Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Jun 09, 2023

AliExpress Partners With ‘The Moment3!’ NFT Project

AliExpress Partners With ‘The Moment3!’ NFT ProjectAliExpress, the renowned global e-commerce platform and subsidiary of China’s Alibaba Group, is making its entry into the world of non-fungible tokens (NFTs) through a newly announced partnership with The Moment3!, a Web3 project. The collaboration aims to release a collection of 5,555 NFTs later this month.Photo by Andrey Metelev on UnsplashWhat is ‘The Moment3!’?Oddly, we know very little about the project. Its Telegram channel has just been established, it doesn’t have a website, while its Discord and Twitter channels are also recently established with modest followings. Anonymity is a feature in Web3 and perhaps that’s the approach this project is taking. Whatever the background, it has to be said that there must be some talent behind the project for it to secure the backing of an entity like AliExpress by way of this partnership.This recent announcement was initially made on AliExpress’ official Twitter account but that tweet has since been removed. The project itself tweeted out news of the partnership on Thursday. The Moment3!’s mission, as stated in its Twitter bio, revolves around utilizing NFTs to immortalize special moments on the blockchain.According to the project’s Discord channel, The Moment3! aims to connect with real-world businesses and provide NFT owners with benefits and exclusive rights beyond the collectible value.NFT debutThis marks AliExpress’ initial venture into the NFT market, although its parent company, Alibaba, has previously explored the Web3 space. In September 2022, Alibaba’s luxury shopping platform, Tmall Luxury Pavilion, introduced an immersive shopping metaverse experience and introduced the Meta Pass, granting users free access to virtual experiences.Alibaba-Centric Web3 projectsThere have been several other Web3-related investments and developments related to Alibaba Group companies in recent months.Last month, Alibaba Cloud, one of the world’s largest cloud computing companies, joined forces with the Avalanche layer one blockchain project to introduce “Cloudverse,” a launchpad facilitating the creation of personalized spaces within the metaverse for businesses.In April Alibaba Cloud was the co-organizer of the Web3 Festival, an event held in Hong Kong to showcase the autonomous Chinese territory for the development of the Web3 sector. The four-day event attracted 10,000 attendees.In early May, Artifact Labs, a Hong Kong-based start-up company that specializes in metaverse and Web3 product offerings, raised $3.25 million in a funding round led by Blue Pool Capital. The investment firm is the personal investment vehicle of Alibaba founders Jack Ma and Joe Tsai.NFT warningAliExpress, owned by Alibaba Group, is a global e-commerce platform that does not cater to customers in mainland China, despite being headquartered in China. The Chinese government prohibited all cryptocurrency transactions in September 2021. NFTs remained legal although authorities recently issued a warning on their use, together with some guidelines.With its new collaboration, AliExpress is expanding its reach into the Web3 space and exploring the potential of NFTs. As the release date approaches, anticipation grows to witness the specific features and benefits offered by the 5,555 NFTs that will soon be available to the public.

news
Policy & Regulation·

May 08, 2023

BNP Paribas Partners With Chinese in Digital Yuan Push

BNP Paribas Partners With Chinese in Digital Yuan PushThe Chinese authorities continue with their sustained efforts to promote use of the digital yuan, on this occasion by hooking up with French international banking group, BNP Paribas.According to the South China Morning Post (SCMP) on Friday, the partnership will see BNP Paribas collaborating with the Bank of China (BOC) to promote the digital yuan to its corporate clients. The digital yuan or e-CNY is a digital representation of the Chinese sovereign currency, issued by the BOC.Photo by Eric Prouzet on Unsplashe-CNY system accessAs part of the arrangement, BNP Paribas China will connect into the BOCs system, accessing an e-CNY management system. The BOC has authorized ten banks in China including the four state-owned banks, all of which are domestic lenders, to deal with its digital currency business.The direct e-CNY system access enables straight-through processing, allowing BNP Paribas to offer digital wallet functionality to its corporate clients relative to the digital yuan. Essentially, the system will allow BNP Paribas China’s corporate clients to link their bank accounts with an accompanying digital wallet. Other functionality that will be enabled as a consequence includes access to smart contract applications through the m-CBDC bridge (central bank digital currency).BNP Paribas China CEO CG Lai commented on the partnership: “While this collaboration can supplement the Bank’s offline payment collection capabilities and further optimize our clients’ account structure, this also reinforced the Bank’s commitment to the China market.” Lai outlined that the bank intends to enhance customer service capabilities by pursuing digital innovation that, like in this instance, contributes to China’s economic development.Louise Zhang, Head of BNP Paribas China Transaction Banking claimed that the partnership will “provide innovative, efficient cash management and trade financing services to local and multinational clients.”CBDC developmentThere has been a lot of activity in recent years when it comes to the development of CBDCs. The central banks of most nations have carried out some level of preparatory or investigative work relative to a digital currency. However, China has been by far the leader in its development of a CBDC.The BOC first began research into a digital currency in 2014. The country’s State Council approved the development of the digital yuan in partnership with China’s commercial banks in 2017. Beyond initial development, a testing phase began in 2019 with the project known as the Digital Currency Electronic Payment (DCEP) system emerging as the first version of the digital yuan after a number of years of development.In 2020, the BOC began more extensive testing of the digital currency in four Chinese cities — Shenzhen, Suzhou, Chengdu and Xiong’an. To promote use of the currency at that time, they offered free digital yuan to residents of those cities to spend, in that way, stepping up efforts to popularize the digital currency.Last month, the administrators of the Chinese city of Xuzhou announced that it was in the process of publishing a pilot scheme which will set out a means for promoting China’s e-CNY digital currency. Also in April, the eastern city of Changshu clarified that it is gearing up to commence paying state employees in the city in e-CNY. According to an announcement made by the city’s finance bureau the civil servants will start to receive e-CNY as payment in May.

news
Web3 & Enterprise·

Jan 18, 2024

Lillius selected to join Cronos Accelerator Program

AI sports challenge app Lillius has been selected as the first South Korean project in the Web3, sports and lifestyle categories to participate in the Cronos Accelerator Program, according to an official announcement on Wednesday (KST).Photo by Kelly Sikkema on UnsplashBridging exercise and Web3Lillius is a mobile app that allows users to participate in different sports and exercise challenges that use AI motion detection technology to analyze their form while performing the movements. After they complete a challenge, users can receive rewards based on their score. Notably, some of the challenges feature exclusive lessons from Korean Olympic medalists like taekwondo athlete Lee Dae-hoon, fencer Nam Hyun-hee and wrestler Jung Ji-hyun. Fostering innovationThe Cronos Accelerator Program, operated by global blockchain firm Cronos Labs, is an initiative aimed at nurturing and propelling startups in the Defi, Web3 and blockchain sphere, providing support in areas like technology, tokenomics, marketing, fundraising and more. In particular, participants in the program can receive mentoring and secure investment opportunities from industry experts. All participants are also eligible to receive an immediate stipend of $30,000 and the chance to win a $100,000 follow-up investment from Cronos Labs and its other partners. By participating in the Accelerator Program, Lillius plans to leverage its market potential, product appeal, cutting-edge AI technology and networks across the Cronos chain to become an innovative Web3 sports platform used worldwide.

news
Loading