Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Policy & Regulation·

Aug 22, 2024

China introduces legal framework to tackle crypto-linked money laundering

China's highest judicial authorities, the Supreme People's Court and the Supreme People's Procuratorate, have released a judicial interpretation that includes the use of virtual assets to transfer illicit funds as a recognized method of money laundering. This move aims to strengthen the legal basis for investigating and prosecuting cases linked to cryptocurrency and money laundering activities.Photo by Vidar Nordli-Mathisen on UnsplashClarifying the legal status of crypto transactionsThe new judicial interpretation classifies virtual asset trading as a potential channel for money laundering. It specifies that using virtual-asset transactions or financial-asset exchanges to transfer or convert the proceeds of crime falls under the act of “disguising or concealing the source and nature of criminal proceeds and their gains by other means” as outlined in the country’s criminal law. Liu Honglin, founder of the Shanghai-based Man Kun law firm, clarified in a social media post that the interpretation does not equate all cryptocurrency trading with money laundering. According to Liu, the directive is not intended to criminalize the possession or trading of cryptocurrencies domestically but to provide clear legal guidelines for prosecuting specific illegal activities linked to crypto transactions. Impact on crypto trading and enforcementShao Shiwei, a fintech lawyer based in Shanghai, suggested that this interpretation could pose challenges for stablecoin merchants and increase legal risks for those involved in receiving illicit funds through crypto trading. The interpretation is part of broader efforts to regulate the virtual asset space, following the comprehensive ban on crypto trading activities by the People’s Bank of China and other authorities in September 2021. Despite the ban, many investors have continued to find ways to engage in crypto trading, sometimes circumventing capital control measures. For example, in May, Chinese police dismantled an underground bank that utilized the USDT stablecoin for foreign currency exchanges involving over 13.8 billion yuan ($1.9 billion). This incident underscores the ongoing challenges in enforcing existing regulations against the backdrop of innovative methods to bypass legal restrictions. 

news
Web3 & Enterprise·

Nov 21, 2023

NEOPIN and Sevenline Labs collaborate to boost Web3 gaming expansion

NEOPIN and Sevenline Labs collaborate to boost Web3 gaming expansionCentralized decentralized finance (CeDeFi) protocol NEOPIN has entered into a partnership with Sevenline Labs, a Korea-based company specializing in blockchain solutions. This collaboration is aimed at fostering expansion in the Web3 gaming ecosystem.Photo by Alicia Christin Gerald on UnsplashGames of different genres and platformsSevenline Labs is currently operating a Web3-powered esports tournament platform called Miracle Play. Leveraging application programming interfaces (APIs), the platform offers games of different platforms of genres on blockchain networks. It enables mobile, desktop, console and Web3 gamers to engage in diverse tournaments and earn rewards from competitions.Sevenline’s inaugural service, operating on the Polygon Network, has successfully completed a closed beta test specifically targeted at Indonesian communities. Currently, the company is in the process of conducting an open beta test. Looking ahead, Sevenline is planning to extend its support to various chains compatible with Ethereum virtual machines (EVMs). This expansion includes notable blockchain platforms such as Avalanche, Binance Smart Chain, Oasys, Solana and Klaytn. The ultimate objective of Sevenline is to orchestrate large-scale tournaments between different mainnets, with each of them representing a distinct faction.Through the collaboration between NEOPIN and Sevenline Labs, NEOPIN’s global partners will introduce their Web3 games to the Miracle Play platform. This move allows users to voluntarily host and participate in various tournaments, thereby enhancing the visibility and popularity of these games. Concurrently, Web3 gaming companies that have formed partnerships with Sevenline will be incorporated into the NEOPIN ecosystem.Native tokens to be supportedThe integration of the NEOPIN wallet with Miracle Play is a strategic move that aims to attract a global user base, particularly those who have completed Know Your Customer (KYC) and Anti-Money Laundering (AML) checks. This strategy presents a win-win scenario for both NEOPIN and Miracle Play. NEOPIN benefits by gaining access to a dedicated community of Web3 gamers who will actively organize and partake in tournaments on the Miracle Play platform. In return, Miracle Play taps into the decentralized finance (DeFi) user base associated with NEOPIN. Furthermore, both platforms plan to support their native tokens — the NEOPIN (NPT) token and the Miracle Play (MPT) token in the future.Ethan Kim, CEO of NEOPIN, expressed that the partnership will be beneficial in three aspects: attracting Web3 gaming partners, acquiring mutual users and expediting the adoption of the Web3 gaming ecosystem. He emphasized NEOPIN’s commitment to accelerating the global expansion of the NEOPIN ecosystem through these strategic efforts in promoting the Web3 gaming sector.

news
Web3 & Enterprise·

Sep 11, 2023

Lillius and Crypto.com Team Up for NFT Collaboration and Global Marketing

Lillius and Crypto.com Team Up for NFT Collaboration and Global MarketingLillius, a Korean artificial intelligence (AI) sports challenge app, has signed a business deal with global crypto trading platform Crypto.com to collaborate on a non-fungible token (NFT) project and global marketing strategies. The two companies will work together to promote Lillius’ platform mainly by issuing and distributing NFT rewards within the app.Elevating fitness with AILillius, set to launch its open beta service this month, is a mobile app where users can participate in exercise challenges that use AI motion detection technology to analyze their form while doing the movements. After they complete a given challenge, they can receive rewards based on the score they earn. Some of these challenges feature lessons from Korean Olympic medalists like taekwondo athlete Lee Dae-hoon, fencer Nam Hyun-hee, and wrestler Jung Ji-hyun.Photo by Huckster on UnsplashTo grow its platform, Lillius has also minted NFT figurines for iconic athletes such as table tennis player Ryu Seung-min, swimmer Park Tae-hwan, and archer Joo Hyun-jung, among others.Unlocking global Web3 sports experiencesUnder the new partnership, Crypto.com will be responsible for leveraging its global infrastructure to support Lillius’ broader global expansion and various marketing endeavors.“Our partnership with Crypto.com will expand access to Web3-based sports experiences for users around the world and serve as an important milestone in advancing our Web3 sports ecosystem,” said Julia Kim, CEO of Lillius. “We plan to enhance Lillius’ global competitiveness and lead the Web3 sports industry.”Crypto.com has consistently been participating in sports-related marketing projects and investing in such businesses as well. In 2021, it signed a naming rights agreement to change the name of the world-renowned sports and entertainment arena, the Staples Center, to Crypto.com Arena. It also became the first virtual asset platform to sponsor the 2022 FIFA Qatar World Cup. Furthermore, the platform has worked with some of the world’s biggest sports associations such as the UFC and Paris Saint-Germain F.C., playing a key role in bridging the gap between blockchain and sports. Its latest business agreement with Lillius comes as part of more concentrated efforts to enter the Korean market.“Through this partnership, we will cultivate the merging of sports and blockchain technology by providing Crypto.com’s 80 million users with a unique sports-related consumer experience,” said Patrick Yoon, CEO of Crypto.com Korea.

news
Loading