Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Policy & Regulation·

Jun 27, 2023

Singapore’s Central Bank Paves the Way for Digital Asset Networks

Singapore’s Central Bank Paves the Way for Digital Asset NetworksSingapore’s Monetary Authority (MAS) has taken a significant step towards the future of digital assets by proposing a comprehensive framework for the design of open and interoperable networks for tokenized digital assets.Photo by Pixabay on PexelsDetailed frameworkIn a report published on Monday, titled “Enabling Open & Interoperable Networks,” MAS presented a detailed framework aimed at understanding the design options necessary to facilitate the seamless trading of digital assets across diverse networks and liquidity pools. The framework is rooted in the core principles of financial market infrastructure and draws inspiration from cutting-edge projects that have been at the forefront of advancing these concepts.To ensure a robust and comprehensive approach, the report was jointly developed with subject matter experts from the Bank for International Settlements’ (BIS) Committee on Payments and Market Infrastructure (CPMI), with valuable contributions from prominent financial institutions including DBS Bank, JP Morgan, HSBC, SBI Digital Asset Holdings, Standard Chartered, and UOB.MAS defines digital asset networks as platforms that leverage distributed ledger technology (DLT) or blockchain to enable secure and efficient transfers of digital assets without the need for traditional intermediaries. These networks serve as the foundation for open and interoperable infrastructure, facilitating the issuance, transfer, and custody of digital assets. By promoting transparency, efficiency, and trust, the report suggests that they will play a pivotal role in shaping the digital asset ecosystem.Project GuardianThe report underscores the immense potential of digital asset networks in a future financial landscape, where digital assets and currencies can be seamlessly exchanged across different networks. MAS believes that these networks could revolutionize the way financial transactions occur, leading to increased efficiency and expanded possibilities. The framework also lays the groundwork for future exploration as part of the Project Guardian initiative, encompassing additional focused themes such as Trust Anchors and Institutional DeFi.MAS has also announced the expansion of Project Guardian to include a broader range of financial asset classes. The project now features an industry group comprising 11 leading financial institutions that will spearhead industry pilots in asset and wealth management, fixed income, and foreign exchange. Esteemed banks such as HSBC, Standard Chartered, DBS, and Citi are set to conduct multiple trials focusing on tokenization. For instance, Standard Chartered, in collaboration with Linklogis, is developing an initial token offering platform to issue asset-backed security tokens listed on the Singapore Exchange.Despite its cautious stance on cryptocurrency speculation, MAS recognizes the immense potential for value creation and efficiency gains within the digital asset ecosystem. Leong Sing Chiong, MAS’ Deputy Managing Director of Markets and Development, emphasized the authority’s optimism, stating: “We see significant potential for value creation and efficiency gains in the digital asset ecosystem.”This latest initiative by MAS comes on the heels of its recent proposal for standards governing the use of digital money, including central bank digital currencies (CBDCs) and stablecoins. Singapore’s central bank is paving the way for the future of digital assets and making a strong effort to assert its position as a global leader in digital asset innovation through the establishment of this framework alongside industry collaboration.

news
Policy & Regulation·

Nov 11, 2025

Japan to tighten crypto lending rules as regulator backs bank stablecoin pilot

Japan’s Financial Services Agency (FSA) is moving to close gaps in crypto regulation and support a new bank-led stablecoin pilot, as markets watch for a potential Bank of Japan rate hike. Tougher oversight of crypto lending and IEOsAccording to a CoinPost report, at the fifth meeting of its Digital Asset Working Group held last week, the FSA discussed introducing new requirements to bring crypto lending clearly within the regulatory framework. While firms managing or staking crypto must register as exchanges, some operators have avoided registration by structuring services as borrowing schemes, which are not legally treated as asset management.Photo by Possessed Photography on UnsplashThe FSA flagged that users face both credit and volatility risks, yet operators are not required to segregate customer assets or use cold wallets. Some services offer returns around 10% or tie up funds for several years, with weak risk management and exposure to re-lending defaults and staking slashing. Under the new policy direction, operators will need stronger risk management for re-lending and staking, tighter custody controls, and clearer risk disclosures and advertising. Institutional-only borrowing not offered to the public will remain exempt. Some members questioned whether the new requirements would be practical to implement for off-chain operators, noting that staking is fundamentally on-chain. The group also examined initial exchange offerings (IEOs) lacking financial audits, particularly those aimed at retail investors. Members discussed limits similar to equity crowdfunding: investments over 500,000 yen ($3,000) capped at 5% of annual income or net assets, up to 2 million yen ($13,000). Most past domestic IEOs were under 500,000 yen ($3,200). Some warned such caps could be bypassed through secondary trading, where tokens are immediately tradable. Major banks pilot stablecoinAlongside stricter rules, the FSA will support a stablecoin pilot led by MUFG Bank, Sumitomo Mitsui Banking Corporation, and Mizuho Bank. CoinDesk Japan noted the project, the first under the Payment Innovation Project, will include three additional participants. Mitsubishi Corporation will oversee operations, while Progmat and Mitsubishi UFJ Trust and Banking will handle issuance and custody. The pilot, launching this month with implementation targeted within the year, will test whether a joint stablecoin by major banks can navigate regulatory and operational challenges. Rate hike speculation mountsJapan’s calibrated digital asset push comes as speculation grows over a possible Bank of Japan (BOJ) rate hike next month. Minutes from the BOJ’s October meeting, cited by South Korean outlet Edaily, show one board member saying most conditions for a hike have been met and that financial conditions would stay easy even after an increase. The BOJ kept its rate at 0.5% at that meeting. A rate hike was described as likely if firms are seen committing to wage increases ahead of next spring’s labor talks and if no major global shocks emerge. Markets, however, remain cautious, citing uncertainty over U.S. tariff effects and whether newly elected Prime Minister Sanae Takaichi will endorse such a hawkish stance. 

news
Policy & Regulation·

Aug 04, 2023

Hong Kong Lawmaker Explores Digital Asset Links With Mainland

Hong Kong Lawmaker Explores Digital Asset Links With MainlandIn a move aimed at bolstering its position as a rising global Web3 hub, Hong Kong Legislative Council member Johnny Ng has expressed his aspiration to foster greater collaboration between digital asset platforms in Hong Kong and a Shanghai-based exchange.Photo by Simon Zhu on UnsplashDigital asset exchange interconnectivityAs Hong Kong continues to position itself as a key player in the emerging Web3 landscape, Ng envisions a future where licensed virtual asset exchanges in Hong Kong could be interconnected with their counterparts in Shanghai.Ng’s remarks came during an interview with Chinese media outlet The Paper. Drawing a parallel with the established Shanghai-Hong Kong Stock Connect program that seamlessly connects the stock markets of both cities, Ng raised the question of whether a similar connection could be established for licensed digital asset exchanges. Ng’s idea hinges on the potential to bridge appropriate platforms in Shanghai with those licensed in Hong Kong for virtual asset trading.Interconnected talent poolThe lawmaker’s enthusiasm for interconnectivity also extends to the talent pool. He expressed his desire for more Web3 talent exchanges between Hong Kong and the mainland, recognizing Shanghai’s status as a financial hub boasting numerous exceptional financial enterprises.Hong Kong’s approach to the Web3 landscape stands in contrast to mainland China’s stringent cryptocurrency regulations. While China banned cryptocurrency transactions in 2021, Hong Kong has embraced crypto firms, even encouraging partnerships between these firms and local banks.This year, Hong Kong authorities unveiled a series of cryptocurrency-related policy statements, aimed at fortifying its stature as a global financial center. A significant step followed in December, when the Hong Kong Legislative Council passed an amendment introducing a comprehensive licensing framework for virtual asset service providers (VASPs).In a recent development underscoring Hong Kong’s pro-crypto stance, HashKey and OSL have become the pioneering recipients of licenses for retail trading under the new regulatory regime, which commenced on June 1.Differing policy approachesPeople following developments in crypto and Web3 in China and East Asia have been speculating if the strategic positive shift in Hong Kong towards developing as a regional hub relative to the sector is indicative of a softening in the approach of mainland China towards the industry. It appears that Hong Kong’s pursuit of crypto business has been sanctioned by Beijing.Commentators have been monitoring the emergence of further encouraging signals. In May, Chinese state television featured a segment that covered cryptocurrency and in particular Bitcoin. Binance CEO Changpeng Zhao (CZ) was sufficiently encouraged by the development to suggest that it was “a big deal,” although the clip was later removed from the broadcaster’s website.Ng’s proposal aligns with the broader narrative of Hong Kong’s ambitious push into the Web3 landscape, capitalizing on its favorable regulatory environment to attract crypto-related ventures. As discussions evolve around the potential interconnectivity between Hong Kong and Shanghai’s digital asset exchanges, the global cryptocurrency community watches with interest to see if there are any emerging signs that Beijing will reciprocate positively.

news
Loading