn to mobile devices, they are inadvertently exposing themselves to potential breaches, as malware can be installed through various touch points.

Research published by Malaysian crypto data aggregator, CoinGecko, earlier this month, also points to the Philippines as having the second highest level of interest in crypto in Southeast Asia, after Singapore.

 

Targeting popular platforms

Cybercriminals commonly target accounts of popular online gaming platforms and crypto wallets using advanced stealers or “stalkerware” that allow them to spy on individuals through their mobile devices, Kaspersky stated. The firm’s monitoring data revealed that malware is spreading through legitimate channels such as official marketplaces and advertisements in popular apps.

Across Southeast Asia, the total number of crypto-phishing detections decreased to 147,649 in 2022 from 164,330 in 2021, according to Kaspersky. However, only Singapore (down 74%), Thailand (down 51%), and Vietnam (down 15%) observed declines in detections. Besides the Philippines, crypto-related attacks also increased in Indonesia (from 19,584 in 2021 to 24,642 in 2022) and Malaysia (from 16,071 to 16,767).

Kaspersky discovered an average of 400,003 new malicious files per day in 2022, representing an increase of 20,000 files per day compared to the previous year. Hia emphasized that scammers are relentless in their efforts to steal cryptocurrency due to its increasing popularity and adoption, particularly in Southeast Asia. He urged cryptocurrency adopters in the region to stay informed about the latest tricks used by crypto phishers to protect their digital assets.

 

Email-based attacks

Roman Dedenok, a spam analysis expert at Kaspersky, revealed that crypto phishers often employ email-based attacks to target crypto users. He explained that scammers entice victims with the prospect of participating in a cryptocurrency giveaway, offering popular digital assets such as Bitcoin, Ethereum, Litecoin, Tron, or Ripple.

The scammers provide a three-point guide to claim the free cryptocurrency along with a link to the “promotion” website. Clicking on the link leads users to a phishing site where they are prompted to specify the wallet to which they want the funds transferred.

In response to the growing cybersecurity concerns, Kaspersky is engaging in discussions with government institutions worldwide. In the Philippines, while the central bank does not directly regulate cryptocurrency, it has established guidelines for virtual asset service providers. The Chairman of the Securities and Exchange Commission (SEC) in the Philippines, Emilio Aquino, recently delayed publication of a regulatory framework for crypto, on the basis of having “to make sure people don’t get burned.”

Entities involved with virtual assets are required to obtain a license from the Bangko Sentral ng Pilipinas, the central bank of the Philippines, to comply with regulations.

More to Read
View All
Web3 & Enterprise·

Feb 28, 2024

Blockchain game performance is key to Wemade’s future success

South Korea’s securities and investment banking house, Shinhan Securities, has maintained the investment rating for Korean game company Wemade as “hold,” according to local financial media outlet Etoday. Shinhan Securities cited uncertainties in the crypto market outlook and the firm’s need to improve business performance as the ground for its latest investment rating. The performance of the firm’s blockchain games is a significant factor in Wemade’s future success as the overall excitement surrounding mobile massively multiplayer online role-playing games (MMORPGs) cools down.  Shinhan Securities’ head analyst Kang Seok-oh wrote in his analysis report that for Q4 2023, the firm recorded an operation loss of approximately $53 million (KRW 70.8 billion) and a consensus deficit close to $39.4 million (KRW 52.6 billion). Sales for the game company declined during the same period because the revenue from license sales, which was included in the Q3 2023 revenue, was not counted in the Q4 2023 figures, according to the report. Photo by Lorenzo Herrera on UnsplashNew games to enter the Chinese market Wemade is set to roll out more new games relative to last year, with plans to enter the Chinese market with “Mir4” and “MirM,” both of which are based on blockchain technology. Its MMORPG “Night Crows,” which ranked 3rd in mobile game sales last year, is also scheduled for a global launch on March 12. “The Legend of Mir”, the firm’s another new game in the pipeline, will be released in the second half of this year.  Kang said the key question is how much influence the crypto market boom will have on the future performance of the firm’s blockchain games. Furthermore, with the firm’s local sales slowing down following the cease of its referral marketing strategy, keeping its existing services profitable would be another important point, he said.  “Although Wemade keeps making its efforts to enter the Chinese market by signing contracts and obtaining the license permit Version Number from the Chinese government, it seems unlikely that Korean games will enjoy the high popularity they once had before China’s ban on Korean culture. Everything would have to turn out in the game company’s favor to improve its business performance,” Kang said. 

news
Web3 & Enterprise·

Sep 13, 2023

Bullish Emerges as a Bidder for Bankrupt FTX Exchange

Bullish Emerges as a Bidder for Bankrupt FTX ExchangeBullish, a Gibraltar-based crypto exchange with strong ties to Asia, has emerged as a prominent bidder for the bankrupt trading platform FTX, which filed for bankruptcy protection in November last year.Photo by Kelly Sikkema on UnsplashValuable customer baseUp until that point, FTX was a thriving player in the cryptocurrency market. However, it is now in the process of seeking new ownership or financial restructuring to resurrect its operations. In a report published on Tuesday, The Block outlined that according to sources familiar with the situation, Bullish is eager to acquire FTX primarily for its valuable customer base.The news follows the filing of a stakeholder brief to the bankruptcy court in Delaware in the United States by the FTX Debtor on Monday. The brief outlined that the Debtor, led by new CEO John Ray, has reached out to more than 75 bidders to evaluate the potential relaunch of the FTX exchange business.Bullish aims to leverage FTX’s existing user network, intending to convert as many of them as possible into Bullish customers. However, it’s worth noting that this complex negotiation process may face challenges and uncertainties along the way.Asian connectionsAlthough it’s incorporated and registered in Gibraltar, only 4% of the company’s staff are Gibraltar-based. Meanwhile, the firm has offices in Singapore and Hong Kong with those locations accounting for 49% of the company’s overall workforce, according to LinkedIn data. Back in November the firm confirmed that it wasn’t one of the many crypto businesses with exposure to the FTX collapse.Bullish was founded by Brendan Blumer, with Bloomer currently acting as the exchange’s Chairman. Blumer previously founded Block.one, the developer behind the EOS blockchain. He also successfully founded and later exited Okay.com, Hong Kong’s largest digital property agency.Other Asia-centric players in the crypto sector had expressed interest in buying the FTX business (or parts of the business) earlier in the year. These included Singapore’s BSQ Capital and Gamepay, India’s CoinDCX, Japan’s 5G networks developer Docomo and e-commerce giant Rakuten, and Hong Kong’s OKC Holdings.Tribe Capital interestThe Block article also outlines that US-based Tribe Capital is another significant bidder in the running. Tribe Capital had FTX within its venture portfolio prior to the exchange’s downfall and subsequent bankruptcy at the close of the previous year. It had also appeared on the list of 363 sales parties back in June, and prior to that still, it had expressed its interest in buying the business.To establish a clear timeline for its business restructuring efforts, the estate has set a deadline for new bids, which falls on September 24. The FTX estate is still at an early stage in trying to resuscitate the business. Even if it’s successful in that endeavor, it’s not expected that a new business will emerge until Q2 2024 at the earliest.Separately, a criminal prosecution against FTX Founder Sam Bankman-Fried is progressing with a trial scheduled to take place in New York in October. Presently Bankman-Fried is incarcerated in a New York City jail while he awaits trial, having been found to have breached his bail conditions on the grounds of witness tampering.

news
Markets·

May 09, 2025

Binance survey reveals evolving security habits of Asian platform users

Global crypto exchange Binance has carried out a survey which reveals that the security habits of Asian platform users are evolving positively.Photo by Vadim Artyukhin on UnsplashUsers responding to more sophisticated scamsIn a blog post published by the crypto exchange platform on May 6, Binance revealed that it had carried out a survey of nearly 30,000 platform users across Asia. The company’s takeaway following analysis of the survey data is that “scams are evolving — and so are crypto users.” The firm suggested that users are “stepping up their security game,” with exchanges facing growing demand from their users for real-time protection and smarter security tools. Increasing use of 2FAThe exchange platform found that 80.5% of survey respondents now use Binance two-factor authentication (2FA). While the use of 2FA is definitely a move in the right direction, it doesn’t guarantee the safety of a user’s digital assets.  In an article published by Forbes last month Forbes Contributor Davey Winder warned that infostealer malware can compromise 2FA codes in as little as 10 seconds. In June of last year, an OKX user lost $2 million in crypto to a hacker who utilized AI despite the victim having used Google’s 2FA. Double-checking transfersThe survey found that 73.3% of users double-check transfers before sending digital assets. Due to the nature of decentralized cryptocurrency, crypto transactions are not easily reversed and are usually irreversible. That puts a greater responsibility on crypto users to ensure that they are sending funds to the appropriate wallet address. Double-checking transfer addresses is not only necessary due to human error. Malware is also used by hackers to spoof such addresses, tricking the sender into sending the digital assets to their address rather than the one that was originally intended. It emerged in May 2024 that a Bitcoin trader had lost more than $70 million in Bitcoin in an “address poisoning” scam. Binance itself had warned users last September that “clipper malware,” which intercepts clipboard data on a user’s phone or desktop, replacing copied wallet addresses with alternative addresses under the hacker’s control, is increasingly being employed in hacking attempts. While the survey has revealed a positive evolution in the security habits of Asian platform users, there’s still room for further improvement. Just 17.6% of survey respondents utilize address whitelisting, a measure that restricts account user access to a safe list of pre-defined trusted addresses. Only 21.5% of survey respondents use anti-phishing codes as a security mechanism. The objective of phishing is to steal data, install malware on a user’s device or otherwise gain account access. An anti-phishing code aids the user in verifying the authenticity of emails and texts from a specific service. Security remains a major issue within crypto. Last month, hackers employed social engineering tactics to steal $330 million in Bitcoin from an elderly American victim. Exchange platforms themselves continue to struggle to safeguard user funds. Earlier this year, Binance competitor, Dubai-headquartered Bybit, suffered a $1.5 billion hack believed to have been perpetrated by North Korea’s Lazarus Group. Lazarus is also thought to have been behind a $235 million crypto theft at Indian crypto exchange WazirX in July 2024.

news
Loading